Endpoint Malicious Code Mitigation via Targeted Scanning Patterns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus systems lack an efficient method for identifying and mitigating malicious codes across computer systems, often resulting in false positives and requiring individual scanning processes that are not tailored to specific endpoints, leading to ineffective data collection and communication bandwidth issues.
Innovation Solution
A system where a first malicious code pattern is used to scan a computer, with results forwarded to a support server that provides an aggressive pattern for initial scanning, followed by targeted updates based on collected data to identify and mitigate specific malicious codes, using a state repository to manage scanning events and deliver tailored mitigations to affected endpoint computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual scanning processes are performed on each computer using generic antivirus patterns, then comprehensive coverage is achieved, but false positives increase and detection precision decreases
Solution Approach 1:
The patent applies local quality by transitioning from generic antivirus patterns to computer-specific malicious code patterns. Each endpoint receives tailored scanning patterns based on its identified infections, improving detection accuracy while reducing false positives. The state repository tracks individual computer infection histories to generate customized pattern sets for each endpoint.
Solution Approach 2:
The system performs preliminary scanning with aggressive patterns to identify potential infections before deploying targeted mitigations. This preliminary action allows the support server to analyze scan results, identify specific malicious codes, and then provide customized pattern updates to affected endpoints, improving subsequent detection precision.
2Reliability
If comprehensive scanning is performed on all computers using updated malicious code patterns, then detection coverage is improved, but communication bandwidth consumption increases
Solution Approach 1:
The patent extracts and targets only the specific malicious codes identified in each endpoint's scan results. Instead of distributing comprehensive pattern updates to all computers, the support server sends customized pattern sets containing only the mitigations relevant to each endpoint's identified infections, significantly reducing communication bandwidth consumption while maintaining detection coverage.
Solution Approach 2:
The system segments the antivirus update process by computer and infection type. The state repository divides the overall scanning task into individual computer-specific tasks, allowing the support server to generate and distribute customized pattern updates to each endpoint based on its specific infection profile, rather than broadcasting updates to all computers.
3Ease of manufacture
If generic antivirus response actions are executed on all computers, then standardized mitigation is achieved, but adaptability to specific endpoint infections decreases
Solution Approach 1:
The patent implements dynamics by making the antivirus response adaptive rather than static. The support server dynamically generates customized malicious code patterns based on each endpoint's scan results and infection history stored in the state repository. This allows the system to maintain standardized mitigation processes while adapting the specific patterns to each endpoint's unique infection profile.
Solution Approach 2:
The system uses feedback from endpoint scan results to continuously improve and customize mitigations. The support server receives scan results from endpoints, analyzes them to identify specific malicious codes, and then provides customized pattern updates back to the endpoints. This feedback loop enables standardized processes to produce customized solutions for each endpoint's specific infections.
Data Source
AI summary
Mitigation for combating malicious codes is delivered to particular endpoint computers. A first malicious code pattern is received in a first computer over a computer network. The first computer is scanned using the first malicious code pattern, with the result of the scanning forwarded to a second computer. The first computer is identified as having a file scanned using the first malicious code pattern. In response, the first computer is provided a second malicious code pattern. The first computer is scanned for malicious codes using the second malicious code pattern.


