Centralized Malware Detection System With Universal XML Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection systems are incompatible, leading to a lack of information sharing among different security applications, which hampers the effective detection and management of malware across various security products.

Innovation Solution

A centralized security management system with a central knowledge database and interpreter module that provides customized XML interfaces for receiving and parsing information queries from remote security applications, utilizing multiple analytical modules to analyze suspicious objects using various malware detection techniques and correlating results for accurate classification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security applications from different vendors are used, then detection coverage is improved, but information sharing and compatibility deteriorate

Engineering Contradiction:
Improvedetection coverageVSAvoidinformation sharing compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a central knowledge database that serves as an intermediary between multiple security applications from different vendors. This database receives malware information from various sources, standardizes the data format, and distributes it back to the security applications, enabling information sharing without requiring direct compatibility between the applications themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The central knowledge database provides universal interfaces that can accommodate multiple security applications from different vendors simultaneously. It implements standardized data exchange formats and protocols that allow diverse security products to share information through a common platform, making the system universally compatible across different vendor ecosystems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If each security application maintains its own malware database, then vendor independence is improved, but information sharing capability deteriorates

Engineering Contradiction:
Improvevendor independenceVSAvoidmalware information sharing
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the malware information storage and management function from the security applications themselves, placing it in a separate central knowledge database. This allows each security application to maintain its independence while the centralized database consolidates malware information from all sources, preventing information loss and enabling sharing without compromising vendor independence.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If multiple scanning engines are deployed, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple scanning engines and their respective malware databases into a single centralized knowledge database. This consolidation maintains the detection capabilities of multiple engines while reducing system complexity by eliminating redundant infrastructure and simplifying the architecture through a unified information repository that all security applications can access.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2447877B1System and method for detection of malware and management of malware-related information
Publication Date: 2015.05.27 AO KASPERSKY LAB
  • EP2447877B1 patent drawingFigure 1
  • EP2447877B1 patent drawingFigure 2
  • EP2447877B1 patent drawingFigure 3A~3C

AI summary

Disclosed are systems and methods for centralized detection and management of malware-related information for use by different security applications. In one example, the centralized security management system comprises a central knowledge database of security information, such as information about various types of malware and other security threats. The system further includes an interpreter module that provides a plurality of customized Extensible Markup Language (XML) interfaces for receiving and parsing information queries from remote security applications developed by different vendors. The system further includes a plurality of local and remote analytical modules (engines) that analyze information queries from the security applications using malware-related information contained in the central knowledge database.