Proactive Malicious Shared Library Detection via Remote Reputation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems are ineffective in proactively detecting malicious shared libraries, which can be injected or loaded by malware to compromise user data and system integrity, as they often rely on traditional detection methods that may fail to identify newly introduced or mutated malware.
Innovation Solution
A proactive detection method utilizing a remote reputation system that scans electronic devices for suspicious shared libraries, collects historical data from multiple devices, and compares it against known malware patterns to identify and classify shared libraries as potentially malicious, employing a scanner and reputation server to determine the malicious nature of shared libraries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional detection methods are used, then system simplicity is maintained, but detection effectiveness against new malware fails
Solution Approach 1:
The patent transitions from local, device-level detection to a distributed, network-based detection system. By collecting shared library data from multiple electronic devices and analyzing it centrally, the system adds a network dimension to traditional local scanning, enabling detection of malware patterns that span across multiple devices while maintaining relatively simple local agents.
Solution Approach 2:
The patent introduces a reputation server as an intermediary between local scanning systems and malware databases. This intermediary collects, aggregates, and analyzes shared library information from multiple devices, then provides reputation assessments back to local systems, effectively mediating between distributed detection points and central intelligence.
2Reliability
If proactive detection of suspicious shared libraries is implemented, then security detection capability is improved, but false positive rate increases
Solution Approach 1:
The patent implements a feedback mechanism where the reputation server receives detection results from multiple devices, analyzes patterns, and updates reputation information that is then fed back to local systems. This continuous feedback loop allows the system to learn from actual malware behavior across the network, refining detection accuracy and reducing false positives over time.
Solution Approach 2:
The system enables self-service detection by having each electronic device automatically scan its own shared libraries, report findings to the reputation server, and receive updated detection criteria. This decentralized self-service approach distributes the detection workload while leveraging collective intelligence to improve individual device security without requiring manual intervention.
3Measurement precision
If historical data from multiple devices is collected and analyzed, then detection accuracy is improved, but data processing time increases
Solution Approach 1:
The patent applies preliminary action by having electronic devices continuously collect and report shared library information to the reputation server in the background, before detection is actually needed. This pre-collection and pre-analysis of data from multiple devices allows the reputation server to maintain updated malware intelligence ready for immediate deployment to local systems, reducing processing time when detection is required.
Data Source
AI summary
A method for proactively detecting shared libraries suspected of association with malware includes the steps of determining one or more shared libraries loaded on an electronic device, determining that one or more of the shared libraries include suspicious shared libraries by determining that the shared library is associated with indications that the shared library may have been maliciously injected, loaded, and/or operating on the electronic device, and identifying the suspicious shared libraries to a reputation server.


