Circulating Monitor Module for Malicious Code Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional antivirus systems are not evolving fast enough to keep up with the rapid evolution of malicious codes in the IoT era, making them time-consuming, labor-intensive, and costly to maintain.
Innovation Solution
A monitor module is created by combining multiple antivirus systems, which circulates through a communication system to detect malicious codes and execute protection actions based on an evolution bias vector and probability vector, using either an admixture or association model to select and associate antivirus systems for effective protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional antivirus systems are used to detect malicious codes, then the system can provide basic virus protection, but the system cannot evolve fast enough to keep up with the rapid evolution of malicious codes in the IoT era
Solution Approach 1:
The patent combines multiple antivirus systems into a monitor module that circulates through the communication system. This merging of multiple antivirus systems enables the monitor module to evolve independently and adapt to new malicious codes faster than traditional single-system antivirus, resolving the contradiction between evolution speed and protection effectiveness.
Solution Approach 2:
The monitor module dynamically evolves by analyzing behavior characteristic vectors and executing multi-objective optimization algorithms to select optimal protection actions. This dynamic evolution capability allows the system to keep up with rapidly evolving malicious codes while maintaining high protection effectiveness.
2Measurement precision
If traditional antivirus systems manually study and build virus patterns, then the system can detect known viruses, but the process is time-consuming, labor-consuming, and costly
Solution Approach 1:
The monitor module performs self-evolution by automatically analyzing behavior characteristic vectors and executing optimization algorithms to generate protection strategies. This self-service mechanism eliminates the need for manual virus pattern study and building, maintaining high detection accuracy while significantly reducing time consumption and operational costs.
Solution Approach 2:
The system uses feedback from behavior analysis and optimization results to continuously improve the monitor module's detection capabilities. This feedback loop enables automatic learning from detected malicious codes, maintaining high measurement precision without requiring manual intervention to build virus patterns.
3Adaptability or versatility
If multiple antivirus systems are combined into a monitor module, then the system can evolve independently and adapt quickly, but the system complexity increases
Solution Approach 1:
The monitor module serves multiple functions: it circulates through the communication system, detects malicious codes, analyzes behavior characteristic vectors, executes optimization algorithms, and implements protection actions. This multi-functionality consolidates what would otherwise require multiple separate systems into a single evolving unit, managing complexity while maintaining high adaptability.
Solution Approach 2:
The system manages complexity by dynamically adjusting parameters such as the evolution bias vector and probability vector to optimize performance. These parameter changes allow the monitor module to adapt to different malicious code types without requiring proportional increases in system structure complexity.
Data Source
AI summary
A protecting method and system for malicious code, and a monitor apparatus are provided. The monitor apparatus circulates a monitor module obtained from a combination of a plurality of antivirus systems in a communication system, so as to monitor a plurality of electronic apparatuses in the communication system. When the monitor module is circulated to one of the electronic apparatuses and the malicious code is detected, a protection result is decided and one or more corresponding process actions are executed based on the protection result by the monitor module.

