Malicious Entity Detection Using Low-Usage Period Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and removing malware in processing systems are resource-intensive, leading to hindered system usage during scans and inefficiencies in identifying malicious entities.

Innovation Solution

A method that determines entity properties within a processing system's range of operating usage, records these properties, and assesses their maliciousness using cryptographic hashes, checksums, and other attributes, allowing for efficient identification and quarantine of malicious entities while minimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current methods of scanning for malware are used, then detection capability is improved, but processing system resources are consumed and user productivity is hindered

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by determining entity properties and recording them during low-usage periods before malware detection is needed. This allows the scanning process to be prepared in advance during off-peak times, so that when users need the system, the detection can proceed more efficiently without blocking user productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The scanning process is performed periodically during low-usage periods rather than continuously or during peak usage times. This periodic action allows the system to maintain malware detection capability while avoiding interference with user productivity during critical periods.

Inventive Principle:
Principle #19Periodic action

2Reliability

If scanning processes are performed to detect malware, then security is improved, but processing system resources are consumed

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing system resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Entity properties are determined and recorded during low-usage periods as a preliminary action. This allows the system to prepare security checks in advance when resource consumption is minimal, maintaining security without consuming excessive processing resources during peak times.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The scanning process is made dynamic by adjusting when it executes based on system usage conditions. The system transitions between scanning and non-scanning states according to processing system resource availability and usage patterns, optimizing the balance between security and resource consumption.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If comprehensive malware scanning is performed, then detection accuracy is improved, but scan time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidscan time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary determination of entity properties during low-usage periods, preparing data that will be needed for accurate malware detection. This preliminary action allows comprehensive scanning to be completed more quickly during actual detection phases, reducing overall scan time while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The scanning process is segmented into different phases: property determination during low-usage periods, recording of entity properties, and actual malware detection when needed. This segmentation allows each phase to be optimized independently, improving detection accuracy while reducing the time required for comprehensive scanning.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8640235B2Determination of malicious entities
Publication Date: 2014.01.28 GEN DIGITAL INC
  • US8640235B2 patent drawing
  • US8640235B2 patent drawing
  • US8640235B2 patent drawing

AI summary

A method/system of determining if one or more entities in a data storage medium of a processing system are malicious, wherein the method comprises recording entity properties of the one or more entities when at least part of the processing system is in a range of operating usage; and determining, using the entity properties, if the one or more entities are malicious.