Application Anomaly Detection via Behavior Profile Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security programs fail to detect anomalies in trusted application programs exploited by malicious attacks due to high false-positive rates and inability to recognize behavior deviations from the program's purpose, leading to potential malicious activity going undetected.
Innovation Solution
An apparatus and method that utilize a behavior monitor, anomaly detector, and anomaly stopper to analyze and stop anomalous behavior of application programs based on a behavior profile specific to each application, reducing false positives and preventing malicious attacks by classifying behavior as normal or anomalous according to predefined profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional anomaly detection-based security programs monitor all application behaviors using uniform criteria, then new type of attacks can be detected, but false-positive rate becomes high
Solution Approach 1:
The patent segments the monitoring approach by creating separate behavior profiles for each application program. Instead of using uniform monitoring criteria for all applications, the system divides monitoring into application-specific segments with customized allowed behavior lists, reducing false positives while maintaining attack detection capability.
Solution Approach 2:
The patent applies local quality by tailoring monitoring strictness to each application's characteristics. Each application receives a customized behavior profile reflecting its specific functionality and legitimate operations, allowing the system to be less restrictive for trusted applications while maintaining high detection for suspicious ones.
2Measurement precision
If conventional security programs allow all behaviors of trusted application programs without behavior analysis, then false-positive rate decreases, but malicious attacks exploiting application vulnerabilities go undetected
Solution Approach 1:
The patent performs preliminary action by pre-defining allowed behaviors for each application program before monitoring begins. The behavior profile lists legitimate operations in advance, enabling the system to quickly determine whether observed behaviors are anomalous without extensive real-time analysis, thus reducing false positives while maintaining security.
3Measurement precision
If signature-based anti-virus programs use pattern matching with known malicious codes, then detection accuracy for known threats is high, but protection against day-zero attacks using unknown malicious codes is provided
Solution Approach 1:
The patent inverts the traditional approach by instead of looking for what is malicious (signature-based), it looks for what is normal (behavior profile-based). By defining allowed behaviors and treating deviations as anomalies, the system can detect unknown attacks without relying on prior knowledge of malicious patterns.
Data Source
AI summary
An apparatus and method for preventing an anomaly of an application program are provided. More particularly, an apparatus and method for preventing an anomaly of an application program that detect and stop an anomaly on the basis of a behavior profile for an application program are provided. The apparatus includes a behavior monitor that detects behavior of an application program in operation, an anomaly detector that determines whether the detected behavior of the application program is an anomaly on the basis of a behavior profile of the application program in operation, and an anomaly stopper that stops the behavior of the application program determined as an anomaly by the anomaly detector. Possible application program behavior is stored according to its purpose in a behavior profile and an anomaly is detected and stopped on the basis of the behavior profile, thereby decreasing a false-positive rate of anomaly detection and simultaneously solving a problem of a conventional security programs being incapable of defending against attacks using the authority of a program trusted by a user.


