Local Security Application for Application Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus systems face high computational burdens and increased errors due to repeated requests for categorizing applications on remote servers, leading to inefficiencies in detecting malicious applications.
Innovation Solution
A method and system that categorize applications on computing devices by obtaining classification results from a security server, designating them as relevant based on heuristic rules, and updating classifications using attributes such as file numbers, permissions, and executable file details, thereby reducing the need for computational resources and minimizing errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If caching services are used to remember results of previously performed tasks on remote infrastructure, then the computing burden on the remote server is reduced, but the error rate in application classification increases
Solution Approach 1:
The patent introduces a local security application as an intermediary between the computing device and the remote server. This local application performs preliminary classification of applications using cached data and heuristics, filtering requests before they reach the remote server. This mediator approach reduces server burden while maintaining classification accuracy by only sending uncertain cases to the server.
Solution Approach 2:
The system performs preliminary classification actions locally using cached classification results and heuristic analysis before consulting the remote server. By pre-processing and filtering applications locally, the system reduces the number of requests sent to the server while maintaining accurate classification, thus reducing both computing burden and error rates.
2Reliability
If multiple antivirus applications are hooked up to a remote server for application classification, then the detection capability is improved, but the burden on the remote infrastructure increases
Solution Approach 1:
The patent segments the classification system into local and remote components. The local security application handles preliminary classification and filtering, while the remote server handles only the final arbitration for uncertain cases. This segmentation allows multiple antivirus applications to operate with reduced server burden while maintaining detection capability.
Solution Approach 2:
Instead of all antivirus applications sending every classification request to the remote server, the system implements partial action by handling most classifications locally using cached data and heuristics. Only when local classification confidence is insufficient does the system invoke the remote server, thus maintaining detection capability while significantly reducing infrastructure burden.
3Reliability
If identical classification tasks are performed repeatedly on the remote infrastructure, then the most recent classification information is obtained, but the computational resources are wasted
Solution Approach 1:
The system performs preliminary checks using cached classification results before submitting requests to the remote server. By pre-processing and comparing against cached data, the system avoids redundant classification tasks on the server while ensuring that only necessary requests are processed, thus saving computational resources while maintaining information freshness.
Solution Approach 2:
The system implements feedback mechanisms where local classification results are compared against cached data, and only when discrepancies or uncertainties are detected does the system query the remote server. This feedback loop ensures that computational resources are used only when necessary to obtain updated classification information.
Data Source
AI summary
Disclosed herein are systems and methods for categorizing an application on a computing device. In one aspect, an exemplary method comprises, obtaining results of a classification of an application from a security server, when the results of the classification satisfy rules of relevance, designating the results of the classification as relevant and determining a category of the application based on the designation of the results as relevant, and when the results of the classification do not satisfy the rules of relevance, performing at least one of: terminating the categorization of the application, and updating the classification of the application based on a set of attributes of the application.


