Immunization Signatures for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malicious code detection methods face challenges in efficiently identifying new malicious codes and managing database size, leading to increased CPU overhead, memory usage, and power consumption issues, especially in portable devices, and are ineffective until updated databases are available.

Innovation Solution

An immunization system comprising an immunization client apparatus and server that compares binary code signatures with stored signatures to diagnose malicious codes, using a filter database and immunization database to reduce database size and operation time, and allows individual client apparatuses to detect new malicious codes without being infected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a large database storing signatures of known malicious codes is maintained to improve detection capability, then the detection accuracy improves, but the CPU overhead, memory usage, and power consumption increase

Engineering Contradiction:
Improvemalicious code detection accuracyVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential diagnostic information from complete malicious code signatures, creating condensed immunization signatures that retain detection capability while reducing data volume. This extraction principle directly addresses the contradiction by maintaining detection accuracy with reduced memory storage and lower power consumption for database operations

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing complete malicious code signatures and comparing against them, the patent inverts the approach by storing condensed immunization signatures that represent the essential diagnostic features. This inversion reduces the database size and associated power consumption while maintaining the ability to detect malicious codes through comparative analysis

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If a large database storing signatures of known malicious codes is maintained to improve detection capability, then the detection accuracy improves, but the CPU overhead increases

Engineering Contradiction:
Improvemalicious code detection accuracyVSAvoidCPU overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential diagnostic information from complete malicious code signatures, creating condensed immunization signatures that retain detection capability while reducing data volume. This extraction principle directly addresses the contradiction by maintaining detection accuracy with reduced memory storage and lower power consumption for database operations

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the complete malicious code signature into essential diagnostic components, storing only these segmented elements in the immunization database. This segmentation reduces the complexity of database operations and CPU overhead while preserving the ability to accurately detect malicious codes through comparison of key diagnostic features

Inventive Principle:
Principle #1Segmentation

3Reliability

If a large database storing signatures of known malicious codes is maintained to improve detection capability, then the detection accuracy improves, but the memory usage increases

Engineering Contradiction:
Improvemalicious code detection accuracyVSAvoidmemory usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential diagnostic information from complete malicious code signatures, creating condensed immunization signatures that retain detection capability while reducing data volume. This extraction principle directly addresses the contradiction by maintaining detection accuracy with reduced memory storage and lower power consumption for database operations

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If the database is updated frequently to detect new malicious codes, then the detection capability against new threats improves, but the operation time and resource consumption increase

Engineering Contradiction:
Improvedetection capability against new malicious codesVSAvoidoperation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary extraction of diagnostic information from malicious code signatures before they need to be used for detection. By pre-processing and condensing the signature data into immunization signatures, the system reduces the operation time required during actual detection activities, allowing for faster response to new threats without proportionally increasing resource consumption

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8464340B2System, apparatus and method of malware diagnosis mechanism based on immunization database
Publication Date: 2013.06.11 SAMSUNG ELECTRONICS CO LTD
  • US8464340B2 patent drawing
  • US8464340B2 patent drawing
  • US8464340B2 patent drawing

AI summary

An immunization system including: an immunization client apparatus which determines whether a target code is a malicious code by performing an immunization operation with respect to a first immunization signature and a code signature that is extracted from the target code and reports the result of the determination to an immunization server; and the immunization server which diagnoses whether the target code is the malicious code, updates a second immunization signature based on the reported result of the determination, and transmits to the immunization client apparatus an update message about the updated second immunization signature, wherein the immunization client apparatus updates the first immunization signature based on the received update message is provided.