Context-Driven Behavioral Heuristics for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security solutions are largely reactive and struggle to detect and remove new, unknown threats without incorrectly identifying innocent files, leading to a need for improved methods to detect unwanted data like malware and spyware.

Innovation Solution

A system and method that performs a scan to generate results, identifies the context of the scan, and conditionally indicates the presence of unwanted data by combining scan results with contextual information, using heuristic signatures and behavioral monitoring to improve detection reliability and reduce false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions use reactive detection methods with fixed signatures, then detection accuracy for known threats is maintained, but the ability to detect new unknown threats is poor and false positives increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoiddetection adaptability to new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic heuristic signatures that can adapt to new threat patterns without requiring manual signature updates. The system dynamically adjusts detection parameters based on behavioral context and threat intelligence, enabling proactive detection of unknown threats while maintaining accuracy through contextual filtering

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops that analyze scan results and contextual information to refine detection accuracy. By continuously learning from scan outcomes and adjusting heuristic application based on contextual feedback, the system reduces false positives while improving detection of new threats

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If heuristic signatures are expanded to detect more threat variants, then detection coverage increases, but false detections of benign files increase

Engineering Contradiction:
Improveheuristic detection coverageVSAvoidfalse detection rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by tailoring heuristic application to specific contextual environments. Different heuristics are weighted and applied differently based on the operational context (e.g., network scan vs. file system scan), allowing expanded heuristic coverage in high-risk areas while maintaining stricter filtering in low-risk contexts to reduce false positives

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces contextual information as an intermediary layer between raw scan results and final detection decisions. This contextual intermediary filters and refines heuristic matches, allowing broader heuristic coverage while using context as a mediator to eliminate false detections before final reporting

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If scan results are analyzed in isolation without context, then scanning speed is maintained, but detection accuracy for new threats is insufficient

Engineering Contradiction:
Improvescanning speedVSAvoiddetection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary contextual analysis before final detection decisions. By pre-establishing contextual frameworks and preparing contextual filters in advance, the system can quickly integrate context with scan results without significant speed penalty, improving detection precision while maintaining productivity through efficient contextual preparation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7917955B1System, method and computer program product for context-driven behavioral heuristics
Publication Date: 2011.03.29 MCAFEE LLC
  • US7917955B1 patent drawing
  • US7917955B1 patent drawing
  • US7917955B1 patent drawing

AI summary

A system, method and computer program product are provided for detecting unwanted data. A scan for unwanted data is performed to generate results of the scan. A context of the scan is then identified. Further, the presence of unwanted data is conditionally indicated based on both the results of the scan and the context of the scan.