Dynamic Remote Malware Scanning via Susceptible Data Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional remote malware scanning techniques require uploading entire files over networks, leading to significant traffic and bandwidth issues, and rely on static mechanisms that can be compromised by malicious entities, compromising security and reliability.
Innovation Solution
Dynamic remote malware scanning involves generating scanning objects based on a dynamic configuration that focuses on malware-susceptible data, creating a signature, and sending the object for scanning only if it doesn't match a previously identified signature, thereby reducing data transmission and using flexible mechanisms to evade static detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If entire files are uploaded for remote malware scanning, then scanning completeness is improved, but network traffic and bandwidth consumption increase significantly
Solution Approach 1:
The patent extracts only the essential scanning data from the entire file, separating malware-susceptible data from malware-insusceptible data. By taking out only the relevant portions for scanning, the system reduces network traffic while maintaining scanning effectiveness, as the extracted data contains sufficient information for malware detection without requiring transmission of the complete file.
Solution Approach 2:
The patent segments the file into malware-susceptible data and malware-insusceptible data, then transmits only the susceptible portions to the scanning engine. This segmentation allows the system to divide the scanning task into manageable parts, reducing the data volume over the network while preserving the ability to detect malware in the critical sections.
2Ease of manufacture
If static mechanisms are used for remote malware scanning, then implementation simplicity is improved, but security and reliability are compromised due to spiability by malicious entities
Solution Approach 1:
The patent introduces dynamic configuration mechanisms that allow the scanning system to adapt its behavior based on runtime conditions. The dynamic configuration enables the system to change scanning parameters, data selection criteria, and processing logic based on the specific file characteristics and threat landscape, making it resistant to static analysis by malicious entities while maintaining operational simplicity through automated adaptation.
Solution Approach 2:
The patent changes key parameters of the scanning process dynamically, including the selection of data portions to scan, the scanning methods applied, and the configuration of scanning engines based on file type, size, and detected characteristics. These parameter changes prevent predictable patterns that could be exploited by malware authors while keeping the system manageable through structured configuration options.
3Extent of automation
If sequential communication is used for remote malware scanning, then processing intelligence location is improved, but scanning speed decreases due to sequential transfer of file portions
Solution Approach 1:
The patent performs preliminary actions by pre-identifying and pre-selecting malware-susceptible data portions before the actual scanning process. This preliminary data selection and preparation allows the system to transmit only essential data to the remote scanning engine, reducing the sequential transfer time and enabling faster scanning while maintaining centralized processing intelligence.
Solution Approach 2:
The patent applies partial action by transmitting only the necessary portions of data for scanning rather than the entire file. This partial transmission approach reduces the time required for data transfer and processing, thereby increasing scanning speed while the scanning engine maintains full processing capability on the received data portions.
Data Source
AI summary
There are provided measures for enabling dynamic remote malware scanning. Such measures could exemplarily include identification of an electronic file to be scanned for malware, generation of at least one scanning object of the identified electronic file on the basis of a dynamic configuration by a remote entity, said at least one scanning object being generated by using malware-susceptible data of the identified electronic file and neglecting malware-insusceptible data of the identified electronic file, transfer of the at least one scanning object of the identified electronic file for remote malware scanning to the remote entity, and execution of a malware scan of the at least one scanning object of the electronic file at the remote entity by a malware scanning engine or application.


