Client-Side Malicious Code Remediation via Gateway Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current gateway solutions for blocking malicious software threats often require user or administrator interaction and may not effectively prevent malware from accessing alternative websites, allowing infections to persist even when some requests are blocked.

Innovation Solution

A method and system that involve requesting network site interaction from a client computing facility, determining unacceptable interactions based on an acceptance policy, denying access, and sending information to the client to determine if the interaction is automatically generated, prompting remedial actions such as scanning, isolating, or removing malicious code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If gateway solutions block network requests to malicious websites, then malware transmission is prevented, but user interaction is required and alternative website requests may still succeed

Engineering Contradiction:
Improvemalware prevention effectivenessVSAvoiduser interaction requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The client computing facility automatically performs remedial actions without requiring user or administrator interaction. The system self-diagnoses by receiving information about blocked requests, determines if the request was automatically generated by malware, and autonomously executes remedial actions such as scanning, isolating, or removing malicious code.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway facility sends information back to the client computing facility about blocked network requests. The client interprets this feedback information, determines whether the blocked request was caused by malware, and takes appropriate remedial action based on this feedback loop.

Inventive Principle:
Principle #23Feedback

2Reliability

If gateway solutions block network requests, then some malware transmission is stopped, but sophisticated malware can make alternate requests that may succeed

Engineering Contradiction:
Improvemalware transmission blockingVSAvoidmalware alternative request capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary analysis by receiving and interpreting information about blocked requests before taking remedial action. The client computing facility determines in advance whether the blocked request was automatically generated by malware, preparing the appropriate remedial response before the malware can complete its infection cycle through alternative requests.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces conventional mechanical gateway blocking mechanisms with an intelligent client-based system that uses information processing and automated decision-making. Instead of relying solely on gateway blocking, the system substitutes this with client-side analysis of blocked request information and automated remedial actions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If conventional gateway blocking is used, then network access control is simplified, but malware detection precision is insufficient

Engineering Contradiction:
Improvenetwork access control complexityVSAvoidmalware detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system adds a new dimension to network security by moving from purely network-level blocking to a combination of network monitoring and client-side analysis. The gateway provides network-level blocking information, while the client computing facility performs local analysis of the blocked requests, adding a computational analysis dimension that improves detection precision.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9112899B2Remedial action against malicious code at a client facility
Publication Date: 2015.08.18 SOPHOS LTD
  • US9112899B2 patent drawing
  • US9112899B2 patent drawing
  • US9112899B2 patent drawing

AI summary

Aspects of this invention may relate to a malicious application remedial action request application where a network site interaction may be requested from a client computing facility; the network site interaction from the client computing facility may be determined to be unacceptable based on an acceptance policy at a gateway facility; access to the network site from the client computing facility may be denied; information relating to the attempted interaction with the network site may be sent from the gateway facility to the client computing facility, wherein the information may indicate that the attempted interaction occurred; and the client computing facility may interpret the information relating to the attempted interaction, determine whether the attempted interaction was the result of an automatically generated request, and take remedial action in the event that the attempted interaction was the result of the automatically generated request.