Inoculator Engine Block Objects Prevent Malware Re-infection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware protection solutions are expensive and inefficient for large businesses, as they often require extensive resources to maintain and do not effectively prevent re-infection of computers and networked devices, leading to increased costs due to high re-infection rates.
Innovation Solution
The implementation of an inoculator engine that uses a block object or 'wedge' to prevent specific software programs from installing or executing on computing devices by occupying memory space and registry areas with inert data objects, thereby blocking re-infection without the need for active running code or software agents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional malware protection solutions (software agents, active running code, behavioral blocking software) are used, then malware detection and removal capability is improved, but device complexity and maintenance cost increase
Solution Approach 1:
The patent extracts the active running code and behavioral blocking components from the protection system, replacing them with inert data objects (block objects and fake registry keys) that are placed in the target system. This removes the complexity of running protection code while maintaining protection capability through passive blocking mechanisms.
Solution Approach 2:
The patent creates copies of malware characteristics (block objects that resemble malware files, fake registry keys that mimic legitimate registry entries) to deceive malware into thinking the system is vulnerable, when in fact these copies serve as blocking mechanisms that prevent actual malware execution.
2Reliability
If enterprise systems with active protection software are deployed, then security monitoring is improved, but maintenance cost and resource consumption increase
Solution Approach 1:
The block objects and fake registry keys are self-configuring and self-maintaining. Once deployed, they automatically block malware without requiring active monitoring, updating, or management. The system serves itself by having the inert data objects permanently occupy the memory spaces and registry areas that malware would otherwise exploit.
Solution Approach 2:
The protection mechanism is established in advance by placing block objects and fake registry keys into the target system before malware infection attempts occur. This preliminary action creates permanent barriers that automatically prevent malware execution without requiring real-time intervention or active protection software.
3Ease of repair
If re-imaging procedures are performed on infected computers, then system restoration is achieved, but re-infection risk increases
Solution Approach 1:
The block objects and fake registry keys are installed during or after the re-imaging process, creating permanent protective barriers before the system is returned to service. This preliminary protective action ensures that even if malware attempts to re-infect the restored system, the pre-placed block objects will prevent successful installation.
Solution Approach 2:
The patent applies preliminary anti-action by placing block objects and fake registry keys that specifically counteract malware installation attempts. These objects are positioned in advance to occupy the exact memory spaces and registry areas that malware would target, creating a preemptive defense against re-infection.
4Speed
If active running code is used for malware blocking, then real-time protection is improved, but resource consumption increases
Solution Approach 1:
The patent removes the active running code component entirely from the protection mechanism. Instead of using processes that continuously monitor and block malware, the system uses inert data objects that passively occupy memory spaces and registry areas, eliminating processor resource consumption while maintaining blocking capability.
Solution Approach 2:
The protection mechanism uses static copies (block objects and fake registry keys) rather than active code. These copied structures resemble malware or legitimate system components but are inert data that consume no processing resources while effectively blocking malware execution through their presence in critical system areas.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In an embodiment of the invention, a method includes: determining, in a computer, an area where an undesired computer program will reside; and providing a data object in the area, so that the data object is an antibody that provides security to the computer and immunity against the undesired program. Another embodiment of the invention also provides an apparatus (or system) that can be configured to perform at least some of the above functionalities.