Cloud-Based Malware Detection Using System Environment Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting and removing malicious programs are ineffective due to the rapid evolution of malware, which often exploits system vulnerabilities not accounted for in local security software, leading to delayed detection and spread of new malicious programs.
Innovation Solution
A scanning device and cloud management system that reads system environment information, generates personalized scanning content indications based on both the program and contextual attributes, and performs matching in a cloud database to accurately identify and remove malicious programs, avoiding the need for frequent updates of local engines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If local engine scanning is used with built-in scanning positions and features, then the scanning device can operate independently, but the detection capability becomes outdated quickly as malicious programs evolve and bypass existing detection methods
Solution Approach 1:
The system performs preliminary actions by proactively sending system environment information to the cloud server before threats can spread. The cloud server pre-generates scanning content indications based on the environment information, enabling rapid response to new malicious programs before they can bypass detection or spread widely.
Solution Approach 2:
The system implements feedback by continuously transmitting system environment information to the cloud server, which analyzes this information and returns updated scanning content indications. This closed-loop feedback mechanism ensures the local scanning device always has current detection capabilities adapted to the specific system environment, maintaining high detection accuracy against evolving threats.
2Reliability
If the local engine is manually updated after obtaining malicious program samples, then the detection capability can be improved, but the update process takes time during which malicious programs spread over large areas
Solution Approach 1:
The system performs preliminary action by continuously transmitting system environment information to the cloud server, which pre-analyzes and prepares scanning content indications before threats spread. This eliminates the manual update delay by having detection capabilities ready in advance based on the specific system environment.
Solution Approach 2:
The cloud server acts as an intermediary between the local scanning device and the evolving threat landscape. It receives system environment information, analyzes new malicious program characteristics, and returns updated scanning content indications, enabling rapid adaptation without manual engine updates and preventing widespread propagation of new threats.
3Measurement precision
If cloud server generates personalized scanning content indications based on system environment information, then the detection accuracy for new threats improves, but the communication and processing overhead increases
Solution Approach 1:
The system extracts only the essential system environment information (such as operating system version, installed software, hardware configuration) and transmits it to the cloud server for analysis. This selective extraction maintains high detection precision by focusing on relevant environmental factors while minimizing communication overhead and processing complexity.
Solution Approach 2:
The cloud server dynamically adjusts scanning content indications based on changes in system environment parameters. By monitoring and responding to parameter changes in the system environment, the system maintains high detection precision for new threats while optimizing the amount of data transmitted and processed, thereby managing system complexity efficiently.
Data Source
AI summary
The invention discloses a scanning device, a cloud management device, a method and system for checking and killing a malicious program. Therein, a cloud management device for checking and killing a malicious program comprises: a second transmission interface; a first indicator configured to generate a first scanning content indication according to characteristics of a newborn malicious program and system environment information transmitted by a client device; a first matcher configured to obtain via the second transmission interface feature data of the unknown program file transmitted by the client device, and hereby perform matching in known records of feature data of malicious programs; and a second indicator configured to generate a second scanning content indication when the first matcher fails to match to a known record, the second scanning content indication comprising scanning a specified attribute of the unknown program file and/or a specified attribute of the contextual environment of the unknown program file, and transmit the same to the client device through the second transmission interface.


