Macro Virus Detection Plug-in for Data Files
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting macro viruses face challenges in coverage due to varying data file structures and resource-intensive real-time monitoring, leading to poor user experience and false warnings.
Innovation Solution
A method and apparatus that pre-register a macro virus detecting module as a plug-in to the data file processing program, allowing detection only when the file is opened but not loaded, enabling internal analysis and reducing system resource usage by limiting detection to specific events, with features matched against virus and micro features to determine warnings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static analysis is performed on all data files to detect macro viruses, then detection coverage may be improved, but the method is difficult to achieve in practical use due to different data file structures and encryption
Solution Approach 1:
The patent pre-registers a macro virus detecting module as a plug-in of the data file processing program before actual file operations occur. This preliminary setup allows the detection module to be automatically activated when files are opened, enabling detection without requiring complex pre-analysis of all possible data file structures. The module is prepared in advance to handle macro virus detection specifically when triggered by file opening events.
Solution Approach 2:
The patent introduces a macro virus detecting module as an intermediary component between the data file processing program and the files themselves. This module acts as a mediator that intercepts file opening operations and performs detection before the main processing program loads file contents. This intermediary approach simplifies the detection process by focusing only on macro virus-specific analysis rather than requiring comprehensive analysis of all data file structures.
2Reliability
If real-time monitoring of data file processing behaviors is implemented to detect macro viruses, then detection capability is improved, but more system resources are occupied affecting overall machine performance
Solution Approach 1:
Instead of continuous real-time monitoring, the patent implements periodic detection by triggering the macro virus detecting module only at specific event points - when a data file is opened but not yet loaded. This periodic action occurs at discrete intervals based on user operations rather than continuously, significantly reducing system resource consumption while maintaining effective detection capability at critical moments when macro viruses are most likely to be activated.
Solution Approach 2:
The detection is performed preliminarily when a file is opened but before its contents are fully loaded into memory. This timing allows the detecting module to analyze the file structure and detect macro viruses before they can be executed, without requiring continuous monitoring resources. The preliminary detection at this specific stage achieves security goals while minimizing ongoing system resource usage.
3Reliability
If real-time monitoring intercepts malicious behaviors to ensure security, then security is improved, but frequent warnings are given for both normal and malicious behaviors resulting in poor user experience
Solution Approach 1:
The patent applies local quality by making the detection module highly specialized for macro virus detection rather than attempting to monitor all types of file operations. The module is configured with specific detection capabilities focused on macro virus characteristics, allowing it to distinguish between normal macro operations and malicious virus behaviors. This specialized local detection quality reduces false warnings by accurately identifying only genuine threats rather than flagging all macro operations as suspicious.
Solution Approach 2:
The detection occurs preliminarily at the file opening stage before any macro execution takes place. By detecting macro viruses at this early stage, the system can prevent malicious macros from executing altogether, rather than monitoring and warning during execution. This preliminary detection approach eliminates the need for frequent warnings during user operations, as threats are blocked before they can manifest as suspicious behaviors requiring user attention.
Data Source
AI summary
Disclosed are a method and an apparatus for detecting macro viruses. The method includes: if a data file processing program has already performed an opening operation on a target data file but has not yet performed a loading operation on a content of the target data file, calling a macro virus detecting module registered previously as a plug-in of the data file processing program; detecting the target data file by using the macro virus detecting module. Applying the embodiment of the present disclosure, the macro virus detecting module may identify the format of all data files and may perform the internal analysis of the data files, thus improving the coverage of the detected data files.

