Incremental Backup Malware Detection via Sector Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus techniques struggle to effectively detect and remove rootkits and other malicious codes, which are difficult to detect and remove due to their ability to conceal processes, modify operating systems, and interfere with security products.

Innovation Solution

The method involves evaluating incremental backups by scanning modified addressable portions of a data storage device for malicious codes, mapping these portions to associated files, and selecting a clean backup for restoration, utilizing a backup selection module that includes a sector scanner and mapping module to identify and remove malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If incremental backups contain only modified addressable portions rather than entire files, then the backup size and storage requirements are reduced, but the ability to detect malicious codes becomes more difficult

Engineering Contradiction:
Improvebackup data sizeVSAvoidmalicious code detection
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent divides the backup evaluation process into two parallel scanning approaches: sector-level scanning that examines individual modified addressable portions, and file-level scanning that maps these portions to complete files. This segmentation allows the system to detect malicious codes in both fragmented and complete data contexts, resolving the detection difficulty while maintaining reduced backup sizes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a mapping module as an intermediary that connects modified addressable portions to their associated complete files. This mapping mechanism enables the system to analyze both the fragmented backup data and the complete file structure, allowing malicious code detection to work effectively despite the incremental backup containing only portions of files

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional antivirus techniques are used to detect rootkits, then the detection process interferes with the malicious codes' concealment mechanisms, but the malicious codes remain difficult to detect and remove

Engineering Contradiction:
Improvemalware detection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of scanning the infected system directly (which allows rootkits to conceal themselves), the patent inverts the approach by scanning incremental backups that contain copies of the modified data. This reverse scanning method allows detection of malicious codes in a controlled environment where they cannot actively conceal themselves, improving detection reliability without requiring complex real-time interference with malware operations

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent performs preliminary scanning of incremental backups before restoration occurs. By evaluating the backup data for malicious codes in advance and selecting only clean backups for restoration, the system prevents infected data from being restored to the system, achieving reliable malware detection without the complexity of real-time interception of malware concealment mechanisms

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7962956B1Evaluation of incremental backup copies for presence of malicious codes in computer systems
Publication Date: 2011.06.14 TREND MICRO INC
  • US7962956B1 patent drawing
  • US7962956B1 patent drawing
  • US7962956B1 patent drawing

AI summary

In one embodiment, incremental backups containing information on modified addressable portions of a data storage device are evaluated for presence of malicious codes (“malwares”). Each modified addressable portion may be individually accessed and scanned for malicious codes. Each modified addressable portion may also be mapped to its associated file, allowing the associated file to be scanned for malicious codes. These allow an incremental backup to be evaluated even when it only contains portions, rather than the entirety, of several different files. A clean incremental backup may be selected for restoring the data storage device in the event of malicious code infection.