Endpoint Security Malware Detection and Data Logging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security and antivirus software often fail to provide comprehensive information about security breaches, leaving users uncertain about the extent of malware impacts and lacking in remedial actions.

Innovation Solution

A system and method for reporting security vulnerabilities by detecting malware presence, determining the duration of its presence, logging accessed sensitive data items, and conditionally performing security actions based on the duration and access, to inform users about potential compromises and recommend remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If security software detects and removes malware quickly, then response speed is improved, but users are left without comprehensive information about the extent of the security breach and compromised data

Engineering Contradiction:
Improvemalware detection and removal speedVSAvoidinformation about compromised data
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The system performs preliminary actions by logging sensitive data items accessed during the malware's presence window before the malware is removed. This allows the system to capture information about compromised data while the malware is still present, ensuring both quick removal and comprehensive reporting.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by providing users with detailed information about the security breach, including the list of compromised sensitive data items, the duration of malware presence, and specific remedial actions they should take. This closes the information gap created by rapid malware removal.

Inventive Principle:
Principle #23Feedback

2Loss of information

If security software provides detailed information about security breaches, then user awareness is improved, but the complexity of the security system increases

Engineering Contradiction:
Improveinformation completeness about breachVSAvoidsecurity system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the security reporting function into distinct components: malware detection, time window determination, sensitive data access logging, and conditional reporting. This modular approach provides comprehensive information while managing system complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary logging of sensitive data accesses during the malware's presence window, so that when reporting is needed, the information is already captured and organized. This reduces the complexity of real-time analysis while maintaining information completeness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the system logs all sensitive data accesses during malware presence, then reporting accuracy is improved, but the amount of data to be processed and reported increases

Engineering Contradiction:
Improvebreach assessment accuracyVSAvoiddata volume to process
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system applies local quality by focusing logging efforts specifically on sensitive data items during the malware's presence window, rather than logging all system activities. This concentrates data collection on high-value targets, improving breach assessment accuracy while limiting data volume to what is truly relevant.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses partial action by logging only the specific sensitive data items accessed during the malware's presence window, rather than comprehensively logging all system activities. This provides sufficient information for accurate breach assessment without the overhead of exhaustive data collection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9323930B1Systems and methods for reporting security vulnerabilities
Publication Date: 2016.04.26 CA TECH INC
  • US9323930B1 patent drawing
  • US9323930B1 patent drawing
  • US9323930B1 patent drawing

AI summary

A computer-implemented method for reporting security vulnerabilities may include (1) detecting that a malware application is present on an endpoint computing system, (2) determining a window of time during which the malware application was present in a specified condition on the endpoint computing system, (3) logging a list of sensitive data items accessed during the window of time, and (4) conditioning performance of a security action to report the list of sensitive data items on a determination that both (A) a length of the window of time is longer than a security threshold length and is indicative of the malware application being located on the endpoint computing system long enough to potentially compromise a sensitive data item and (B) the malware application was accessed during the window of time. Various other methods, systems, and computer-readable media are also disclosed.