Malicious Software Detection via Internet Resource Reputation Database
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security software relies on pre-defined signatures to detect malicious software, failing to recognize unknown behavior or code, and is unable to effectively differentiate between legitimate and illegitimate websites, leading to potential system corruption or crashes when downloading applications from unknown sources.
Innovation Solution
A method and apparatus using an Internet resource information database to monitor application downloads, identifying suspicious applications by comparing source and time information, and mitigating malicious activity by terminating execution, preventing input/output and network activity, and blocking external connections, while utilizing reputation data and threat indicia to assess application safety.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security software programs use pre-defined signatures to detect malicious software, then detection accuracy for known threats is improved, but the ability to detect unknown malicious software is worsened
Solution Approach 1:
The system performs preliminary actions by collecting reputation data about Internet resources (websites, publishers, applications) before users download or execute them. This advance preparation creates a database of trusted and untrusted sources, enabling the system to block malicious software before it can infect the system, rather than relying solely on post-infection detection.
Solution Approach 2:
The patent introduces an intermediary mechanism - the Internet resource information database containing reputation data - that mediates between the user and potential malicious software. This database acts as a buffer that evaluates and rates Internet resources, allowing the system to make informed decisions about whether to allow downloads or executions without directly exposing the system to unknown threats.
2Reliability
If security software programs monitor all application downloads and executions, then detection capability is improved, but system performance and user convenience are worsened
Solution Approach 1:
The system applies local quality by selectively monitoring only specific Internet-related activities (downloads from websites, executions of downloaded applications) rather than all system activities. The reputation data is applied locally to Internet resource evaluations, allowing comprehensive security for web-based threats while maintaining system performance for other operations.
Solution Approach 2:
The system implements self-service by automatically evaluating Internet resources against the reputation database and making blocking or allowing decisions without requiring user intervention. The security software autonomously compares source information against stored reputation data and executes appropriate actions (block, allow, prompt user) based on the evaluation results.
3Reliability
If the system blocks all applications from unknown sources, then system security is improved, but user access to legitimate but unrecognized applications is worsened
Solution Approach 1:
The system applies partial action by blocking only those applications from unknown sources that have negative or suspicious reputation ratings, while allowing applications from sources with positive or neutral reputations. This selective approach provides security against clearly malicious sources while maintaining access to legitimate applications from reputable but perhaps less well-known publishers.
Solution Approach 2:
The system uses feedback mechanisms where the reputation database is continuously updated based on user reports, system analysis of application behavior, and feedback from multiple users about the same Internet resource. This feedback loop allows the system to adapt to new threats and adjust its blocking decisions, reducing false positives while maintaining security.
Data Source
AI summary
A method and apparatus for detecting malicious software activity, using at least one processor, based on an Internet resource information database in memory is described. In one embodiment, a method for detecting malicious software activity, using at least one processor, based on an Internet resource information database in memory includes processing Internet activity to determine source and time information associated with at least one application download, comparing the Internet resource information database with the source and time information associated with the at least one application download to identify at least one suspicious application, and monitoring execution of the at least one suspicious application.


