Contextual Data Scanning for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for scanning data for malware and restricted content are inadequate as they rely on static blacklists, which can be easily circumvented by attackers who change their Uniform Resource Identifiers (URIs) frequently, and do not effectively utilize contextual information associated with the data, address, source, or sender.
Innovation Solution
The proposed solution involves attaching contextual information to data as it passes through computing devices, which is then scanned to identify target data and communicate with a central repository for analysis, allowing for the identification of malware and restricted content by correlating this information with stored patterns and policies, thereby enhancing the detection of malicious or unauthorized content transfers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If static blacklist scanning is used to detect malware, then the scanning process is simple and fast, but the detection accuracy deteriorates because attackers can easily circumvent by changing URIs
Solution Approach 1:
The patent transitions from static blacklist scanning to dynamic contextual scanning. The system attaches contextual information to data as it passes through computing devices and uses this dynamic information to identify target data, allowing the scanning mechanism to adapt to changing attacker behaviors while maintaining scanning efficiency
Solution Approach 2:
The patent introduces contextual information as an intermediary element between the scanning facility and the data being scanned. This contextual information, which includes patterns from multiple client requests and source characteristics, serves as a mediator that enhances detection accuracy without significantly impacting scanning speed
2Measurement precision
If contextual information is attached to and scanned with data, then the detection accuracy improves, but the device complexity increases due to additional scanning components and data processing
Solution Approach 1:
The patent merges the contextual information scanning with the existing data scanning process. Rather than creating separate scanning systems, the contextual information is attached to data and scanned together through the existing scanning facility, reducing overall system complexity while improving detection accuracy
Solution Approach 2:
The scanning facility is designed to handle both regular data scanning and contextual information scanning through a unified mechanism. This multi-functional approach allows the same scanning infrastructure to serve multiple purposes, avoiding the need for additional complex components
3Measurement precision
If contextual information from multiple client requests is analyzed, then the ability to identify target sources improves, but the loss of time increases due to additional analysis steps
Solution Approach 1:
The patent performs preliminary actions by attaching contextual information to data as it passes through computing devices before the actual scanning occurs. This pre-processing of contextual information allows for more efficient analysis during scanning, reducing the time penalty that would otherwise be incurred
Data Source
AI summary
In embodiments of the present invention improved capabilities are described for contextual information caused to be attached to data as it passes through a series of computing devices, the contextual information relating to the series of computing devices. The data and the contextual information may then be scanned to determine if the data is a target data. In response to the identification of a target data, the contextual information may be communicated to a central repository. The contextual information may then be analyzed in relation to other information stored in the central repository to determine a target source.


