Image Analysis Security Module for Malicious Code Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased transfer of image files between devices due to improved processing power has highlighted the need for enhanced security measures, as these files can potentially contain malicious code that can harm devices upon opening.

Innovation Solution

An image analysis security module is introduced to analyze image files for vulnerabilities before they are opened on a device. This module can be located at various points in the communication pathway, such as between transmitter and recipient devices, and employs a three-step processing system to identify operating systems, image types, and scan for malicious content, unauthorized accounts, and other vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If image files are transferred between devices more frequently due to improved processing power, then the utility and productivity of image file sharing is improved, but the risk of malicious code execution and security threats increases

Engineering Contradiction:
Improveimage file transfer efficiencyVSAvoidmalicious code execution risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security scanning of image files before they are opened or executed on a device. The security module analyzes the image file in advance to detect malicious code, embedded executables, and vulnerabilities, preventing harmful actions before they can occur. This preliminary detection allows safe transfer and sharing of image files while blocking potentially malicious ones.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If minimal security modules are used for image files as in conventional approaches, then the device complexity and resource consumption are reduced, but the security detection capability is insufficient

Engineering Contradiction:
Improvesecurity module complexityVSAvoidvulnerability detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary security module that sits between the image file and the application that would open it. This security module acts as a mediator that analyzes the image file for malicious content, embedded code, and vulnerabilities before allowing the file to be processed by the application. This intermediary approach provides comprehensive security without requiring modifications to the application itself or the image file format.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive security scanning is performed on all image files, then the vulnerability detection precision is improved, but the processing time and energy consumption increase

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoidsecurity scanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security module performs comprehensive analysis only when necessary - such as when an image file is received from an untrusted source, when the file size or structure indicates potential malicious content, or when previous scans have identified suspicious patterns. For files from trusted sources with clean histories, the scanning can be reduced or skipped, balancing security precision with processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12321463B2Security vulnerability detection for image files
Publication Date: 2025.06.03 BANK OF AMERICA CORP
  • US12321463B2 patent drawing
  • US12321463B2 patent drawing
  • US12321463B2 patent drawing

AI summary

An image analysis security apparatus includes a content delivery network, an image analyzer and a scan engine. The content delivery network receives an image file, quarantines the file and classifies the file with an operating system. The image analyzer receives the file and classifies the file with an image type. The scan engine loads security modules based on the operating system and the image type, communicates with a vulnerability database to receive vulnerability updates, communicates with a cyber threat intelligence database to receive collection analysis relating to unauthorized accesses to data that occurred within a predetermined time period and communicates with an open-source intelligence database to receive public data for intelligence objectives. The scan engine scans and labels the image file using the security modules in tandem with the information received from the databases.