Immunization Signatures for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malicious code detection methods face challenges in efficiently identifying new malicious codes and managing database size, leading to increased CPU overhead, memory usage, and power consumption issues, especially in portable devices, and are ineffective until updated databases are available.
Innovation Solution
An immunization system comprising an immunization client apparatus and server that compares binary code signatures with stored signatures to diagnose malicious codes, using a filter database and immunization database to reduce database size and operation time, and allows individual client apparatuses to detect new malicious codes without being infected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a large database storing signatures of known malicious codes is maintained to improve detection capability, then the detection accuracy improves, but the CPU overhead, memory usage, and power consumption increase
Solution Approach 1:
The patent extracts only the essential diagnostic information from complete malicious code signatures, creating condensed immunization signatures that retain detection capability while reducing data volume. This extraction principle directly addresses the contradiction by maintaining detection accuracy with reduced memory storage and lower power consumption for database operations
Solution Approach 2:
Instead of storing complete malicious code signatures and comparing against them, the patent inverts the approach by storing condensed immunization signatures that represent the essential diagnostic features. This inversion reduces the database size and associated power consumption while maintaining the ability to detect malicious codes through comparative analysis
2Reliability
If a large database storing signatures of known malicious codes is maintained to improve detection capability, then the detection accuracy improves, but the CPU overhead increases
Solution Approach 1:
The patent extracts only the essential diagnostic information from complete malicious code signatures, creating condensed immunization signatures that retain detection capability while reducing data volume. This extraction principle directly addresses the contradiction by maintaining detection accuracy with reduced memory storage and lower power consumption for database operations
Solution Approach 2:
The patent segments the complete malicious code signature into essential diagnostic components, storing only these segmented elements in the immunization database. This segmentation reduces the complexity of database operations and CPU overhead while preserving the ability to accurately detect malicious codes through comparison of key diagnostic features
3Reliability
If a large database storing signatures of known malicious codes is maintained to improve detection capability, then the detection accuracy improves, but the memory usage increases
Solution Approach 1:
The patent extracts only the essential diagnostic information from complete malicious code signatures, creating condensed immunization signatures that retain detection capability while reducing data volume. This extraction principle directly addresses the contradiction by maintaining detection accuracy with reduced memory storage and lower power consumption for database operations
4Adaptability or versatility
If the database is updated frequently to detect new malicious codes, then the detection capability against new threats improves, but the operation time and resource consumption increase
Solution Approach 1:
The patent performs preliminary extraction of diagnostic information from malicious code signatures before they need to be used for detection. By pre-processing and condensing the signature data into immunization signatures, the system reduces the operation time required during actual detection activities, allowing for faster response to new threats without proportionally increasing resource consumption
Data Source
AI summary
An immunization system including: an immunization client apparatus which determines whether a target code is a malicious code by performing an immunization operation with respect to a first immunization signature and a code signature that is extracted from the target code and reports the result of the determination to an immunization server; and the immunization server which diagnoses whether the target code is the malicious code, updates a second immunization signature based on the reported result of the determination, and transmits to the immunization client apparatus an update message about the updated second immunization signature, wherein the immunization client apparatus updates the first immunization signature based on the received update message is provided.


