Antivirus Record Classification for False Positive Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus solutions face inefficiencies in detecting and eliminating false activations, leading to non-malicious software being incorrectly flagged and blocked, due to human error and limitations in existing heuristic and signature-based detection methods.

Innovation Solution

A system and method for managing antivirus records that involves a remote server processing and classifying antivirus records based on detection events across multiple user computers, using statistical data and classification algorithms to determine if a record triggers false activations, and updating its status from 'working' to 'test' if it exceeds a detection threshold, thereby reducing false notifications and actions on clean files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proactive detection methods (heuristic analysis, code emulation, behavior analysis) are used to detect unknown malicious applications, then detection capability is improved, but processor time and computer resources are significantly consumed

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessor time and computer resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary classification of antivirus records into 'useful' and 'false positive' categories before they are applied in detection operations. By pre-processing and pre-classifying records using statistical data from multiple user computers, the system prepares detection data in advance, reducing the need for resource-intensive real-time analysis during actual malware detection operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by collecting statistical data from multiple user computers about antivirus record effectiveness. This feedback loop allows the system to identify which records produce false positives and which are truly useful, then adjust the detection system accordingly by removing false positive records and retaining useful ones, thereby improving detection efficiency without increasing resource consumption.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If antivirus records are continuously updated to detect new malicious software, then detection accuracy is improved, but false activations increase due to human error and overlapping code segments

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse activations
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The system introduces an intermediary classification process that acts as a mediator between antivirus record creation and deployment. Before antivirus records are applied to detect malicious software, they undergo classification using statistical data from multiple user computers to identify and separate false positive records from useful ones. This intermediary step prevents false activations while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing the antivirus record management system to automatically identify and remove false positive records through statistical analysis of user computer data. Instead of relying solely on manual expert review, the system autonomously classifies records based on real-world performance data, reducing human error and minimizing false activations in continuously updated antivirus databases.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If heuristic detection and behavior analysis are used to counter unknown malicious applications, then detection coverage is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the antivirus record management process into distinct components: data collection from user computers, statistical analysis, classification into 'useful' and 'false positive' categories, and deployment. By dividing the complex task of managing antivirus records with high detection coverage into manageable segments, the system reduces operational complexity while maintaining versatility in detecting unknown malicious applications.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10685109B2Elimination of false positives in antivirus records
Publication Date: 2020.06.16 AO KASPERSKY LAB
  • US10685109B2 patent drawing
  • US10685109B2 patent drawing
  • US10685109B2 patent drawing

AI summary

Systems and methods for managing antivirus records. A method can include providing a data store of antivirus records, providing an antivirus application to be executed on each of a plurality of user computers, and executing instructions by a remote server to implement a processing tool configured to collect an antivirus record parameter for a particular antivirus record and collect statistical data of a detection events associated with the antivirus record, and a processing tool to configured to determine a false activation using the antivirus record parameter and the statistical data.