Antimalware Signatures Database Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing manual signature creation processes for malware detection are prone to errors, lack optimality, and are not automated, making them inefficient in covering a large number of malware samples with low false positives and compact repository size.
Innovation Solution
A system and method for automatically generating and optimizing grouped signatures using attribute vectors from clean and malware files, which includes identifying potential subsets, collecting statistics, grouping similar files, and selecting optimal signatures based on a predefined target function to achieve low false positives and efficient processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual signature creation methods are used, then human operators can create signatures, but the process is prone to errors, guessing, and human operator mistakes
Solution Approach 1:
The system performs self-service by automatically generating, optimizing, and selecting signatures without human intervention. The automated signature generation process analyzes malware samples, extracts features, and creates optimized signatures independently, eliminating human operator errors while maintaining high reliability through algorithmic precision and statistical optimization.
Solution Approach 2:
The patent replaces the mechanical human operator process with an automated computational system. Instead of human operators manually creating signatures through guessing and testing, the system uses algorithmic processes including feature extraction, statistical analysis, and automated optimization to generate signatures, substituting human cognitive processes with deterministic computational methods.
2Reliability
If a large collection of signatures is created to cover all known malware samples, then malware coverage is improved, but the repository size increases and scan time increases
Solution Approach 1:
The system changes parameters by optimizing signature characteristics including selecting the most discriminative features, adjusting signature length, and tuning sensitivity thresholds. By modifying these parameters, the system achieves high malware coverage with a reduced number of signatures, thereby decreasing scan time while maintaining detection accuracy through parameter-optimized signature selection.
Solution Approach 2:
The patent extracts only the essential and most discriminative features from malware samples to create compact signatures. Instead of using complete malware samples or all possible features, the system identifies and extracts the critical distinguishing characteristics, creating a condensed representation that maintains high detection accuracy while reducing repository size and scan time.
3Weight of stationary object
If a compact repository size is maintained, then storage efficiency is improved, but the ability to cover all known malware samples is reduced
Solution Approach 1:
The system achieves compact repository size while maintaining comprehensive malware coverage by changing parameters including signature compression ratios, feature selection criteria, and clustering thresholds. These parameter adjustments enable the system to represent diverse malware families using fewer, more efficient signatures, reducing repository size without sacrificing detection capability.
Solution Approach 2:
The patent creates universal signatures that can detect multiple malware variants within a family through multi-functionality. By designing signatures that capture common characteristics across different malware samples, a single signature can cover multiple threats, reducing the total number of signatures needed while maintaining comprehensive coverage.
4Speed
If fast scan time is achieved, then processing speed is improved, but the ability to perform thorough inspection is reduced
Solution Approach 1:
The system segments the inspection process into multiple stages including initial filtering using compact signatures, intermediate analysis of suspicious files, and detailed inspection only when necessary. This segmentation enables fast scan speeds for the majority of files while maintaining thorough inspection capabilities for files that require deeper analysis, balancing speed and precision through hierarchical processing.
Data Source
AI summary
A method for creating a collection with optimized family-specific signatures for protecting from malware includes collecting statistics of potential signatures for chosen sample attribute vectors, the statistics of potential signatures being collected for clean files and malware files, estimating a probability to find a potential signature in the clean files, grouping malware files with the same signature in clusters (families), choosing the most optimal signature for the malware family files based on a predefined target function, and exporting a collection with optimized family-specific signatures configured to be implemented by scan engines.


