Local Security Application for Application Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus systems face high computational burdens and increased errors due to repeated requests for categorizing applications on remote servers, leading to inefficiencies in detecting malicious applications.

Innovation Solution

A method and system that categorize applications on computing devices by obtaining classification results from a security server, designating them as relevant based on heuristic rules, and updating classifications using attributes such as file numbers, permissions, and executable file details, thereby reducing the need for computational resources and minimizing errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If caching services are used to remember results of previously performed tasks on remote infrastructure, then the computing burden on the remote server is reduced, but the error rate in application classification increases

Engineering Contradiction:
Improvecomputing burden on remote serverVSAvoiderror rate in application classification
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent introduces a local security application as an intermediary between the computing device and the remote server. This local application performs preliminary classification of applications using cached data and heuristics, filtering requests before they reach the remote server. This mediator approach reduces server burden while maintaining classification accuracy by only sending uncertain cases to the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary classification actions locally using cached classification results and heuristic analysis before consulting the remote server. By pre-processing and filtering applications locally, the system reduces the number of requests sent to the server while maintaining accurate classification, thus reducing both computing burden and error rates.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple antivirus applications are hooked up to a remote server for application classification, then the detection capability is improved, but the burden on the remote infrastructure increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidburden on remote infrastructure
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the classification system into local and remote components. The local security application handles preliminary classification and filtering, while the remote server handles only the final arbitration for uncertain cases. This segmentation allows multiple antivirus applications to operate with reduced server burden while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of all antivirus applications sending every classification request to the remote server, the system implements partial action by handling most classifications locally using cached data and heuristics. Only when local classification confidence is insufficient does the system invoke the remote server, thus maintaining detection capability while significantly reducing infrastructure burden.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If identical classification tasks are performed repeatedly on the remote infrastructure, then the most recent classification information is obtained, but the computational resources are wasted

Engineering Contradiction:
Improveclassification information freshnessVSAvoidcomputational resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary checks using cached classification results before submitting requests to the remote server. By pre-processing and comparing against cached data, the system avoids redundant classification tasks on the server while ensuring that only necessary requests are processed, thus saving computational resources while maintaining information freshness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where local classification results are compared against cached data, and only when discrepancies or uncertainties are detected does the system query the remote server. This feedback loop ensures that computational resources are used only when necessary to obtain updated classification information.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11295016B2System and method of categorization of an application on a computing device
Publication Date: 2022.04.05 AO KASPERSKY LAB
  • US11295016B2 patent drawing
  • US11295016B2 patent drawing
  • US11295016B2 patent drawing

AI summary

Disclosed herein are systems and methods for categorizing an application on a computing device. In one aspect, an exemplary method comprises, obtaining results of a classification of an application from a security server, when the results of the classification satisfy rules of relevance, designating the results of the classification as relevant and determining a category of the application based on the designation of the results as relevant, and when the results of the classification do not satisfy the rules of relevance, performing at least one of: terminating the categorization of the application, and updating the classification of the application based on a set of attributes of the application.