Malicious Code Deactivation via Preliminary Process Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing prevalence of unknown or variant malicious code, including zero-day vulnerabilities and intelligent malicious code, poses a significant challenge for existing security systems, as they often bypass traditional security equipment and are difficult to analyze, necessitating a technology that can effectively protect against and rapidly inspect malicious code.
Innovation Solution
A malicious code deactivating apparatus and method that utilizes a comparator and controller to postpone the execution of newly created or downloaded processes, performing a preliminary inspection against a white list received from an external server, and includes an analyzer to manage the execution based on inspection results, ensuring high security and processing speed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security equipment is used to detect malicious code, then the system structure is simple, but the detection precision deteriorates due to inability to identify unknown or variant malicious code
Solution Approach 1:
The system performs preliminary malicious code inspection on newly created or downloaded processes before they are fully executed. The comparator extracts target processes and stores their information in a database for pre-inspection, allowing the system to identify potential threats before they can cause harm, thereby improving detection precision without requiring complex real-time analysis infrastructure
Solution Approach 2:
The patent introduces an external server as an intermediary that performs the actual malicious code inspection. The terminal device sends target process information to the external server, which then conducts the inspection and returns results. This intermediary approach allows the terminal to achieve high detection precision without maintaining complex inspection capabilities locally
2Measurement precision
If comprehensive malicious code inspection is performed on all processes, then the detection precision improves, but the processing speed deteriorates due to time-consuming analysis
Solution Approach 1:
The system applies inspection only to specific target processes that meet certain criteria (newly created or downloaded processes), rather than performing comprehensive inspection on all processes. The comparator selectively extracts target processes based on their characteristics, allowing the system to maintain high inspection accuracy for critical processes while avoiding unnecessary inspection of benign processes, thus preserving overall processing speed
Solution Approach 2:
The system performs inspection preparation in advance by extracting target process information and storing it in a database before the actual inspection occurs. This preliminary organization of data allows the external server to conduct inspection more efficiently, reducing the time required for actual malicious code analysis and maintaining faster process execution speeds
3Reliability
If new processes are executed immediately without inspection, then the processing speed is high, but the reliability deteriorates due to potential malicious code execution
Solution Approach 1:
The system takes preliminary anti-action by blocking the execution of target processes before they can run. The comparator identifies target processes and the controller blocks their execution pending inspection results from the external server. This prevents potential malicious code from executing while still allowing legitimate processes to proceed, thereby improving system security reliability with minimal time loss
Solution Approach 2:
The system implements a feedback mechanism where the external server inspects target processes and returns inspection results to the terminal device. The controller receives these feedback results and makes informed decisions about whether to allow or block process execution. This feedback loop ensures that only processes confirmed as safe are executed, maintaining high reliability while minimizing delays through automated decision-making
Data Source
AI summary
Disclosed are a malicious code deactivating apparatus and a method of operating the same. The malicious code deactivating apparatus and the method of operating the same provide a high security malicious code deactivating apparatus for preliminarily performing a malicious code inspection on a target process and then executing the target process in a terminal unit, by including a monitor, a comparator, a controller, an analyzer, and a storage.


