Exploit Detection via Grouped Software Profile Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to efficiently detect if initial content, such as websites or email attachments, serves exploits to target devices, making it difficult to protect devices from malicious payloads and vulnerabilities.

Innovation Solution

A method and apparatus that compare the connections and content received by groups of target devices with similar software profiles but appearing as having different profiles, allowing for the detection of exploits by identifying additional connections or content transmitted due to exposure to similar initial content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current detection methods are used, then device protection is provided, but detection efficiency and accuracy are insufficient leading to high false positive rates

Engineering Contradiction:
Improveexploit detection accuracyVSAvoiddetection efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The detection system segments target devices into multiple groups based on their software profiles (operating system, browser, plugins, etc.). Each group is analyzed separately by comparing their connections and content after exposure to initial content, allowing for more precise detection while maintaining efficiency through grouped analysis rather than individual device evaluation.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If software profiles are modified to appear different, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveprofile differentiation accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system creates virtual copies of software profiles by modifying version numbers and characteristics to represent different device configurations. These profile copies are used to simulate various device scenarios without requiring physical test devices, simplifying the overall system while improving detection accuracy through controlled profile variations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10360379B2Method and apparatus for detecting exploits
Publication Date: 2019.07.23 F SECURE CORP
  • US10360379B2 patent drawing
  • US10360379B2 patent drawing
  • US10360379B2 patent drawing

AI summary

Methods and apparatus are disclosed for detecting if a source of initial content is serving exploits to a target device exposed to initial content. The method includes selecting at least two target devices and dividing the selected target devices into at least two groups, and causing the at least two groups to appear towards the initial content as having different software profiles towards the initial content. Information is obtained regarding at least one of connections and content transmitted/received by the at least two groups as a result of exposure to the initial content. The obtained information between the at least two groups is compared. If the comparison indicates that target devices in one of the at least two groups transmit/receive at least one of additional connections and additional content due to being exposed to the initial content, deciding that a source of the initial content serves exploits.