Malware Detection System Dynamic Threat Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic message security systems fail to effectively protect against threats embedded in links and resources, as they often rely on outdated rules and signatures, and do not provide targeted protection to authorized users, leading to resource overload and inadequate threat detection.

Innovation Solution

A malware detection system that utilizes a messaging system database to dynamically check messages for threats by analyzing contact lists and message archives, and implements user authorization to ensure only authorized users receive threat protection, transforming links into encoded forms with additional security checks and warnings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security checks are performed on each link access, then threat detection capability is improved, but system resources (processor capacity, memory, network bandwidth) become overloaded

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary security checks when links are first encountered and caches the results. Subsequent accesses to the same links reuse the cached security status rather than performing full security checks again, reducing resource consumption while maintaining threat detection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements selective security checking based on link characteristics and user context. Not all links receive the same level of security scrutiny - the system adapts the depth and type of security checks based on local conditions such as link source, user authorization level, and historical security data

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If protected resource references are widely distributed, then security protection availability is improved, but system resources are overwhelmed due to excessive access requests

Engineering Contradiction:
Improvesecurity protection availabilityVSAvoidsystem resource capacity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system introduces an intermediary authorization layer between users and security checking resources. This intermediary verifies user credentials and authorization status before allowing access to security checking services, filtering out unauthorized requests that would otherwise consume system resources

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts security checking parameters based on user authorization status. Authorized users receive full security checking services, while unauthorized users have their requests limited or redirected, changing the operational parameters of the security system based on user credentials

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If static rules and signatures are used for threat detection, then system complexity is reduced, but threat detection effectiveness deteriorates due to outdated information

Engineering Contradiction:
Improvesystem complexityVSAvoidthreat detection effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system transitions from static security rules to dynamic security assessment. Security parameters and threat detection criteria are continuously updated based on current security data, user behavior patterns, and historical message analysis, allowing the system to adapt to new threats without requiring complete rule set replacements

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where security outcomes from message scanning and link checking are fed back into the system to refine future security decisions. This feedback loop allows the system to learn from past security events and improve threat detection effectiveness over time while maintaining manageable system complexity

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11258785B2User login credential warning system
Publication Date: 2022.02.22 MIMECAST SERVICES LTD
  • US11258785B2 patent drawing
  • US11258785B2 patent drawing
  • US11258785B2 patent drawing

AI summary

Virtually every online account requires login credentials like username and password for access. Using different credentials for each account can reduce the likelihood of unauthorized access to these accounts. Remembering all the different credentials, however, can be a challenge and it is not uncommon for a user to mistakenly provide credentials to a site that are for another, sensitive site. Accordingly, a system for warning a user of such an error is provided. The system includes a browser plugin that responds to a user entering their credentials at a requesting site by looking up an identifier of a trusted site associated with the user's credentials. The identifiers of the requesting and trusted sites are compared, and if they do not match, the browser plugin blocks the user from submitting their credentials to the requesting site. Advantageously, the system reduces the likelihood that credentials to sensitive accounts are provided by accident.