Malicious Code Removal via File Format Conversion and Open-Save

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional signature-based malicious code detection methods are limited in detecting and removing non-signature based malicious codes, especially those employing packers and polymorphism, which can evade detection and vaccination.

Innovation Solution

An apparatus and method that includes a file-type determining module, an open and save-as module for document files, and an image format converting module for image files, allowing for the safe removal or reporting of malicious codes by opening and saving files as new files or converting file formats, respectively, while monitoring for exceptions and reporting to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If signature-based detection methods are used, then detection speed is improved, but detection precision deteriorates because malicious codes employing packers and polymorphism can evade detection

Engineering Contradiction:
Improvedetection speedVSAvoiddetection precision
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent segments the file processing into distinct modules: file-type determining module, open and save-as module for document files, and image format converting module for image files. This segmentation allows different detection and removal strategies to be applied to different file types, improving both detection precision and processing efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary processes between file detection and removal: for document files, it uses an application to open and save-as a new file; for image files, it converts to a different format. These intermediary steps enable the system to remove malicious codes while preserving legitimate file content, resolving the contradiction between detection speed and precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional detection methods are used, then ease of operation is improved, but reliability deteriorates because non-signature based malicious codes cannot be detected

Engineering Contradiction:
Improveease of operationVSAvoiddetection reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a universal malicious code removal system that handles multiple file types (document files and image files) through a single integrated apparatus. The file-type determining module automatically routes files to appropriate processing modules, maintaining ease of operation while improving reliability through multi-functional detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the detection parameter from signature-based to behavior-based detection. Instead of relying on fixed signatures, the system opens document files in applications and converts image files to different formats, observing the behavior and results to detect and remove malicious codes. This parameter change maintains ease of operation while significantly improving detection reliability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If file opening and saving operations are performed to remove malicious codes, then removal effectiveness is improved, but loss of time increases due to additional processing steps

Engineering Contradiction:
Improveremoval effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions based on file type detection: document files are opened and saved-as new files, while image files are converted to different formats. These preliminary actions are automatically determined by the file-type determining module, ensuring effective malicious code removal while minimizing unnecessary processing time through intelligent routing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic processing where the removal method adapts based on file type. Document files undergo open-save operations while image files undergo format conversion. This dynamic approach ensures optimal removal effectiveness for each file type while minimizing processing time by avoiding unnecessary operations.

Inventive Principle:
Principle #15Dynamics

4Productivity

If automated malicious code removal is implemented, then productivity is improved, but device complexity increases due to multiple modules and processing steps

Engineering Contradiction:
Improveautomated removal efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated removal system into distinct functional modules: file-type determining module, open and save-as module, image format converting module, exception monitoring module, and reporting module. This segmentation improves productivity by enabling specialized processing for each file type while managing complexity through clear module boundaries and defined interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal malicious code removal apparatus that handles both document and image files through a single integrated system. The file-type determining module automatically routes files to appropriate processing modules, achieving high productivity through automation while managing complexity through universal design principles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8590016B2Apparatus and method for removing malicious code inserted into file
Publication Date: 2013.11.19 ELECTRONICS & TELECOMM RES INST
  • US8590016B2 patent drawing
  • US8590016B2 patent drawing
  • US8590016B2 patent drawing

AI summary

Provided are an apparatus and method for safely removing a malicious code from a file, or reporting the probable presence of a malicious code when it cannot be removed safely.The method includes: determining whether a file is a document or image file; opening and saving the document file as a new file by using an application associated with the document file to remove a malicious code from the document file, when it is determined that the file is the document file; and converting the image file into a different file format from a present file format and saving the converted image file to remove a malicious code from the image file, when it is determined that the file is the image file.