Zero-Day Rotating Guest Image Profile for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware detection systems are inadequate in detecting zero-day exploits due to the time lag between software component releases and the deployment of fully-instrumented software profiles, leading to missed malicious activities and ineffective classification.

Innovation Solution

A threat detection platform that provisions two virtual environments: one with a fully-instrumented legacy software profile and another with a temporary software profile based on a legacy activity monitor package, allowing for concurrent analysis and incremental updates to detect zero-day exploits until full instrumentation is complete.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a fully-instrumented software profile is developed for a newly released software component, then malware detection accuracy is improved, but the development time and time lag increase, allowing zero-day exploits to go undetected

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddevelopment time lag
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by creating a temporary software profile before the fully-instrumented profile is complete. This temporary profile allows immediate testing and detection of known malware patterns, reducing the time lag. The preliminary profile is later replaced or supplemented by the complete instrumentation once developed, ensuring both rapid response and thorough detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The software profile development is segmented into two phases: a temporary profile with basic activity monitors for immediate use, and a fully-instrumented profile with comprehensive monitors for complete detection. This segmentation allows the system to deploy detection capabilities immediately while the full instrumentation is being developed, eliminating the waiting period without sacrificing eventual detection thoroughness.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional anti-virus scanning programs use known malware signatures, then detection of known malware is effective, but detection of zero-day exploits fails completely

Engineering Contradiction:
Improvedetection effectiveness for known malwareVSAvoiddetection capability for new malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection approach by transitioning from static signature-based detection to dynamic behavior-based detection. The temporary software profile enables behavioral monitoring that can identify zero-day exploits by detecting suspicious activities and patterns, while maintaining the ability to use known signatures for established threats. This dynamic adaptation allows the system to handle both known and unknown malware effectively.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If activity monitors are configured to capture all functionality of a software component, then complete malware detection coverage is achieved, but the instrumentation development becomes excessively time-consuming

Engineering Contradiction:
Improvedetection coverageVSAvoidinstrumentation development speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies partial action by implementing a temporary software profile that includes only the most critical activity monitors needed for immediate detection, rather than waiting for complete instrumentation of all functionality. This partial implementation enables rapid deployment while maintaining detection of the most significant threats, and the remaining instrumentation is added subsequently without delaying initial protection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10075455B2Zero-day rotating guest image profile
Publication Date: 2018.09.11 MAGENTA SECURITY HOLDINGS LLC
  • US10075455B2 patent drawing
  • US10075455B2 patent drawing
  • US10075455B2 patent drawing

AI summary

According to one embodiment, a threat detection platform features a housing, a communication interface, a processor coupled to the communication interface, and a data store. The data store includes (i) an event log, (ii) a first virtual machine, and (iii) a second virtual machine. The first virtual machine is provisioned with a first guest image that is based on an instrumented software profile that includes a first software component and activity monitors configured for the first software component. The second virtual machine is provisioned with a second guest image that is based on a temporary software profile that includes a second software component that is a more recent version of the first software component and the activity monitors configured for the first software component.