Malicious Software Detection via Internet Resource Reputation Database

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security software relies on pre-defined signatures to detect malicious software, failing to recognize unknown behavior or code, and is unable to effectively differentiate between legitimate and illegitimate websites, leading to potential system corruption or crashes when downloading applications from unknown sources.

Innovation Solution

A method and apparatus using an Internet resource information database to monitor application downloads, identifying suspicious applications by comparing source and time information, and mitigating malicious activity by terminating execution, preventing input/output and network activity, and blocking external connections, while utilizing reputation data and threat indicia to assess application safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security software programs use pre-defined signatures to detect malicious software, then detection accuracy for known threats is improved, but the ability to detect unknown malicious software is worsened

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect unknown threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by collecting reputation data about Internet resources (websites, publishers, applications) before users download or execute them. This advance preparation creates a database of trusted and untrusted sources, enabling the system to block malicious software before it can infect the system, rather than relying solely on post-infection detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - the Internet resource information database containing reputation data - that mediates between the user and potential malicious software. This database acts as a buffer that evaluates and rates Internet resources, allowing the system to make informed decisions about whether to allow downloads or executions without directly exposing the system to unknown threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security software programs monitor all application downloads and executions, then detection capability is improved, but system performance and user convenience are worsened

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies local quality by selectively monitoring only specific Internet-related activities (downloads from websites, executions of downloaded applications) rather than all system activities. The reputation data is applied locally to Internet resource evaluations, allowing comprehensive security for web-based threats while maintaining system performance for other operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements self-service by automatically evaluating Internet resources against the reputation database and making blocking or allowing decisions without requiring user intervention. The security software autonomously compares source information against stored reputation data and executes appropriate actions (block, allow, prompt user) based on the evaluation results.

Inventive Principle:
Principle #25Self-service

3Reliability

If the system blocks all applications from unknown sources, then system security is improved, but user access to legitimate but unrecognized applications is worsened

Engineering Contradiction:
Improvesystem securityVSAvoiduser access to applications
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies partial action by blocking only those applications from unknown sources that have negative or suspicious reputation ratings, while allowing applications from sources with positive or neutral reputations. This selective approach provides security against clearly malicious sources while maintaining access to legitimate applications from reputable but perhaps less well-known publishers.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses feedback mechanisms where the reputation database is continuously updated based on user reports, system analysis of application behavior, and feedback from multiple users about the same Internet resource. This feedback loop allows the system to adapt to new threats and adjust its blocking decisions, reducing false positives while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8978139B1Method and apparatus for detecting malicious software activity based on an internet resource information database
Publication Date: 2015.03.10 CA TECH INC
  • US8978139B1 patent drawing
  • US8978139B1 patent drawing
  • US8978139B1 patent drawing

AI summary

A method and apparatus for detecting malicious software activity, using at least one processor, based on an Internet resource information database in memory is described. In one embodiment, a method for detecting malicious software activity, using at least one processor, based on an Internet resource information database in memory includes processing Internet activity to determine source and time information associated with at least one application download, comparing the Internet resource information database with the source and time information associated with the at least one application download to identify at least one suspicious application, and monitoring execution of the at least one suspicious application.