Exploit Detection via Grouped Software Profile Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods fail to efficiently detect if initial content, such as websites or email attachments, serves exploits to target devices, making it difficult to protect devices from malicious payloads and vulnerabilities.
Innovation Solution
A method and apparatus that compare the connections and content received by groups of target devices with similar software profiles but appearing as having different profiles, allowing for the detection of exploits by identifying additional connections or content transmitted due to exposure to similar initial content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current detection methods are used, then device protection is provided, but detection efficiency and accuracy are insufficient leading to high false positive rates
Solution Approach 1:
The detection system segments target devices into multiple groups based on their software profiles (operating system, browser, plugins, etc.). Each group is analyzed separately by comparing their connections and content after exposure to initial content, allowing for more precise detection while maintaining efficiency through grouped analysis rather than individual device evaluation.
2Measurement precision
If software profiles are modified to appear different, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The system creates virtual copies of software profiles by modifying version numbers and characteristics to represent different device configurations. These profile copies are used to simulate various device scenarios without requiring physical test devices, simplifying the overall system while improving detection accuracy through controlled profile variations.
Data Source
AI summary
Methods and apparatus are disclosed for detecting if a source of initial content is serving exploits to a target device exposed to initial content. The method includes selecting at least two target devices and dividing the selected target devices into at least two groups, and causing the at least two groups to appear towards the initial content as having different software profiles towards the initial content. Information is obtained regarding at least one of connections and content transmitted/received by the at least two groups as a result of exposure to the initial content. The obtained information between the at least two groups is compared. If the comparison indicates that target devices in one of the at least two groups transmit/receive at least one of additional connections and additional content due to being exposed to the initial content, deciding that a source of the initial content serves exploits.


