Watermark Cookies for Malware Detection in Virtual Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack effective methods for detecting and clustering malicious HTTP cookies, which are used by malware to facilitate unauthorized access and data transmission, leading to difficulties in identifying and preventing malware propagation within networks.

Innovation Solution

A system and process for malicious HTTP cookies detection and clustering, involving the extraction of cookies from network traffic, analysis of patterns, and generation of signatures to identify malicious cookies, along with the use of watermark cookies in a virtual environment to detect malware by monitoring access to these cookies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall rules are used to filter network traffic, then basic unauthorized access protection is provided, but malicious HTTP cookies cannot be effectively detected or clustered

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidcookie pattern analysis complexity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the cookie analysis process into distinct components: extraction of cookies from HTTP traffic, pattern matching against known malicious signatures, clustering similar cookies together, and hierarchical organization. This segmentation transforms the complex problem of malicious cookie detection into manageable stages, improving detection reliability while controlling analytical complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by pre-establishing clusters of malicious cookie patterns and storing them as signatures before actual detection occurs. When network traffic is analyzed, cookies are compared against these pre-computed signatures, significantly improving detection speed and accuracy without requiring complex real-time analysis of every cookie.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive cookie analysis is performed to identify malicious patterns, then malware detection accuracy improves, but processing time and system resources increase

Engineering Contradiction:
Improvecookie identification accuracyVSAvoidtraffic analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent pre-computes and stores cookie patterns and their hierarchical relationships before actual traffic analysis. By organizing cookies into clusters and pre-establishing signatures, the system avoids performing comprehensive analysis on every cookie during traffic monitoring, thus maintaining high identification accuracy while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified representations (signatures) of malicious cookie patterns that capture essential characteristics without requiring full cookie analysis. These signature copies enable rapid comparison and identification during traffic analysis, maintaining detection precision while significantly reducing computational overhead.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If malware samples are detonated in a clean virtual environment, then safe analysis is enabled, but detection of cookie-stealing malware requires additional watermark cookies

Engineering Contradiction:
Improvemalware execution safetyVSAvoidvirtual environment setup
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent pre-installs watermark cookies into the virtual environment before detonating malware samples. This preliminary setup enables automatic detection of cookie-stealing behavior without requiring complex analysis tools or post-execution forensic investigation, maintaining safety while simplifying the detection mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The watermark cookies act as intermediaries between the virtual environment and the malware. By embedding detectable markers (watermark cookies) in the environment, the system enables indirect detection of malicious behavior through cookie access patterns, simplifying the overall detection architecture while maintaining safety.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10853484B2Cookies watermarking in malware analysis
Publication Date: 2020.12.01 PALO ALTO NETWORKS INC
  • US10853484B2 patent drawing
  • US10853484B2 patent drawing
  • US10853484B2 patent drawing

AI summary

Techniques for cookies watermarking in malware analysis are disclosed. In some embodiments, a system, process, and/or computer program product for cookies watermarking in malware analysis includes receiving a sample at a cloud security service; detonating the sample in an instrumented virtual environment; and determining that the sample is malware based on detecting an attempt to access a watermark cookie during an automated malware analysis using the instrumented virtual environment.