Antimalware Ranking via Social Interaction Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing antimalware solutions do not effectively assess and mitigate malware threats based on a user's social context and associations, failing to provide personalized protection against specific malware types encountered by individuals within their social groups.
Innovation Solution
A computer system that receives malware notifications, identifies individuals within a user's social group at increased risk, generates communication graphs to predict malware infections, and ranks antimalware programs based on their ability to protect against user-specific threats by analyzing interactions with clusters that have encountered malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional antimalware solutions are used, then basic malware protection is provided, but the protection is not personalized or tailored to user-specific social context and associations
Solution Approach 1:
The system performs preliminary actions by building communication graphs and identifying malware risk clusters in advance, before actual malware encounters occur. This allows the system to pre-assess user risk profiles based on social associations and proactively recommend appropriate antimalware solutions, rather than reacting after infection occurs.
Solution Approach 2:
The patent introduces a new dimension of social context analysis by creating communication graphs that map user interactions and associations. This transforms the traditional single-dimension malware detection approach into a multi-dimensional system that considers both technical malware characteristics and social network relationships, enabling personalized protection recommendations.
2Measurement precision
If social context analysis is implemented, then personalized malware risk assessment is achieved, but data processing requirements and computational resources increase
Solution Approach 1:
The system extracts only the essential and relevant features from complex social communication data, such as communication frequency, interaction patterns, and association strength with known malware-risk users. By selecting and processing only these key features rather than analyzing all raw communication data, the system achieves accurate risk assessment while minimizing computational overhead.
Solution Approach 2:
The system implements partial action by focusing computational resources on analyzing only those social associations that are most relevant to malware risk, rather than processing all possible user data. The communication graph analysis selectively examines connections to users identified as being in malware-prone clusters, avoiding unnecessary processing of unrelated social interactions.
3Reliability
If communication graphs are generated to predict malware infections, then proactive threat identification is enabled, but system complexity and data structure requirements increase
Solution Approach 1:
The system segments the complex social network into manageable communication graphs organized by user clusters and interaction patterns. Rather than attempting to analyze the entire social network at once, the system divides it into smaller, manageable segments that can be independently analyzed for malware risk, making the overall system more tractable and less complex.
Solution Approach 2:
The communication graph serves as an intermediary data structure that mediates between raw social interaction data and malware risk assessment. This intermediate representation simplifies the complex relationships by organizing them into graph structures with nodes and edges, making it easier to analyze and process without directly handling the full complexity of raw social data.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments are directed to determining a risk of encountering malware based on social context, to determining malware threats based on social associations and to ranking antimalware programs according to the program's ability to protect against specific threats. In one scenario, a computer system receives a malware notification associated with a user that identifies a type of malware encountered by the user. The computer system identifies various persons that are part of a social group associated with the user and determines that at least one of the identified persons associated with the user has an increased likelihood of encountering the identified type of malware, based on information derived from identifying the persons that are part of the social group. Optionally, the computer system notifies the identified persons of the increased likelihood of encountering the identified type of malware.