Dynamic Anti-Malware Signature Selection and Loading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-malware solutions face challenges in efficiently selecting and loading relevant malware detection signatures across networked computer systems, leading to increased storage requirements and potential threats from irrelevant signatures.

Innovation Solution

An anti-malware system with a dynamic signature loader and selector component that determines and loads only relevant signatures based on multiple data sources, including local and global threat data, machine configurations, and network detections, ensuring that signatures are updated automatically and efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all known threat signatures are loaded, then protection coverage is improved, but storage space requirements increase

Engineering Contradiction:
Improveprotection coverageVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent divides the complete malware signature database into multiple subsets, each tailored to specific machine types, operating systems, and threat scenarios. Instead of loading all signatures uniformly, the system segments them according to relevance criteria such as machine architecture, OS version, and detected threat patterns, allowing selective loading of only necessary signature subsets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts which signature subsets are loaded based on real-time conditions including detected threats, machine configuration changes, and network environment. The signature loading is not static but adapts continuously to current security needs, loading additional signatures when threats are detected and unloading less relevant ones when threats subside.

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If a fixed subset of signatures is used, then storage space is reduced, but protection coverage deteriorates

Engineering Contradiction:
Improvestorage spaceVSAvoidprotection coverage
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system transforms the static fixed subset approach into a dynamic adaptive system that automatically adjusts signature loading based on current security conditions. When new threats are detected or machine configurations change, the system dynamically loads additional relevant signatures, ensuring protection coverage evolves with emerging threats rather than remaining static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms that monitor detected threats, machine configurations, and security events, using this information to determine which additional signature subsets should be loaded. This feedback loop ensures that protection coverage is expanded automatically when security conditions warrant it, while maintaining storage efficiency when threats are minimal.

Inventive Principle:
Principle #23Feedback

3Reliability

If signatures for all potential network threats are loaded, then network-wide protection is improved, but storage and distribution complexity increase

Engineering Contradiction:
Improvenetwork-wide protectionVSAvoidsignature distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network protection task by creating machine-specific and threat-specific signature subsets. Instead of distributing complete signature databases to all machines, the system segments signatures according to machine types, network roles, and threat relevance, distributing only the necessary subsets to each machine thereby reducing distribution complexity while maintaining network-wide protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by tailoring signature subsets to specific machine characteristics, network positions, and local threat conditions. Each machine receives customized signature subsets appropriate to its specific context rather than a universal set, optimizing both protection effectiveness and distribution efficiency for each local environment.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2920737B1Dynamic selection and loading of Anti-malware signatures
Publication Date: 2019.07.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2920737B1 patent drawingFigure 1
  • EP2920737B1 patent drawingFigure 2
  • EP2920737B1 patent drawingFigure 3

AI summary

An anti-malware system dynamically loads and unloads additional malware detection signatures based on a collection of data sources that indicate what signatures are relevant to a host machine in its current environment. A signature selector component determines what relevant signatures should be loaded. The signature selector component uses a variety of data sources either individually, or in combination, to determine relevancy of the available malware detection signatures. The anti-malware system dynamically determines which of the available malware detection signatures and classes of signatures are relevant and should be provided to a machine based on available information. The malware detection signatures are obtained and loaded automatically from one or more sources when a threat becomes relevant. A program or application may be blocked from accessing files until the relevant malware detection signatures have been loaded onto the machine.