Dynamic Malware Protection via Risk-Based Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contemporary anti-malware technologies face challenges in effectively protecting users from malware, particularly those who are not fully compliant with security measures or who inadvertently install infected executables, due to performance bottlenecks and user behavior, leading to incomplete scanning and increased vulnerability.
Innovation Solution
A dynamic protection system that computes a risk score based on user behavior, machine state, and threat conditions, allowing for variable protection levels by running applications as virtualized programs or in sandboxes, and adjusting network access to mitigate malware risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anti-malware software performs real-time scanning with full capability, then malware protection is improved, but system performance deteriorates due to CPU cycle consumption and creation of performance bottlenecks
Solution Approach 1:
The patent implements dynamic protection levels that adjust based on user risk profiles. High-risk users receive enhanced real-time scanning and virtualization protection, while low-risk users receive reduced protection to minimize performance impact. The system dynamically varies protection intensity according to individual user behavior patterns and threat conditions.
Solution Approach 2:
The patent applies different protection levels to different users based on their risk profiles. Instead of uniform protection for all users, the system tailors security measures to local user characteristics, providing intensive protection to high-risk users and minimal protection to low-risk users, thereby optimizing the balance between security and performance.
2Reliability
If anti-malware software scans all files and processes, then malware detection is improved, but user experience deteriorates due to file access locks and intrusive behavior
Solution Approach 1:
The system dynamically adjusts scanning intensity based on user risk profiles. Low-risk users experience minimal interruption as their files are scanned less frequently or not at all during normal operations. High-risk users undergo more thorough scanning when needed, with the system adapting scan frequency and depth to user behavior patterns and current threat conditions.
Solution Approach 2:
The patent implements differentiated scanning strategies for different user segments. Instead of uniformly scanning all files for all users, the system applies local quality control by providing intensive scanning to high-risk users and reduced scanning to low-risk users, thereby improving user experience for the majority while maintaining security where needed.
3Productivity
If users exclude processes and folders from scanning to improve performance, then system speed is improved, but malware protection deteriorates due to incomplete scanning
Solution Approach 1:
The system performs preliminary risk assessment of users by analyzing their behavior patterns, file access history, and interaction with known malicious content. Based on this preliminary analysis, users are classified into risk categories that determine their protection level, allowing the system to proactively adjust scanning coverage before malware infections occur.
Solution Approach 2:
The system continuously monitors user behavior and malware detection results, using this feedback to refine risk profiles and adjust protection levels. When users exhibit behaviors indicative of malware infection or when new threats are detected, the system updates risk assessments and modifies scanning coverage accordingly, creating a adaptive protection mechanism.
Data Source
AI summary
The subject disclosure is directed towards protecting against malware, by classifying a user's risk level, which corresponds to a likelihood of malware being activated. To make the classification, data is collected that represents a probability of encountering malware, a probability of a user activating that malware, and the impact to the machine is activated. The classification maps to a protection level, which may be dynamically adjustable, e.g., based upon current risk conditions. The protection level determines a way to mitigate possible damage, such as by running a program as a virtualized program, running a virtualized operating system, or sandboxing a process.


