Emergency Security Operations for Malware Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users often struggle to effectively respond to malware infections on their devices, as existing security measures are inadequate in preventing further damage and propagation of malware, and there is a lack of immediate solutions for home users without IT support.
Innovation Solution
A system and method for invoking emergency operations that include initiation features such as tray applications, hardware buttons, or key sequences, which trigger security actions like changing whitelists, terminating programs, setting firewall restrictions, capturing logfiles, and transmitting them to a security server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users reboot their device to remove malware, then the device restarts, but the malware persists because it invades startup files
Solution Approach 1:
The system performs preliminary actions by capturing logfiles and transmitting malware information to a server before the user reboots the device. This ensures that even if the malware persists after reboot, the critical data has already been secured and transmitted for analysis and removal.
2Reliability
If users completely shut down their computer and contact IT personnel, then professional help is obtained, but the user loses memory of what happened by the time IT personnel access the device
Solution Approach 1:
The system performs preliminary actions by automatically capturing logfiles and transmitting malware information to a server before the user shuts down the device. This preserves critical information about the malware infection, ensuring that IT personnel receive comprehensive data even if the user's memory fades over time.
Solution Approach 2:
The system introduces an intermediary component (the security software and server) that captures and transmits malware information independently of human memory. This intermediary ensures that critical data is preserved and transmitted accurately, bridging the gap between the user's initial observation and the IT personnel's later analysis.
3Reliability
If anti-malware software uses whitelists to block unauthorized programs, then security is improved, but users must constantly update whitelists to include new legitimate programs
Solution Approach 1:
The system applies self-service by automatically managing whitelist updates and security configurations. The security software monitors for new legitimate programs and updates the whitelist without requiring manual user intervention, thereby maintaining high security while eliminating the burden of constant manual updates.
4Reliability
If the system transmits logfile information to a security server, then malware analysis capability is improved, but network communication requirements increase
Solution Approach 1:
The system extracts the complex malware analysis functionality from the user's device and relocates it to a remote security server. The device only needs to transmit logfile information, while the heavy lifting of analysis is performed on the server, reducing the network communication requirements at the user end while maintaining high analysis accuracy.
Data Source
AI summary
A system and method for invoking the emergency operations includes an initiation feature such as an application in the user's tray, an application on the user's home screen, a hardware button, a specific key sequence (e.g., Fn-V for virus), or other device input that is likely not to be invoked by mistake. Once invoked, one or more security actions are taken to prevent or reduce harm from potential malware. These actions include some or all of using a more secure whitelist, terminating running programs that are not on the whitelist (e.g., a global whitelist), setting of a firewall to restrict communications, capturing certain logfile information and transmitting this information to a security server, setting the firewall to only allow access by certain IP addresses, and blocking and/or terminating certain other programs.


