Inoculator Engine Block Objects Prevent Malware Re-infection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware protection solutions are expensive and inefficient for large businesses, as they often require extensive resources to maintain and do not effectively prevent re-infection of computers and networked devices, leading to increased costs due to high re-infection rates.

Innovation Solution

The implementation of an inoculator engine that uses a block object or 'wedge' to prevent specific software programs from installing or executing on computing devices by occupying memory space and registry areas with inert data objects, thereby blocking re-infection without the need for active running code or software agents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional malware protection solutions (software agents, active running code, behavioral blocking software) are used, then malware detection and removal capability is improved, but device complexity and maintenance cost increase

Engineering Contradiction:
Improvemalware protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the active running code and behavioral blocking components from the protection system, replacing them with inert data objects (block objects and fake registry keys) that are placed in the target system. This removes the complexity of running protection code while maintaining protection capability through passive blocking mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates copies of malware characteristics (block objects that resemble malware files, fake registry keys that mimic legitimate registry entries) to deceive malware into thinking the system is vulnerable, when in fact these copies serve as blocking mechanisms that prevent actual malware execution.

Inventive Principle:
Principle #26Copying

2Reliability

If enterprise systems with active protection software are deployed, then security monitoring is improved, but maintenance cost and resource consumption increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidmaintenance cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The block objects and fake registry keys are self-configuring and self-maintaining. Once deployed, they automatically block malware without requiring active monitoring, updating, or management. The system serves itself by having the inert data objects permanently occupy the memory spaces and registry areas that malware would otherwise exploit.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The protection mechanism is established in advance by placing block objects and fake registry keys into the target system before malware infection attempts occur. This preliminary action creates permanent barriers that automatically prevent malware execution without requiring real-time intervention or active protection software.

Inventive Principle:
Principle #10Preliminary action

3Ease of repair

If re-imaging procedures are performed on infected computers, then system restoration is achieved, but re-infection risk increases

Engineering Contradiction:
Improvesystem restorationVSAvoidre-infection resistance
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The block objects and fake registry keys are installed during or after the re-imaging process, creating permanent protective barriers before the system is returned to service. This preliminary protective action ensures that even if malware attempts to re-infect the restored system, the pre-placed block objects will prevent successful installation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by placing block objects and fake registry keys that specifically counteract malware installation attempts. These objects are positioned in advance to occupy the exact memory spaces and registry areas that malware would target, creating a preemptive defense against re-infection.

Inventive Principle:
Principle #9Preliminary anti-action

4Speed

If active running code is used for malware blocking, then real-time protection is improved, but resource consumption increases

Engineering Contradiction:
Improveprotection response timeVSAvoidprocessor resource
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent removes the active running code component entirely from the protection mechanism. Instead of using processes that continuously monitor and block malware, the system uses inert data objects that passively occupy memory spaces and registry areas, eliminating processor resource consumption while maintaining blocking capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The protection mechanism uses static copies (block objects and fake registry keys) rather than active code. These copied structures resemble malware or legitimate system components but are inert data that consume no processing resources while effectively blocking malware execution through their presence in critical system areas.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2635969B1Inoculator and antibody for computer security
Publication Date: 2020.07.08 GOSECURE INC
  • EP2635969B1 patent drawingFigure 1
  • EP2635969B1 patent drawingFigure 2
  • EP2635969B1 patent drawingFigure 3

AI summary

In an embodiment of the invention, a method includes: determining, in a computer, an area where an undesired computer program will reside; and providing a data object in the area, so that the data object is an antibody that provides security to the computer and immunity against the undesired program. Another embodiment of the invention also provides an apparatus (or system) that can be configured to perform at least some of the above functionalities.