Malicious Application Detection via Behavioral Triggering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virus detection software is often reactive and requires prior knowledge of malicious application signatures, making it ineffective in detecting and removing unknown or newly emerging malicious applications, as it relies on signature-based detection and may generate false positives or negatives.

Innovation Solution

A system that installs an executable application on a client device to stimulate malicious applications by accessing a third-party server, records processes, and transmits data to an analysis server for comparison with clean devices to identify and remove malicious files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virus detection software uses signature-based detection, then it can identify known viruses, but it cannot detect unknown or newly emerging malicious applications

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect new malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by installing a monitoring application on the client device before the actual infection occurs. This monitoring application collects process information and triggers malicious applications in a controlled environment, allowing the system to detect and remove malware before it can cause harm to the user.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary monitoring application that acts as a mediator between the user's legitimate applications and the malicious software. This intermediary collects process information and triggers malicious applications in a controlled manner, enabling detection without direct exposure to the malware's full functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If conventional virus detection software waits to analyze malicious applications before characterizing traits, then it can ensure accurate identification, but it becomes reactive and time-consuming

Engineering Contradiction:
Improvevirus identification accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary characterization by collecting process information and triggering malicious applications in advance. The monitoring application gathers data about the malicious software's behavior, file locations, and process characteristics before the user experiences any harm, enabling rapid identification and removal.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the monitoring application continuously collects process information and compares it against known benign patterns. When anomalies are detected, the system provides feedback by identifying the malicious application and initiating removal, creating a closed-loop detection system that reduces response time.

Inventive Principle:
Principle #23Feedback

3Ease of repair

If virus detection software includes instructions for removing each specific malicious application, then it can provide targeted removal, but it increases complexity and requires continuous updates

Engineering Contradiction:
Improvemalware removal capabilityVSAvoidsoftware update requirements
Core Design Contradiction:
Ease of repairVSDevice complexity

Solution Approach 1:

The monitoring application enables self-service by automatically collecting process information, identifying malicious applications, and initiating removal without requiring manual intervention or continuous software updates. The system uses its built-in monitoring capabilities to characterize and remove malware based on real-time behavior analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies parameter changes by monitoring dynamic process characteristics such as file locations, process names, and behavior patterns rather than relying on static virus signatures. This allows the system to adapt to new malware variants by detecting changes in behavior parameters rather than requiring updates to detection databases.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11687653B2Methods and apparatus for identifying and removing malicious applications
Publication Date: 2023.06.27 SUNSTONE INFORMATION DEFENSE INC
  • US11687653B2 patent drawing
  • US11687653B2 patent drawing
  • US11687653B2 patent drawing

AI summary

A system, method, and apparatus for identifying and removing malicious applications are disclosed. An example apparatus includes an executable application configured to collect data regarding processes operating on a client device during a time period. The executable application is also configured to purposefully access, during the time period, an application server using a web browser on the client device in an attempt to trigger a malicious application potentially located on the client device. The executable application is configured to transmit, after the time period, the collected data to an analysis server to determine whether the malicious application is located on the client device.