Antivirus User Expertise Classification for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus systems face challenges in efficiently detecting and responding to the exponential growth of malware due to limited capabilities and personnel, with existing detection methods like signature and heuristic analysis being exhausted, and users with varying levels of expertise providing unreliable verdicts.

Innovation Solution

A system that classifies users based on their expertise in computer security, where high-expertise users' verdicts are accepted, and low-expertise users' verdicts are verified, with dynamic allocation of computing resources and configuration settings based on user roles to enhance malware detection and processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud computing services are provided to reduce infrastructure burden on clients, then convenience and scalability are improved, but security responsibilities and threat detection complexity are transferred to providers

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity responsibility
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments users into different expertise levels (novice, intermediate, expert) and assigns different roles and verification requirements accordingly. This segmentation allows the system to handle security verification efficiently by applying different processing rules to different user groups, resolving the contradiction between maintaining security and providing convenient cloud services.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional signature and heuristic detection methods are used, then malware detection capability is maintained, but productivity and response speed deteriorate due to limited personnel and processing capacity

Engineering Contradiction:
Improvedetection capabilityVSAvoidresponse speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables users to perform self-verification of security events through their own expertise judgment. Expert users can independently verify and report security threats without requiring extensive manual analysis by antivirus company personnel. This self-service approach dramatically increases productivity while maintaining reliable detection through the accumulated expertise of user contributors.

Inventive Principle:
Principle #25Self-service

3Productivity

If user verdicts are accepted without verification to increase processing speed, then productivity is improved, but measurement precision and detection accuracy deteriorate due to varying user expertise levels

Engineering Contradiction:
Improveprocessing speedVSAvoidverdict accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system applies different verification qualities to different users based on their expertise level. Expert users receive trusted status with their verdicts accepted with minimal verification, while novice users have their verdicts subject to stricter verification processes. This local quality differentiation resolves the contradiction by optimizing both speed and accuracy for each user segment.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms where user verdicts are verified against ground truth data and performance metrics are tracked. This feedback loop allows the system to continuously improve verification processes and adjust trust levels based on actual user performance, ensuring both high productivity and maintained precision.

Inventive Principle:
Principle #23Feedback

4Device complexity

If computing resources are allocated uniformly to all users, then system simplicity is maintained, but productivity and resource efficiency deteriorate due to varying user expertise and contribution quality

Engineering Contradiction:
Improvesystem simplicityVSAvoidresource efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system dynamically allocates computing resources based on user expertise level, verification requirements, and real-time processing needs. Expert users receive fewer verification resources since their judgments are more reliable, while novice users receive more verification resources. This dynamic allocation optimizes overall productivity while maintaining manageable system complexity through automated resource management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8209758B1System and method for classifying users of antivirus software based on their level of expertise in the field of computer security
Publication Date: 2012.06.26 AO KASPERSKY LAB
  • US8209758B1 patent drawing
  • US8209758B1 patent drawing
  • US8209758B1 patent drawing

AI summary

Disclosed are systems, methods and computer program products for classifying users of antivirus software based on user's level of expertise in the field of computer security. In one example, the system receives from antivirus software deployed on a user's computer information about security of the computer and history of user's usage of the software. The system categorizes the received information into categories based on (i) a number of computer threats detected by the user, (ii) a frequency of malware infections of the user's computer, and (iii) a level of user's proficiency with the antivirus software. The system then selects condition-action rules for each category of information and applies the selected rules to the categorized information to determine user's level of expertise in computer security. Finally, the system classifies the user as one of an expert or typical user based on the user's level of expertise.