Centralized Malware Detection System With Universal XML Interfaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection systems are incompatible, leading to a lack of information sharing among different security applications, which hampers the effective detection and management of malware across various security products.
Innovation Solution
A centralized security management system with a central knowledge database and interpreter module that provides customized XML interfaces for receiving and parsing information queries from remote security applications, utilizing multiple analytical modules to analyze suspicious objects using various malware detection techniques and correlating results for accurate classification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security applications from different vendors are used, then detection coverage is improved, but information sharing and compatibility deteriorate
Solution Approach 1:
The patent implements a central knowledge database that serves as an intermediary between multiple security applications from different vendors. This database receives malware information from various sources, standardizes the data format, and distributes it back to the security applications, enabling information sharing without requiring direct compatibility between the applications themselves.
Solution Approach 2:
The central knowledge database provides universal interfaces that can accommodate multiple security applications from different vendors simultaneously. It implements standardized data exchange formats and protocols that allow diverse security products to share information through a common platform, making the system universally compatible across different vendor ecosystems.
2Adaptability or versatility
If each security application maintains its own malware database, then vendor independence is improved, but information sharing capability deteriorates
Solution Approach 1:
The patent segments the malware information storage and management function from the security applications themselves, placing it in a separate central knowledge database. This allows each security application to maintain its independence while the centralized database consolidates malware information from all sources, preventing information loss and enabling sharing without compromising vendor independence.
3Measurement precision
If multiple scanning engines are deployed, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent merges multiple scanning engines and their respective malware databases into a single centralized knowledge database. This consolidation maintains the detection capabilities of multiple engines while reducing system complexity by eliminating redundant infrastructure and simplifying the architecture through a unified information repository that all security applications can access.
Data Source
Figure 1
Figure 2
Figure 3A~3C
AI summary
Disclosed are systems and methods for centralized detection and management of malware-related information for use by different security applications. In one example, the centralized security management system comprises a central knowledge database of security information, such as information about various types of malware and other security threats. The system further includes an interpreter module that provides a plurality of customized Extensible Markup Language (XML) interfaces for receiving and parsing information queries from remote security applications developed by different vendors. The system further includes a plurality of local and remote analytical modules (engines) that analyze information queries from the security applications using malware-related information contained in the central knowledge database.