Volatile Memory Analysis and Visualization for Hidden Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing machines lack visibility into their runtime state, particularly volatile storage, making it difficult to detect malicious activities and maintain network integrity, as traditional anti-virus technologies cannot access critical data in device memory, allowing attackers to exploit this lack of visibility.

Innovation Solution

A system and method for detecting and analyzing anomalous conditions by accessing and integrating volatile memory data, reconstructing data structures, and generating visualizations to identify suspicious activities, including graphical command consoles, remote software agents, and distributed processing servers for evaluating the live runtime state of computing machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional anti-virus technologies are used to detect malicious software artifacts within files or exposed data, then known signatures can be identified, but critical data stored in volatile storage (device memory, RAM) remains inaccessible, allowing attackers to hide malicious activities

Engineering Contradiction:
Improvevisibility into runtime stateVSAvoiddetection capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system divides the memory analysis task into separate functional modules: a memory manager for accessing volatile storage, a data extractor for retrieving runtime state information, and an analyzer for processing extracted data. This segmentation enables comprehensive access to previously inaccessible memory regions while maintaining system stability and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a memory manager as an intermediary component that safely interfaces between the analysis system and volatile storage. This mediator enables reliable access to runtime state data without directly compromising system stability, resolving the contradiction between information access and detection reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If attackers exploit channels in volatile storage for communication and hiding, then they can evade detection, but the system lacks the ability to monitor and detect these hidden activities

Engineering Contradiction:
Improvemalicious activityVSAvoiddetection of hidden channels
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary extraction of runtime state data from volatile storage before malicious activities can fully exploit hidden channels. By continuously monitoring and extracting memory data, the system establishes a baseline that enables detection of anomalous patterns and hidden communication channels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional file-based detection mechanisms with memory-based analysis. Instead of relying on static file signatures, the system uses dynamic memory extraction and pattern recognition to detect hidden channels and anomalous runtime behavior, significantly improving detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If the system provides detailed information about runtime state and anomalous conditions, then users can effectively respond to compromises, but the complexity of accessing and analyzing volatile memory increases

Engineering Contradiction:
Improveuser response capabilityVSAvoidmemory access and analysis mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The memory manager and data extractor components automatically perform memory access, data extraction, and preliminary analysis without requiring manual user intervention. This self-service approach simplifies user interaction while providing comprehensive runtime state information for effective response to security incidents.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The analysis system is designed as a universal platform that can examine multiple types of data structures, process various memory regions, and support different detection methods. This multi-functionality reduces operational complexity for users while maintaining detailed analysis capabilities across diverse runtime states.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If the system continuously monitors runtime state for compliance verification, then policy violations can be detected, but the performance impact and resource consumption increase

Engineering Contradiction:
Improvecompliance verificationVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of continuously analyzing all memory data, the system extracts and analyzes only the specific runtime state information relevant to compliance verification. This partial action approach maintains reliable compliance monitoring while minimizing performance impact and resource consumption by focusing analysis on critical data elements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250258915A1Systems, Methods and Devices for Memory Analysis and Visualization
Publication Date: 2025.08.14 VOLEXITY LLC
  • US20250258915A1 patent drawing
  • US20250258915A1 patent drawing
  • US20250258915A1 patent drawing

AI summary

Systems, methods, and processing devices for aiding with cyber intrusion investigations that includes capabilities for extracting data from a specified range of a volatile memory of a target processing device, reconstructing data structures and artifacts from the extracted data; and generating and presenting a visualization of the reconstructed data structures and the reconstructed artifacts.