Host Reputation Proxy for Polymorphic Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods struggle to effectively assess the reputation of software applications, especially in modern computing environments where malware can exhibit polymorphic variations, making it difficult for security software to identify malicious entities.

Innovation Solution

A system and method that generates reputation scores for entities and hosts by monitoring communications, using reputation information from other entities and hosts, and applying these scores to determine the likelihood of malware presence, thereby reducing false positives and improving malware identification accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security software uses traditional reputation assessment methods, then it can identify known malware, but it fails to detect polymorphic malware variations

Engineering Contradiction:
Improvemalware identification accuracyVSAvoidability to detect polymorphic variations
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transitions from analyzing malware in isolation (single entity dimension) to analyzing malware within the context of its communication network (adding the host dimension). By examining the host's overall reputation derived from multiple entities, the system detects polymorphic malware that individual analysis would miss.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The host acts as an intermediary that aggregates reputation information from multiple entities. Instead of directly assessing each entity's reputation in isolation, the system uses the host as a mediator to synthesize collective reputation data, enabling detection of malicious patterns that individual entities may obscure through polymorphism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security software analyzes each software application individually, then it can assess known applications, but it cannot reliably assess unknown or newly introduced applications

Engineering Contradiction:
Improvereputation assessment reliabilityVSAvoidreputation information availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges individual entity reputation assessments with host-level reputation analysis. By combining information from multiple entities communicating with the same host, the system creates a more robust reputation assessment that remains reliable even when individual entity information is limited or unknown.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host reputation score serves as a universal indicator that applies to all entities communicating with that host. This multi-functional approach allows the system to assess reputation across different entities using a common reference point, enabling reliable assessment of unknown applications through their host's established reputation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If the system generates reputation scores based on individual entity information, then it can provide specific entity assessments, but it produces more false positives with limited information

Engineering Contradiction:
Improveentity reputation assessment accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback by using host reputation scores to validate and adjust individual entity reputation assessments. When host-level analysis provides additional context, it feedbacks to refine entity assessments, reducing false positives by confirming suspicious findings through multiple levels of analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8904520B1Communication-based reputation system
Publication Date: 2014.12.02 CA TECH INC
  • US8904520B1 patent drawing
  • US8904520B1 patent drawing
  • US8904520B1 patent drawing

AI summary

A communication between an entity and a host is identified. Reputation information associated with a set of other entities that communicate with the host is identified. A reputation score associated with the host is generated based on the reputation information associated with a set of other entities. A reputation score associated with the entity is generated based on the reputation score associated with the host.