Instant Message Scanning for Malicious Content Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection systems are ineffective in identifying and mitigating malicious messages transmitted through instant messaging applications, which can compromise processing systems.

Innovation Solution

A method and system for detecting malicious messages in instant messaging services by analyzing textual content and attached files for network addresses associated with malicious activity, and restricting or blocking such messages to prevent threats, including blocking, alerting users, modifying messages, and removing malicious entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional malware scanners are used to detect threats in hard drives or e-mails, then existing security coverage is maintained, but new threats transmitted through instant messaging applications cannot be detected

Engineering Contradiction:
Improvedetection coverageVSAvoidthreat detection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The instant messaging security system performs multiple detection functions within a single integrated platform. It analyzes textual content for malicious URLs, scans attached files for viruses and malware, monitors message metadata for suspicious patterns, and tracks user behavior indicators. This multi-functional approach enables comprehensive threat detection across instant messaging communications while maintaining reliability through unified security processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If instant messaging applications are used for rapid communication, then productivity is improved, but the risk of malware transmission and system compromise increases

Engineering Contradiction:
Improvecommunication speedVSAvoidmalware transmission risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The security system performs preliminary analysis of messages before they are transmitted or displayed to users. Textual content is scanned for malicious URLs and suspicious patterns, attached files are pre-scanned for viruses and malware, and message metadata is analyzed for indicators of compromise. This preliminary security checking occurs automatically in the background, allowing rapid communication to proceed while blocking harmful content before it reaches the user's system.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If message analysis is performed to detect malicious content, then security is improved, but processing time and system resources are consumed

Engineering Contradiction:
Improvemessage securityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The message analysis process is divided into distinct sequential segments: textual content scanning for malicious URLs, attached file scanning for viruses and malware, metadata analysis for suspicious patterns, and user behavior indicator monitoring. Each segment processes specific aspects of the message independently, allowing parallel processing of different message components and reducing overall processing time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If comprehensive scanning of message content and attachments is implemented, then detection accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvethreat detection precisionVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security system introduces an intermediary processing layer between the instant messaging application and the user's processing system. This intermediary component handles all scanning and analysis operations - textual content analysis, file virus scanning, metadata examination, and behavior indicator monitoring - before allowing messages to reach the user. The intermediary absorbs the complexity of comprehensive scanning while presenting a simple interface to users, maintaining high detection precision without increasing user-side system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8769674B2Instant message scanning
Publication Date: 2014.07.01 GEN DIGITAL INC
  • US8769674B2 patent drawing
  • US8769674B2 patent drawing
  • US8769674B2 patent drawing

AI summary

A method, system, computer program product, and/or a computer readable medium of instructions for detecting a malicious message for an instant messaging service. In one form, the method comprises: receiving a message in a first processing system; analyzing the message to determine if the message is malicious; and in response to detecting that the message is malicious, restricting the message from threatening: the first processing system; and a second processing system in data communication with the first processing system. In another form, the method comprises receiving, in a first processing system, input data indicative of an instruction to transfer a message to a second processing system; analyzing the message to be transferred to determine if the message is malicious; and in response to detecting that the message is malicious, restricting the message from being transferred to the second processing system.