Electronic Apparatus DNS Malware Detection and Automated Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection systems burden users with manual countermeasures after infection detection, lacking automated and efficient response mechanisms.

Innovation Solution

An electronic apparatus detects malware intrusion via DNS name resolution errors, automatically rebooting and implementing setting changes such as altering detection thresholds, blocking port transmissions, disabling wireless or wired communication, or a combination thereof.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automated countermeasures are implemented, then user burden is reduced and detection efficiency is improved, but device complexity increases

Engineering Contradiction:
Improveuser burdenVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs self-diagnosis and self-repair by automatically detecting malware intrusion through DNS name resolution errors and executing countermeasures such as rebooting and changing settings without requiring user intervention. This self-service mechanism reduces the burden on users while managing the complexity internally.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures detection thresholds, monitoring periods, and countermeasure protocols before malware intrusion occurs. By preparing detection criteria and response actions in advance, the system can rapidly respond to infections without complex real-time decision-making, thus reducing operational complexity during actual threats.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated countermeasures are implemented, then malware detection efficiency is improved, but device complexity increases

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system continuously monitors DNS name resolution errors in real-time, maintaining persistent detection activity without interruption. This continuous monitoring enables rapid detection and response to malware intrusion, improving productivity while using efficient, streamlined detection mechanisms rather than complex intermittent analysis.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system replaces manual user-based detection and response mechanisms with automated software-based detection through DNS packet analysis. This substitution of mechanical (manual) operations with automated digital processes improves detection efficiency while keeping the system architecture relatively simple and maintainable.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If multiple countermeasures are executed, then malware prevention is improved, but loss of time increases

Engineering Contradiction:
Improvemalware preventionVSAvoidcountermeasure execution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes multiple countermeasure protocols and configuration settings before malware intrusion occurs. When intrusion is detected, these pre-prepared measures can be executed immediately without time-consuming configuration or decision processes, thus achieving reliable prevention with minimal time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system executes countermeasures in periodic cycles, monitoring for malware intrusion and applying corrective actions at predetermined intervals or upon detection triggers. This periodic execution pattern ensures comprehensive coverage and reliable prevention while optimizing execution timing to minimize overall time loss compared to continuous or reactive approaches.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250267167A1Electronic apparatus, control method, and non-transitory computer-readable storage medium storing program
Publication Date: 2025.08.21 SEIKO EPSON CORP
  • US20250267167A1 patent drawing
  • US20250267167A1 patent drawing
  • US20250267167A1 patent drawing

AI summary

An electronic apparatus includes: a detector configured to detect intrusion of malware into the electronic apparatus by detecting a name resolution error that occurs for a DNS packet transmitted from the electronic apparatus; and a countermeasure execution unit configured to reboot the electronic apparatus and execute a setting change of the electronic apparatus when intrusion of malware is detected. In the setting change, at least one of the following is performed: (1) changing at least one of a detection period for occurrence of the name resolution error and a threshold for the number of occurrences of the name resolution error for determining intrusion of malware; (2) blocking packet transmission to a predetermined port; (3) disabling wireless communication; and (4) disabling wired communication.