Malicious Entity Detection Using Low-Usage Period Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting and removing malware in processing systems are resource-intensive, leading to hindered system usage during scans and inefficiencies in identifying malicious entities.
Innovation Solution
A method that determines entity properties within a processing system's range of operating usage, records these properties, and assesses their maliciousness using cryptographic hashes, checksums, and other attributes, allowing for efficient identification and quarantine of malicious entities while minimizing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current methods of scanning for malware are used, then detection capability is improved, but processing system resources are consumed and user productivity is hindered
Solution Approach 1:
The system performs preliminary actions by determining entity properties and recording them during low-usage periods before malware detection is needed. This allows the scanning process to be prepared in advance during off-peak times, so that when users need the system, the detection can proceed more efficiently without blocking user productivity.
Solution Approach 2:
The scanning process is performed periodically during low-usage periods rather than continuously or during peak usage times. This periodic action allows the system to maintain malware detection capability while avoiding interference with user productivity during critical periods.
2Reliability
If scanning processes are performed to detect malware, then security is improved, but processing system resources are consumed
Solution Approach 1:
Entity properties are determined and recorded during low-usage periods as a preliminary action. This allows the system to prepare security checks in advance when resource consumption is minimal, maintaining security without consuming excessive processing resources during peak times.
Solution Approach 2:
The scanning process is made dynamic by adjusting when it executes based on system usage conditions. The system transitions between scanning and non-scanning states according to processing system resource availability and usage patterns, optimizing the balance between security and resource consumption.
3Measurement precision
If comprehensive malware scanning is performed, then detection accuracy is improved, but scan time increases
Solution Approach 1:
The system performs preliminary determination of entity properties during low-usage periods, preparing data that will be needed for accurate malware detection. This preliminary action allows comprehensive scanning to be completed more quickly during actual detection phases, reducing overall scan time while maintaining detection accuracy.
Solution Approach 2:
The scanning process is segmented into different phases: property determination during low-usage periods, recording of entity properties, and actual malware detection when needed. This segmentation allows each phase to be optimized independently, improving detection accuracy while reducing the time required for comprehensive scanning.
Data Source
AI summary
A method/system of determining if one or more entities in a data storage medium of a processing system are malicious, wherein the method comprises recording entity properties of the one or more entities when at least part of the processing system is in a range of operating usage; and determining, using the entity properties, if the one or more entities are malicious.


