Antimalware Ranking via Social Interaction Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing antimalware solutions do not effectively assess and mitigate malware threats based on a user's social context and associations, failing to provide personalized protection against specific malware types encountered by individuals within their social groups.

Innovation Solution

A computer system that receives malware notifications, identifies individuals within a user's social group at increased risk, generates communication graphs to predict malware infections, and ranks antimalware programs based on their ability to protect against user-specific threats by analyzing interactions with clusters that have encountered malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional antimalware solutions are used, then basic malware protection is provided, but the protection is not personalized or tailored to user-specific social context and associations

Engineering Contradiction:
Improvepersonalization of protectionVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by building communication graphs and identifying malware risk clusters in advance, before actual malware encounters occur. This allows the system to pre-assess user risk profiles based on social associations and proactively recommend appropriate antimalware solutions, rather than reacting after infection occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a new dimension of social context analysis by creating communication graphs that map user interactions and associations. This transforms the traditional single-dimension malware detection approach into a multi-dimensional system that considers both technical malware characteristics and social network relationships, enabling personalized protection recommendations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If social context analysis is implemented, then personalized malware risk assessment is achieved, but data processing requirements and computational resources increase

Engineering Contradiction:
Improvemalware risk assessment accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts only the essential and relevant features from complex social communication data, such as communication frequency, interaction patterns, and association strength with known malware-risk users. By selecting and processing only these key features rather than analyzing all raw communication data, the system achieves accurate risk assessment while minimizing computational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements partial action by focusing computational resources on analyzing only those social associations that are most relevant to malware risk, rather than processing all possible user data. The communication graph analysis selectively examines connections to users identified as being in malware-prone clusters, avoiding unnecessary processing of unrelated social interactions.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If communication graphs are generated to predict malware infections, then proactive threat identification is enabled, but system complexity and data structure requirements increase

Engineering Contradiction:
Improvethreat prediction accuracyVSAvoiddata structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex social network into manageable communication graphs organized by user clusters and interaction patterns. Rather than attempting to analyze the entire social network at once, the system divides it into smaller, manageable segments that can be independently analyzed for malware risk, making the overall system more tractable and less complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The communication graph serves as an intermediary data structure that mediates between raw social interaction data and malware risk assessment. This intermediate representation simplifies the complex relationships by organizing them into graph structures with nodes and edges, making it easier to analyze and process without directly handling the full complexity of raw social data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3901803A1Providing antimalware ranking based on social interactions
Publication Date: 2021.10.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3901803A1 patent drawingFigure 1
  • EP3901803A1 patent drawingFigure 2
  • EP3901803A1 patent drawingFigure 3

AI summary

Embodiments are directed to determining a risk of encountering malware based on social context, to determining malware threats based on social associations and to ranking antimalware programs according to the program's ability to protect against specific threats. In one scenario, a computer system receives a malware notification associated with a user that identifies a type of malware encountered by the user. The computer system identifies various persons that are part of a social group associated with the user and determines that at least one of the identified persons associated with the user has an increased likelihood of encountering the identified type of malware, based on information derived from identifying the persons that are part of the social group. Optionally, the computer system notifies the identified persons of the increased likelihood of encountering the identified type of malware.