Antivirus Record Selection for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing antivirus systems face challenges in selecting and storing data for malicious object detection, leading to increased memory usage on user devices without ensuring reliable protection, as current methods fail to effectively optimize the selection of data for detection without requiring large memory volumes.

Innovation Solution

A system and method for generating a set of antivirus records that utilize a remote server to evaluate and select the most effective records for detection, using techniques like signature analysis, heuristic analysis, and proactive analysis, and storing flexible hashes to minimize memory usage on user devices while ensuring comprehensive detection capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the volume of data used for detection is increased to detect more malicious objects, then the detection capability is improved, but the memory space occupied on the user device increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidmemory space occupied
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the antivirus data into two parts: a small set of essential antivirus records stored locally on the user device, and a large database of malicious object information stored on remote servers. This segmentation allows the device to maintain effective detection capability with minimal local storage requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a remote server as an intermediary between the user device and the comprehensive malware database. The server acts as a mediator that provides additional detection data on-demand, allowing the device to achieve high detection capability without storing all the data locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If more antivirus records are stored locally to ensure comprehensive detection, then the detection coverage is improved, but the available space on the hard drive decreases

Engineering Contradiction:
Improvedetection coverageVSAvoidavailable space on hard drive
Core Design Contradiction:
ReliabilityVSVolume of stationary object

Solution Approach 1:

The patent extracts only the most essential antivirus records needed for basic detection and stores them locally on the device. The remaining comprehensive malware database is taken out from the device and stored on remote servers, allowing the device to maintain detection coverage while preserving hard drive space.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transitions from a single-dimension local storage model to a multi-dimensional architecture that combines local minimal storage with remote comprehensive storage. This dimensional change allows the system to achieve comprehensive detection coverage without proportionally increasing local hard drive usage.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3151148B1System and method for generating sets of antivirus records for detection of malware on user devices
Publication Date: 2019.02.20 AO KASPERSKY LAB
  • EP3151148B1 patent drawingFigure 1
  • EP3151148B1 patent drawingFigure 2
  • EP3151148B1 patent drawingFigure 3

AI summary

Disclosed are systems and method for generating a set of antivirus records to be used for detection of malicious files on a user's devices. An exemplary method includes maintaining, by a server, a database of malicious files; generating, by the server, at least one antivirus record for each malicious file; calculating an effectiveness of each antivirus record by determining how many different malicious files were detected using each antivirus record; generating a set of most effective antivirus records; and transmitting, by the server, the set of most effective antivirus records to a client device.