Client-Side Malicious Code Remediation via Gateway Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current gateway solutions for blocking malicious software threats often require user or administrator interaction and may not effectively prevent malware from accessing alternative websites, allowing infections to persist even when some requests are blocked.
Innovation Solution
A method and system that involve requesting network site interaction from a client computing facility, determining unacceptable interactions based on an acceptance policy, denying access, and sending information to the client to determine if the interaction is automatically generated, prompting remedial actions such as scanning, isolating, or removing malicious code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If gateway solutions block network requests to malicious websites, then malware transmission is prevented, but user interaction is required and alternative website requests may still succeed
Solution Approach 1:
The client computing facility automatically performs remedial actions without requiring user or administrator interaction. The system self-diagnoses by receiving information about blocked requests, determines if the request was automatically generated by malware, and autonomously executes remedial actions such as scanning, isolating, or removing malicious code.
Solution Approach 2:
The gateway facility sends information back to the client computing facility about blocked network requests. The client interprets this feedback information, determines whether the blocked request was caused by malware, and takes appropriate remedial action based on this feedback loop.
2Reliability
If gateway solutions block network requests, then some malware transmission is stopped, but sophisticated malware can make alternate requests that may succeed
Solution Approach 1:
The system performs preliminary analysis by receiving and interpreting information about blocked requests before taking remedial action. The client computing facility determines in advance whether the blocked request was automatically generated by malware, preparing the appropriate remedial response before the malware can complete its infection cycle through alternative requests.
Solution Approach 2:
The patent replaces conventional mechanical gateway blocking mechanisms with an intelligent client-based system that uses information processing and automated decision-making. Instead of relying solely on gateway blocking, the system substitutes this with client-side analysis of blocked request information and automated remedial actions.
3Device complexity
If conventional gateway blocking is used, then network access control is simplified, but malware detection precision is insufficient
Solution Approach 1:
The system adds a new dimension to network security by moving from purely network-level blocking to a combination of network monitoring and client-side analysis. The gateway provides network-level blocking information, while the client computing facility performs local analysis of the blocked requests, adding a computational analysis dimension that improves detection precision.
Data Source
AI summary
Aspects of this invention may relate to a malicious application remedial action request application where a network site interaction may be requested from a client computing facility; the network site interaction from the client computing facility may be determined to be unacceptable based on an acceptance policy at a gateway facility; access to the network site from the client computing facility may be denied; information relating to the attempted interaction with the network site may be sent from the gateway facility to the client computing facility, wherein the information may indicate that the attempted interaction occurred; and the client computing facility may interpret the information relating to the attempted interaction, determine whether the attempted interaction was the result of an automatically generated request, and take remedial action in the event that the attempted interaction was the result of the automatically generated request.


