Antimalware Signatures Database Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing manual signature creation processes for malware detection are prone to errors, lack optimality, and are not automated, making them inefficient in covering a large number of malware samples with low false positives and compact repository size.

Innovation Solution

A system and method for automatically generating and optimizing grouped signatures using attribute vectors from clean and malware files, which includes identifying potential subsets, collecting statistics, grouping similar files, and selecting optimal signatures based on a predefined target function to achieve low false positives and efficient processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual signature creation methods are used, then human operators can create signatures, but the process is prone to errors, guessing, and human operator mistakes

Engineering Contradiction:
Improvesignature accuracyVSAvoidautomation level
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically generating, optimizing, and selecting signatures without human intervention. The automated signature generation process analyzes malware samples, extracts features, and creates optimized signatures independently, eliminating human operator errors while maintaining high reliability through algorithmic precision and statistical optimization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical human operator process with an automated computational system. Instead of human operators manually creating signatures through guessing and testing, the system uses algorithmic processes including feature extraction, statistical analysis, and automated optimization to generate signatures, substituting human cognitive processes with deterministic computational methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a large collection of signatures is created to cover all known malware samples, then malware coverage is improved, but the repository size increases and scan time increases

Engineering Contradiction:
Improvemalware coverageVSAvoidscan time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system changes parameters by optimizing signature characteristics including selecting the most discriminative features, adjusting signature length, and tuning sensitivity thresholds. By modifying these parameters, the system achieves high malware coverage with a reduced number of signatures, thereby decreasing scan time while maintaining detection accuracy through parameter-optimized signature selection.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts only the essential and most discriminative features from malware samples to create compact signatures. Instead of using complete malware samples or all possible features, the system identifies and extracts the critical distinguishing characteristics, creating a condensed representation that maintains high detection accuracy while reducing repository size and scan time.

Inventive Principle:
Principle #2Taking out (Extraction)

3Weight of stationary object

If a compact repository size is maintained, then storage efficiency is improved, but the ability to cover all known malware samples is reduced

Engineering Contradiction:
Improverepository sizeVSAvoidmalware coverage
Core Design Contradiction:
Weight of stationary objectVSReliability

Solution Approach 1:

The system achieves compact repository size while maintaining comprehensive malware coverage by changing parameters including signature compression ratios, feature selection criteria, and clustering thresholds. These parameter adjustments enable the system to represent diverse malware families using fewer, more efficient signatures, reducing repository size without sacrificing detection capability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates universal signatures that can detect multiple malware variants within a family through multi-functionality. By designing signatures that capture common characteristics across different malware samples, a single signature can cover multiple threats, reducing the total number of signatures needed while maintaining comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Speed

If fast scan time is achieved, then processing speed is improved, but the ability to perform thorough inspection is reduced

Engineering Contradiction:
Improvescan speedVSAvoidinspection thoroughness
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system segments the inspection process into multiple stages including initial filtering using compact signatures, intermediate analysis of suspicious files, and detailed inspection only when necessary. This segmentation enables fast scan speeds for the majority of files while maintaining thorough inspection capabilities for files that require deeper analysis, balancing speed and precision through hierarchical processing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12265619B2Optimal antimalware signatures database
Publication Date: 2025.04.01 ACRONIS INT
  • US12265619B2 patent drawing
  • US12265619B2 patent drawing
  • US12265619B2 patent drawing

AI summary

A method for creating a collection with optimized family-specific signatures for protecting from malware includes collecting statistics of potential signatures for chosen sample attribute vectors, the statistics of potential signatures being collected for clean files and malware files, estimating a probability to find a potential signature in the clean files, grouping malware files with the same signature in clusters (families), choosing the most optimal signature for the malware family files based on a predefined target function, and exporting a collection with optimized family-specific signatures configured to be implemented by scan engines.