Cloud Malware Classification Using Real-Time Threat Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-malware systems face delays in detecting new malware due to signature file updates and rely heavily on human analysis, which is time-consuming and inefficient, especially in cloud-based systems, while malware evolves to evade detection and interferes with security programs.

Innovation Solution

A cloud-based system with threat servers and a central server that applies real-time rules and heuristics, maintains a master database, and uses automated analysis to classify objects as malware, reducing network traffic and workload, and includes backup servers for maintenance and data recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If cloud-based systems store signatures in a central server to protect against new malware immediately, then detection speed is improved, but the system relies heavily on human analysis which is time-consuming and laborious

Engineering Contradiction:
Improvedetection speedVSAvoidhuman analysis time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The system enables automated analysis where the central server automatically receives, analyzes, and classifies malware objects without requiring human intervention for each object. The server applies algorithms and heuristics to autonomously determine whether objects are malware, eliminating the time-consuming manual analysis process while maintaining rapid detection capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of human analysis with automated computational algorithms. The central server uses automated scanning, pattern recognition, and classification algorithms to analyze malware objects, substituting human intellectual labor with machine-based automated systems that operate continuously without fatigue or delay.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If human analysts investigate each new object thoroughly, then classification accuracy is improved, but the volume of new objects daily makes it unrealistic to have skilled human analysts investigate each object

Engineering Contradiction:
Improveclassification accuracyVSAvoidobjects analyzed per day
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system segments the analysis process into multiple stages: automated preliminary analysis filters out clearly benign objects, automated detection algorithms identify obvious malware, and only suspicious cases requiring nuanced judgment are escalated to human analysts. This segmentation allows the system to handle high volumes of objects while maintaining accuracy for critical cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces automated analysis algorithms and heuristics as intermediaries between the incoming malware objects and human analysts. These intermediary systems perform initial screening and classification, reducing the burden on human analysts to every object while maintaining high accuracy through multiple layers of automated detection before human review.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the central server receives and stores vast amounts of data from remote computers, then detection capabilities are improved, but data communication and management become challenging

Engineering Contradiction:
Improvedetection capabilitiesVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential and relevant data from remote computers that are necessary for malware detection, rather than transmitting and storing all possible data. The central server receives specific object information, behavior data, and malware indicators, filtering out redundant information to reduce data management complexity while maintaining detection reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of the central server actively collecting and managing vast amounts of data from all remote computers, the system inverts the approach by having remote computers send only specific, pre-processed malware-related information to the central server. This reversal reduces the data management burden on the central server while maintaining comprehensive detection capabilities across the network.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP3958088B1Methods and apparatus for dealing with malware
Publication Date: 2025.12.17 WEBROOT INCORPORATED
  • EP3958088B1 patent drawingFigure 1
  • EP3958088B1 patent drawingFigure 2
  • EP3958088B1 patent drawingFigure 3

AI summary

In one aspect, a method of classifying a computer object as malware includes at a base computer (3), receiving data about a computer object from each of plural remote computers (2) on which the object or similar objects are stored and or processed. The base computer (3) comprises plural threat servers (62) arranged to receive said data from the plural remote computers (2) and apply rules and or heuristics against that data in real time to determine whether or not said object is malware and to communicate said determination to the remote computers (2). The base computer (3) comprises at least one central server (74) in communication with the threat servers (62) and arranged to receive said data about objects from the threat servers (62) to maintain a master database (71,72,73) of data received about objects from all of the threat servers (62).