Host Intrusion Prevention via Behavioral Phenotype Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing behavioral monitoring systems for malware detection struggle to differentiate between minor events and definitive malicious activity, leading to challenges in remediation and false positives, as they are limited in their ability to identify and address known classes of malware effectively.

Innovation Solution

A behavioral-based host-intrusion prevention method and system that monitors user interactions and code processes, using 'behavioral genes' and 'code genes' to identify phenotypes indicative of malicious activity, allowing for targeted intrusion prevention actions such as isolating systems, reverting software states, and disconnecting devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing behavioral monitoring systems use a database of blacklisted actions to identify malicious processes, then malware detection capability is improved, but false positives increase and differentiation between minor events and definitive malicious activity deteriorates

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddifferentiation between minor events and malicious activity
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent combines multiple behavioral indicators (user behavior analysis, code operation analysis, and system state changes) into a composite phenotype assessment. Instead of relying on a single blacklisted action database, the system integrates multiple data sources to form a comprehensive view of malicious activity, thereby improving detection reliability while reducing false positives through multi-factor verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates composite behavioral phenotypes by combining different types of behavioral data (user interactions, code operations, system state modifications) into unified malicious activity profiles. This composite approach allows the system to distinguish between minor events and definitive malicious activity by evaluating the combination of behaviors rather than isolated actions.

Inventive Principle:
Principle #40Composite materials

2Object-affected harmful factors

If behavioral monitoring systems terminate processes based on blacklisted actions, then protection against malicious activity is improved, but remediation capability deteriorates as other potential files remain untouched

Engineering Contradiction:
Improveprotection against malicious activityVSAvoidremediation capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The system performs preliminary identification and classification of malicious behaviors by analyzing phenotypes before taking remediation actions. By预先 identifying all components of a malicious activity pattern (including associated files, registry keys, and system state changes), the system can subsequently remediate all affected elements systematically rather than just terminating the visible malicious process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments malicious activity into distinct phenotypic components (user behavior patterns, code operation sequences, system state modifications). This segmentation allows the remediation system to address each component individually and systematically, ensuring that all malicious elements are removed rather than just the primary offending process.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If existing systems use exception lists for known processes to avoid false positives, then false positive rate is reduced, but detection precision for new malware deteriorates

Engineering Contradiction:
Improvefalse positive reductionVSAvoiddetection precision for new malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system transitions from static exception lists to dynamic phenotype-based detection that adapts to new malware patterns. By continuously analyzing behavioral patterns and updating phenotype databases with newly discovered malicious behaviors, the system maintains low false positive rates for known processes while simultaneously improving detection precision for novel malware through learned behavioral patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8607340B2Host intrusion prevention system using software and user behavior analysis
Publication Date: 2013.12.10 SOPHOS LTD
  • US8607340B2 patent drawing
  • US8607340B2 patent drawing
  • US8607340B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for threat detection using a behavioral-based host-intrusion prevention method and system for monitoring a user interaction with a computer, software application, operating system, graphic user interface, or some other component or client of a computer network, and performing an action to protect the computer network based at least in part on the user interaction and a computer code process executing during or in association with a computer usage session.