Incremental Backup Malware Detection via Sector Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus techniques struggle to effectively detect and remove rootkits and other malicious codes, which are difficult to detect and remove due to their ability to conceal processes, modify operating systems, and interfere with security products.
Innovation Solution
The method involves evaluating incremental backups by scanning modified addressable portions of a data storage device for malicious codes, mapping these portions to associated files, and selecting a clean backup for restoration, utilizing a backup selection module that includes a sector scanner and mapping module to identify and remove malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If incremental backups contain only modified addressable portions rather than entire files, then the backup size and storage requirements are reduced, but the ability to detect malicious codes becomes more difficult
Solution Approach 1:
The patent divides the backup evaluation process into two parallel scanning approaches: sector-level scanning that examines individual modified addressable portions, and file-level scanning that maps these portions to complete files. This segmentation allows the system to detect malicious codes in both fragmented and complete data contexts, resolving the detection difficulty while maintaining reduced backup sizes
Solution Approach 2:
The patent introduces a mapping module as an intermediary that connects modified addressable portions to their associated complete files. This mapping mechanism enables the system to analyze both the fragmented backup data and the complete file structure, allowing malicious code detection to work effectively despite the incremental backup containing only portions of files
2Reliability
If traditional antivirus techniques are used to detect rootkits, then the detection process interferes with the malicious codes' concealment mechanisms, but the malicious codes remain difficult to detect and remove
Solution Approach 1:
Instead of scanning the infected system directly (which allows rootkits to conceal themselves), the patent inverts the approach by scanning incremental backups that contain copies of the modified data. This reverse scanning method allows detection of malicious codes in a controlled environment where they cannot actively conceal themselves, improving detection reliability without requiring complex real-time interference with malware operations
Solution Approach 2:
The patent performs preliminary scanning of incremental backups before restoration occurs. By evaluating the backup data for malicious codes in advance and selecting only clean backups for restoration, the system prevents infected data from being restored to the system, achieving reliable malware detection without the complexity of real-time interception of malware concealment mechanisms
Data Source
AI summary
In one embodiment, incremental backups containing information on modified addressable portions of a data storage device are evaluated for presence of malicious codes (“malwares”). Each modified addressable portion may be individually accessed and scanned for malicious codes. Each modified addressable portion may also be mapped to its associated file, allowing the associated file to be scanned for malicious codes. These allow an incremental backup to be evaluated even when it only contains portions, rather than the entirety, of several different files. A clean incremental backup may be selected for restoring the data storage device in the event of malicious code infection.


