Forensic Image Scanning with Multiple Malware Engines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection systems face challenges in detecting malicious code infections due to obfuscation techniques and limited knowledge of emerging viruses, and they cannot be installed simultaneously on a computer system, leading to ineffective scanning and potential missed infections.

Innovation Solution

A method and system that allows for simultaneous scanning of a forensic image of a computer system with multiple commercial and open-source malware detection engines from a master control point dashboard, enabling the use of an unlimited number of detection engines to identify both valid and deleted files, thereby increasing detection effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple malware detection engines are installed simultaneously on a computer system, then detection effectiveness and coverage are improved, but system conflicts and compatibility issues occur

Engineering Contradiction:
Improvemalware detection effectivenessVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a forensic copy (bit-by-bit image) of the original storage device, allowing multiple malware engines to scan the copy simultaneously without conflicts. This copying approach enables parallel scanning with unlimited engines while preserving the original system integrity and avoiding the conflicts that would arise from installing multiple engines on the same live system.

Inventive Principle:
Principle #26Copying

2Reliability

If a single malware detection product is installed on a computer system, then system stability is maintained, but detection coverage is limited

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By creating a forensic image copy of the storage device, the system enables multiple malware detection engines to operate simultaneously on the copy without affecting the original system configuration. This approach achieves comprehensive detection coverage using multiple vendors' engines while maintaining system stability, as the engines scan the static image rather than competing for control of the live file system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transitions from a single-dimension approach (one engine on live system) to a multi-dimensional approach by separating the scanning operation from the original system. The forensic image creates an additional dimension where multiple engines can operate in parallel, achieving both comprehensive coverage and system stability simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If sequential scanning with multiple malware products is performed, then system stability is maintained, but scanning time increases

Engineering Contradiction:
Improvescanning speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the scanning operation by creating separate virtual machine environments, each hosting a different malware detection engine. This segmentation allows all engines to scan the forensic image simultaneously in parallel rather than sequentially, dramatically reducing total scanning time while maintaining detection accuracy through the combined results of multiple independent engines.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The forensic image copy serves as a shared resource that multiple virtual machines can access simultaneously. This copying approach enables parallel scanning operations without the time penalties of sequential execution, as each engine independently analyzes the same image data at the same time, achieving both speed and accuracy.

Inventive Principle:
Principle #26Copying

4Productivity

If multiple malware detection engines are run simultaneously on the same system, then scanning time is reduced, but system conflicts occur

Engineering Contradiction:
Improvescanning efficiencyVSAvoidsystem interference
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent uses a forensic image copy as the scanning target, which eliminates system interference and conflicts that would occur with simultaneous multi-engine scanning on a live system. The static image file can be accessed by multiple engines in parallel without resource contention, file locking issues, or interference with running processes, achieving high scanning efficiency without harmful side effects.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The forensic image acts as an intermediary between the multiple malware engines and the original system. It mediates the scanning process by providing a stable, conflict-free target that can be simultaneously accessed by multiple engines, preventing direct interference between engines and the live system while maintaining scanning efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11354414B2Method to scan a forensic image of a computer system with multiple malicious code detection engines simultaneously from a master control point
Publication Date: 2022.06.07 FORENSIC SCAN LLC
  • US11354414B2 patent drawing
  • US11354414B2 patent drawing
  • US11354414B2 patent drawing

AI summary

A multi-engine malicious code scanning method for scanning data sets from a storage device is provided. The method includes, among other steps obtaining at least one data set from a storage device and generating a single forensic image of the data set and also applying a recover data application to the data set to generate a single recovered data set. A scanning is initiated of the single forensic image and the single recovered data set using the selected plurality of malware engines, where each of the malware engines, installed on the independent operating systems of the virtual operating system may be run concurrently on the single forensic image and the single recovered data set. A report is generated combining each of the malware engines reporting the results of the scans.