Malicious Application Detection via Behavioral Triggering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virus detection software is often reactive and requires prior knowledge of malicious application signatures, making it ineffective in detecting and removing unknown or newly emerging malicious applications, as it relies on signature-based detection and may generate false positives or negatives.
Innovation Solution
A system that installs an executable application on a client device to stimulate malicious applications by accessing a third-party server, records processes, and transmits data to an analysis server for comparison with clean devices to identify and remove malicious files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virus detection software uses signature-based detection, then it can identify known viruses, but it cannot detect unknown or newly emerging malicious applications
Solution Approach 1:
The system performs preliminary actions by installing a monitoring application on the client device before the actual infection occurs. This monitoring application collects process information and triggers malicious applications in a controlled environment, allowing the system to detect and remove malware before it can cause harm to the user.
Solution Approach 2:
The patent introduces an intermediary monitoring application that acts as a mediator between the user's legitimate applications and the malicious software. This intermediary collects process information and triggers malicious applications in a controlled manner, enabling detection without direct exposure to the malware's full functionality.
2Measurement precision
If conventional virus detection software waits to analyze malicious applications before characterizing traits, then it can ensure accurate identification, but it becomes reactive and time-consuming
Solution Approach 1:
The system performs preliminary characterization by collecting process information and triggering malicious applications in advance. The monitoring application gathers data about the malicious software's behavior, file locations, and process characteristics before the user experiences any harm, enabling rapid identification and removal.
Solution Approach 2:
The patent implements feedback mechanisms where the monitoring application continuously collects process information and compares it against known benign patterns. When anomalies are detected, the system provides feedback by identifying the malicious application and initiating removal, creating a closed-loop detection system that reduces response time.
3Ease of repair
If virus detection software includes instructions for removing each specific malicious application, then it can provide targeted removal, but it increases complexity and requires continuous updates
Solution Approach 1:
The monitoring application enables self-service by automatically collecting process information, identifying malicious applications, and initiating removal without requiring manual intervention or continuous software updates. The system uses its built-in monitoring capabilities to characterize and remove malware based on real-time behavior analysis.
Solution Approach 2:
The patent applies parameter changes by monitoring dynamic process characteristics such as file locations, process names, and behavior patterns rather than relying on static virus signatures. This allows the system to adapt to new malware variants by detecting changes in behavior parameters rather than requiring updates to detection databases.
Data Source
AI summary
A system, method, and apparatus for identifying and removing malicious applications are disclosed. An example apparatus includes an executable application configured to collect data regarding processes operating on a client device during a time period. The executable application is also configured to purposefully access, during the time period, an application server using a web browser on the client device in an attempt to trigger a malicious application potentially located on the client device. The executable application is configured to transmit, after the time period, the collected data to an analysis server to determine whether the malicious application is located on the client device.


