Malicious Code Deactivation via Preliminary Process Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing prevalence of unknown or variant malicious code, including zero-day vulnerabilities and intelligent malicious code, poses a significant challenge for existing security systems, as they often bypass traditional security equipment and are difficult to analyze, necessitating a technology that can effectively protect against and rapidly inspect malicious code.

Innovation Solution

A malicious code deactivating apparatus and method that utilizes a comparator and controller to postpone the execution of newly created or downloaded processes, performing a preliminary inspection against a white list received from an external server, and includes an analyzer to manage the execution based on inspection results, ensuring high security and processing speed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security equipment is used to detect malicious code, then the system structure is simple, but the detection precision deteriorates due to inability to identify unknown or variant malicious code

Engineering Contradiction:
Improvemalicious code detection precisionVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary malicious code inspection on newly created or downloaded processes before they are fully executed. The comparator extracts target processes and stores their information in a database for pre-inspection, allowing the system to identify potential threats before they can cause harm, thereby improving detection precision without requiring complex real-time analysis infrastructure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an external server as an intermediary that performs the actual malicious code inspection. The terminal device sends target process information to the external server, which then conducts the inspection and returns results. This intermediary approach allows the terminal to achieve high detection precision without maintaining complex inspection capabilities locally

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive malicious code inspection is performed on all processes, then the detection precision improves, but the processing speed deteriorates due to time-consuming analysis

Engineering Contradiction:
Improvemalicious code inspection accuracyVSAvoidprocess execution speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies inspection only to specific target processes that meet certain criteria (newly created or downloaded processes), rather than performing comprehensive inspection on all processes. The comparator selectively extracts target processes based on their characteristics, allowing the system to maintain high inspection accuracy for critical processes while avoiding unnecessary inspection of benign processes, thus preserving overall processing speed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs inspection preparation in advance by extracting target process information and storing it in a database before the actual inspection occurs. This preliminary organization of data allows the external server to conduct inspection more efficiently, reducing the time required for actual malicious code analysis and maintaining faster process execution speeds

Inventive Principle:
Principle #10Preliminary action

3Reliability

If new processes are executed immediately without inspection, then the processing speed is high, but the reliability deteriorates due to potential malicious code execution

Engineering Contradiction:
Improvesystem security reliabilityVSAvoidprocess execution delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system takes preliminary anti-action by blocking the execution of target processes before they can run. The comparator identifies target processes and the controller blocks their execution pending inspection results from the external server. This prevents potential malicious code from executing while still allowing legitimate processes to proceed, thereby improving system security reliability with minimal time loss

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements a feedback mechanism where the external server inspects target processes and returns inspection results to the terminal device. The controller receives these feedback results and makes informed decisions about whether to allow or block process execution. This feedback loop ensures that only processes confirmed as safe are executed, maintaining high reliability while minimizing delays through automated decision-making

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10599845B2Malicious code deactivating apparatus and method of operating the same
Publication Date: 2020.03.24 NPCORE
  • US10599845B2 patent drawing
  • US10599845B2 patent drawing
  • US10599845B2 patent drawing

AI summary

Disclosed are a malicious code deactivating apparatus and a method of operating the same. The malicious code deactivating apparatus and the method of operating the same provide a high security malicious code deactivating apparatus for preliminarily performing a malicious code inspection on a target process and then executing the target process in a terminal unit, by including a monitor, a comparator, a controller, an analyzer, and a storage.