Client Rendering Verification for Malicious Application Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional communication systems fail to detect malicious applications that alter or interfere with communications by substituting legitimate messages with engineered noise, which existing error correction methods cannot identify, allowing these applications to manipulate client and server actions undetected.

Innovation Solution

A security processor uses variations in soft information to predict how hard information is rendered by a client device, comparing the actual response to the prediction to detect malicious applications affecting communications between servers and clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional error correction methods are used, then communication reliability is maintained against haphazard noise, but malicious applications can substitute legitimate messages with engineered noise undetected

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidmalicious application interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary verification layer that sits between the traditional error correction mechanism and the communication channel. This intermediary uses machine learning models to analyze communication patterns and detect malicious substitutions that traditional error correction would miss, while allowing legitimate haphazard noise to pass through unchanged.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the noise detection function into two distinct components: traditional error correction for haphazard noise and machine learning-based detection for malicious noise. This segmentation allows each component to specialize in its respective threat type without interfering with the other's effectiveness.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If machine learning models are trained on communication data, then detection accuracy improves, but training data requirements increase system complexity

Engineering Contradiction:
Improvemalicious application detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-training machine learning models offline using large datasets before deployment. Once trained, the models are frozen and deployed as static detection components, eliminating the need for continuous online training and reducing runtime system complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses lightweight, pre-trained machine learning models that can be rapidly deployed and replaced without requiring complex infrastructure. These models are designed to be computationally efficient and can be updated independently, reducing the overall system complexity while maintaining detection effectiveness.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12368753B2Methods and apparatus for detecting a presence of a malicious application
Publication Date: 2025.07.22 SUNSTONE INFORMATION DEFENSE INC
  • US12368753B2 patent drawing
  • US12368753B2 patent drawing
  • US12368753B2 patent drawing

AI summary

Methods, systems, and apparatuses for detecting a presence of a malicious application are disclosed. In an example, a method includes storing information to a data structure as a predicted response from a client device. The information is indicative of graphically rendered text or images at the client device corresponding to transactional information and presentation information of a website. The method also includes, during a subsequent access of the website, selecting the transactional information and the presentation information to transmit to the client device. The method further includes receiving second information indicative of graphically rendered text or images at the client device, comparing the second information to the stored predicted response, and determining a malicious application is attempting to affect the controlled usage of a website resource or a second website resource when the received second information does not match the stored predicted response.