Host Intrusion Prevention via Behavioral Phenotype Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing behavioral monitoring systems for malware detection struggle to differentiate between minor events and definitive malicious activity, leading to challenges in remediation and false positives, as they are limited in their ability to identify and address known classes of malware effectively.
Innovation Solution
A behavioral-based host-intrusion prevention method and system that monitors user interactions and code processes, using 'behavioral genes' and 'code genes' to identify phenotypes indicative of malicious activity, allowing for targeted intrusion prevention actions such as isolating systems, reverting software states, and disconnecting devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing behavioral monitoring systems use a database of blacklisted actions to identify malicious processes, then malware detection capability is improved, but false positives increase and differentiation between minor events and definitive malicious activity deteriorates
Solution Approach 1:
The patent combines multiple behavioral indicators (user behavior analysis, code operation analysis, and system state changes) into a composite phenotype assessment. Instead of relying on a single blacklisted action database, the system integrates multiple data sources to form a comprehensive view of malicious activity, thereby improving detection reliability while reducing false positives through multi-factor verification.
Solution Approach 2:
The system creates composite behavioral phenotypes by combining different types of behavioral data (user interactions, code operations, system state modifications) into unified malicious activity profiles. This composite approach allows the system to distinguish between minor events and definitive malicious activity by evaluating the combination of behaviors rather than isolated actions.
2Object-affected harmful factors
If behavioral monitoring systems terminate processes based on blacklisted actions, then protection against malicious activity is improved, but remediation capability deteriorates as other potential files remain untouched
Solution Approach 1:
The system performs preliminary identification and classification of malicious behaviors by analyzing phenotypes before taking remediation actions. By预先 identifying all components of a malicious activity pattern (including associated files, registry keys, and system state changes), the system can subsequently remediate all affected elements systematically rather than just terminating the visible malicious process.
Solution Approach 2:
The patent segments malicious activity into distinct phenotypic components (user behavior patterns, code operation sequences, system state modifications). This segmentation allows the remediation system to address each component individually and systematically, ensuring that all malicious elements are removed rather than just the primary offending process.
3Measurement precision
If existing systems use exception lists for known processes to avoid false positives, then false positive rate is reduced, but detection precision for new malware deteriorates
Solution Approach 1:
The system transitions from static exception lists to dynamic phenotype-based detection that adapts to new malware patterns. By continuously analyzing behavioral patterns and updating phenotype databases with newly discovered malicious behaviors, the system maintains low false positive rates for known processes while simultaneously improving detection precision for novel malware through learned behavioral patterns.
Data Source
AI summary
In embodiments of the present invention improved capabilities are described for threat detection using a behavioral-based host-intrusion prevention method and system for monitoring a user interaction with a computer, software application, operating system, graphic user interface, or some other component or client of a computer network, and performing an action to protect the computer network based at least in part on the user interaction and a computer code process executing during or in association with a computer usage session.


