Cloud Malware Classification Using Real-Time Threat Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-malware systems face delays in detecting new malware due to signature file updates and rely heavily on human analysis, which is time-consuming and inefficient, especially in cloud-based systems, while malware evolves to evade detection and interferes with security programs.
Innovation Solution
A cloud-based system with threat servers and a central server that applies real-time rules and heuristics, maintains a master database, and uses automated analysis to classify objects as malware, reducing network traffic and workload, and includes backup servers for maintenance and data recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If cloud-based systems store signatures in a central server to protect against new malware immediately, then detection speed is improved, but the system relies heavily on human analysis which is time-consuming and laborious
Solution Approach 1:
The system enables automated analysis where the central server automatically receives, analyzes, and classifies malware objects without requiring human intervention for each object. The server applies algorithms and heuristics to autonomously determine whether objects are malware, eliminating the time-consuming manual analysis process while maintaining rapid detection capabilities.
Solution Approach 2:
The patent replaces the mechanical process of human analysis with automated computational algorithms. The central server uses automated scanning, pattern recognition, and classification algorithms to analyze malware objects, substituting human intellectual labor with machine-based automated systems that operate continuously without fatigue or delay.
2Measurement precision
If human analysts investigate each new object thoroughly, then classification accuracy is improved, but the volume of new objects daily makes it unrealistic to have skilled human analysts investigate each object
Solution Approach 1:
The system segments the analysis process into multiple stages: automated preliminary analysis filters out clearly benign objects, automated detection algorithms identify obvious malware, and only suspicious cases requiring nuanced judgment are escalated to human analysts. This segmentation allows the system to handle high volumes of objects while maintaining accuracy for critical cases.
Solution Approach 2:
The patent introduces automated analysis algorithms and heuristics as intermediaries between the incoming malware objects and human analysts. These intermediary systems perform initial screening and classification, reducing the burden on human analysts to every object while maintaining high accuracy through multiple layers of automated detection before human review.
3Reliability
If the central server receives and stores vast amounts of data from remote computers, then detection capabilities are improved, but data communication and management become challenging
Solution Approach 1:
The system extracts only the essential and relevant data from remote computers that are necessary for malware detection, rather than transmitting and storing all possible data. The central server receives specific object information, behavior data, and malware indicators, filtering out redundant information to reduce data management complexity while maintaining detection reliability.
Solution Approach 2:
Instead of the central server actively collecting and managing vast amounts of data from all remote computers, the system inverts the approach by having remote computers send only specific, pre-processed malware-related information to the central server. This reversal reduces the data management burden on the central server while maintaining comprehensive detection capabilities across the network.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one aspect, a method of classifying a computer object as malware includes at a base computer (3), receiving data about a computer object from each of plural remote computers (2) on which the object or similar objects are stored and or processed. The base computer (3) comprises plural threat servers (62) arranged to receive said data from the plural remote computers (2) and apply rules and or heuristics against that data in real time to determine whether or not said object is malware and to communicate said determination to the remote computers (2). The base computer (3) comprises at least one central server (74) in communication with the threat servers (62) and arranged to receive said data about objects from the threat servers (62) to maintain a master database (71,72,73) of data received about objects from all of the threat servers (62).