Dynamic Remote Malware Scanning via Susceptible Data Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote malware scanning techniques require uploading entire files over networks, leading to significant traffic and bandwidth issues, and rely on static mechanisms that can be compromised by malicious entities, compromising security and reliability.

Innovation Solution

Dynamic remote malware scanning involves generating scanning objects based on a dynamic configuration that focuses on malware-susceptible data, creating a signature, and sending the object for scanning only if it doesn't match a previously identified signature, thereby reducing data transmission and using flexible mechanisms to evade static detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entire files are uploaded for remote malware scanning, then scanning completeness is improved, but network traffic and bandwidth consumption increase significantly

Engineering Contradiction:
Improvescanning completenessVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential scanning data from the entire file, separating malware-susceptible data from malware-insusceptible data. By taking out only the relevant portions for scanning, the system reduces network traffic while maintaining scanning effectiveness, as the extracted data contains sufficient information for malware detection without requiring transmission of the complete file.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the file into malware-susceptible data and malware-insusceptible data, then transmits only the susceptible portions to the scanning engine. This segmentation allows the system to divide the scanning task into manageable parts, reducing the data volume over the network while preserving the ability to detect malware in the critical sections.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If static mechanisms are used for remote malware scanning, then implementation simplicity is improved, but security and reliability are compromised due to spiability by malicious entities

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces dynamic configuration mechanisms that allow the scanning system to adapt its behavior based on runtime conditions. The dynamic configuration enables the system to change scanning parameters, data selection criteria, and processing logic based on the specific file characteristics and threat landscape, making it resistant to static analysis by malicious entities while maintaining operational simplicity through automated adaptation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key parameters of the scanning process dynamically, including the selection of data portions to scan, the scanning methods applied, and the configuration of scanning engines based on file type, size, and detected characteristics. These parameter changes prevent predictable patterns that could be exploited by malware authors while keeping the system manageable through structured configuration options.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If sequential communication is used for remote malware scanning, then processing intelligence location is improved, but scanning speed decreases due to sequential transfer of file portions

Engineering Contradiction:
Improveprocessing intelligence locationVSAvoidscanning speed
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The patent performs preliminary actions by pre-identifying and pre-selecting malware-susceptible data portions before the actual scanning process. This preliminary data selection and preparation allows the system to transmit only essential data to the remote scanning engine, reducing the sequential transfer time and enabling faster scanning while maintaining centralized processing intelligence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by transmitting only the necessary portions of data for scanning rather than the entire file. This partial transmission approach reduces the time required for data transfer and processing, thereby increasing scanning speed while the scanning engine maintains full processing capability on the received data portions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11032313B2Dynamic remote malware scanning
Publication Date: 2021.06.08 WITHSECURE CORP (A K A WITHSECURE OYJ)
  • US11032313B2 patent drawing
  • US11032313B2 patent drawing
  • US11032313B2 patent drawing

AI summary

There are provided measures for enabling dynamic remote malware scanning. Such measures could exemplarily include identification of an electronic file to be scanned for malware, generation of at least one scanning object of the identified electronic file on the basis of a dynamic configuration by a remote entity, said at least one scanning object being generated by using malware-susceptible data of the identified electronic file and neglecting malware-insusceptible data of the identified electronic file, transfer of the at least one scanning object of the identified electronic file for remote malware scanning to the remote entity, and execution of a malware scan of the at least one scanning object of the electronic file at the remote entity by a malware scanning engine or application.