Cloud Security File Behavior Sequence Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud security systems cannot determine the security information of unknown files without performing a security scan, and they lack efficient methods to handle the vast number of malicious files in networks where file security databases may not be updated timely.

Innovation Solution

A method and apparatus that receive file security querying information from a cloud client end, create a behavior sequence of the file within its lifecycle, analyze this sequence, and determine the file's security information, combining behavior and identifier information to assess the file's security level without requiring sample collection operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud security systems rely on traditional database querying methods, then known files can be identified quickly, but unknown files cannot be effectively analyzed

Engineering Contradiction:
Improvesecurity determination accuracyVSAvoidcapability to handle unknown files
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static database matching to dynamic behavior sequence analysis. By creating and analyzing behavior sequences that capture file execution patterns across multiple monitoring points, the system adapts to unknown files without requiring pre-existing database entries, thereby improving both reliability for unknown files and versatility in handling diverse file types

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the analysis parameters from fixed database signatures to dynamic behavior characteristics. By extracting behavior information at multiple monitoring points and sequencing these behaviors, the system transforms the approach from signature-based detection to pattern-based analysis, enabling effective identification of unknown files through their operational patterns

Inventive Principle:
Principle #35Parameter changes

2Reliability

If cloud security systems perform comprehensive security scans on all files, then security information can be determined accurately, but system efficiency and response time deteriorate

Engineering Contradiction:
Improvesecurity information accuracyVSAvoidfile processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs partial monitoring at multiple strategic points rather than comprehensive scanning. By placing monitoring points at key stages (pre-execution, execution, post-execution) and analyzing behavior sequences from these partial observations, the system achieves accurate security determination without the overhead of complete security scans, thereby maintaining both reliability and productivity

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary behavior collection at monitoring points before final security determination. By gathering behavior information in advance and creating behavior sequences for analysis, the system prepares security assessment data proactively, enabling faster and more accurate security decisions without requiring time-consuming comprehensive scans at the moment of determination

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cloud security databases are updated frequently to include new malicious files, then detection capability improves, but system complexity and maintenance burden increase

Engineering Contradiction:
Improvemalicious file detection capabilityVSAvoiddatabase update and maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service security analysis through behavior sequence patterns. Instead of relying on external database updates, the system autonomously analyzes file behaviors against established security patterns and monitoring point data. This self-service capability maintains detection reliability without requiring complex manual database updates, reducing maintenance burden while preserving detection effectiveness

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9166998B2Method and apparatus for determining security information of an unknown file in a cloud security system
Publication Date: 2015.10.20 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9166998B2 patent drawing
  • US9166998B2 patent drawing
  • US9166998B2 patent drawing

AI summary

A method for determining security information of an unknown file in a cloud security system is provided. The method includes: a cloud security serving end receives file security querying information reported by a cloud client end when a preconfigured monitoring point is triggered, wherein the file security querying information comprises identifier information and behavior information of a file; creates a behavior sequence of the file within a lifecycle according to the file security querying information of the file, analyzes the behavior sequence of the file within the lifecycle, and determines file security information of the file according to an analyzed result.