Endpoint Malicious Code Mitigation via Targeted Scanning Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus systems lack an efficient method for identifying and mitigating malicious codes across computer systems, often resulting in false positives and requiring individual scanning processes that are not tailored to specific endpoints, leading to ineffective data collection and communication bandwidth issues.

Innovation Solution

A system where a first malicious code pattern is used to scan a computer, with results forwarded to a support server that provides an aggressive pattern for initial scanning, followed by targeted updates based on collected data to identify and mitigate specific malicious codes, using a state repository to manage scanning events and deliver tailored mitigations to affected endpoint computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual scanning processes are performed on each computer using generic antivirus patterns, then comprehensive coverage is achieved, but false positives increase and detection precision decreases

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by transitioning from generic antivirus patterns to computer-specific malicious code patterns. Each endpoint receives tailored scanning patterns based on its identified infections, improving detection accuracy while reducing false positives. The state repository tracks individual computer infection histories to generate customized pattern sets for each endpoint.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary scanning with aggressive patterns to identify potential infections before deploying targeted mitigations. This preliminary action allows the support server to analyze scan results, identify specific malicious codes, and then provide customized pattern updates to affected endpoints, improving subsequent detection precision.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive scanning is performed on all computers using updated malicious code patterns, then detection coverage is improved, but communication bandwidth consumption increases

Engineering Contradiction:
Improvedetection coverageVSAvoidcommunication bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts and targets only the specific malicious codes identified in each endpoint's scan results. Instead of distributing comprehensive pattern updates to all computers, the support server sends customized pattern sets containing only the mitigations relevant to each endpoint's identified infections, significantly reducing communication bandwidth consumption while maintaining detection coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the antivirus update process by computer and infection type. The state repository divides the overall scanning task into individual computer-specific tasks, allowing the support server to generate and distribute customized pattern updates to each endpoint based on its specific infection profile, rather than broadcasting updates to all computers.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If generic antivirus response actions are executed on all computers, then standardized mitigation is achieved, but adaptability to specific endpoint infections decreases

Engineering Contradiction:
Improvemitigation standardizationVSAvoidendpoint-specific customization
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making the antivirus response adaptive rather than static. The support server dynamically generates customized malicious code patterns based on each endpoint's scan results and infection history stored in the state repository. This allows the system to maintain standardized mitigation processes while adapting the specific patterns to each endpoint's unique infection profile.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback from endpoint scan results to continuously improve and customize mitigations. The support server receives scan results from endpoints, analyzes them to identify specific malicious codes, and then provides customized pattern updates back to the endpoints. This feedback loop enables standardized processes to produce customized solutions for each endpoint's specific infections.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9544328B1Methods and apparatus for providing mitigations to particular computers
Publication Date: 2017.01.10 TREND MICRO INC
  • US9544328B1 patent drawing
  • US9544328B1 patent drawing
  • US9544328B1 patent drawing

AI summary

Mitigation for combating malicious codes is delivered to particular endpoint computers. A first malicious code pattern is received in a first computer over a computer network. The first computer is scanned using the first malicious code pattern, with the result of the scanning forwarded to a second computer. The first computer is identified as having a file scanned using the first malicious code pattern. In response, the first computer is provided a second malicious code pattern. The first computer is scanned for malicious codes using the second malicious code pattern.