Isolated Container Analysis for Suspicious Code Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems often fail to prevent the spread of harmful code within organizations, requiring costly and time-consuming measures that hinder operations.

Innovation Solution

A security system that isolates suspicious information in a separate container, using virtual containers and non-native applications to analyze potentially harmful code, and employs hashing to identify and mitigate threats without compromising the main system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems are used to identify harmful code, then security detection capability is improved, but harmful code can still spread to other systems and expensive time-consuming measures are required

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidspread of harmful code
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system divides the computing environment into isolated containers, each capable of holding suspicious code independently. This segmentation prevents harmful code from spreading between containers while maintaining security detection capabilities across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary analysis environment where suspicious code is first examined before being allowed to access other systems. This intermediary layer enables security detection without direct exposure of harmful code to the main system network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security measures are implemented, then harmful code identification is improved, but operational disruptions increase and resources are consumed

Engineering Contradiction:
Improveharmful code identificationVSAvoidoperational disruption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting the environment into isolated containers, the system allows harmful code analysis to occur in containment without affecting other operational systems. This enables continuous business operations while maintaining security monitoring capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates isolated container copies that can be used for analysis purposes. These copies allow security testing and harmful code identification without impacting the original operational systems, thereby maintaining productivity while improving detection reliability.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive analysis of suspicious information is performed, then detection accuracy is improved, but time consumption and resource allocation increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of suspicious code in isolated containers before it can cause harm or require comprehensive manual investigation. This preliminary action in the controlled environment enables rapid detection accuracy without consuming extensive time resources on full-system analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11574056B2System for identifying suspicious code embedded in a file in an isolated computing environment
Publication Date: 2023.02.07 BANK OF AMERICA CORP
  • US11574056B2 patent drawing
  • US11574056B2 patent drawing
  • US11574056B2 patent drawing

AI summary

Providing an isolation system that allows analysts to analyze suspicious information in way that aids in preventing harmful information from spreading to other applications and systems on a network. A plurality of virtual containers may be used by analysts to analyze suspicious information. The suspicious information may first be checked for signatures or patterns before being analyzed by the analyst or the isolation system. The identified signatures or patterns are then compared with the stored signatures or patterns to determine whether the suspicious information comprises harmful information or not. When the identified signatures or patterns are matched with stored signatures or patterns, the system may determine that the suspicious information comprises harmful information and performs one or more mitigation actions.