Multi-layer Malware Detection Visualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting malware, especially repackaged versions, are ineffective due to their reliance on pattern matching and deep packet inspection, which can miss hidden or obfuscated malicious code, leading to logistical challenges in organizing and presenting vast amounts of malware threat data.
Innovation Solution
A system comprising multiple layers of anti-malware testing, where data from different sources is evaluated to identify malware types and visualize their spread, allowing for continuous updates and improved detection methods that do not solely depend on content analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional pattern matching and deep packet inspection methods are used to detect malware, then the detection process is simple and fast, but the detection reliability deteriorates because repackaged and obfuscated malware can evade detection
Solution Approach 1:
The detection system is segmented into multiple independent test layers (first test layer, second test layer, etc.), each performing specific anti-malware tests. This segmentation allows the system to handle complex detection tasks by dividing them into manageable components, improving reliability without overwhelming complexity in a single detection mechanism
Solution Approach 2:
The patent introduces a new dimension to malware detection by creating visualizations that map malware spread across network locations. This dimensional transformation from raw data to visual representations enables better detection and understanding of malware patterns that conventional packet inspection cannot capture
2Reliability
If multiple layers of anti-malware testing are implemented to improve detection reliability, then the detection capability improves, but the device complexity and data processing burden increase
Solution Approach 1:
The system extracts and processes only the necessary test data from each layer, separating useful information about malware types and spread patterns from the bulk of network traffic. This extraction approach maintains high detection reliability while reducing the processing burden on individual components
Solution Approach 2:
The patent creates visual representations (copies) of malware spread patterns and test results, allowing the system to analyze and present information without processing every raw data packet in detail. These visual copies enable efficient data processing and presentation while maintaining detection accuracy
3Measurement precision
If vast amounts of malware threat data are collected and analyzed, then the detection accuracy improves, but the ease of operation deteriorates due to logistical challenges in organizing and presenting the data
Solution Approach 1:
The system transforms complex, multi-dimensional malware data into visualizations that map malware vectors and types across network locations. This dimensional transformation makes the data more manageable and easier to interpret, maintaining high measurement precision while significantly improving ease of operation
Solution Approach 2:
The patent uses visualizations with color-coded representations to differentiate and highlight various malware types and their spread patterns. This color-coding approach organizes complex data intuitively, allowing users to quickly identify and operate with specific malware threats without processing raw data complexity
Data Source
AI summary
The present disclosure relates to methods and apparatus that collect data regarding malware threats, that organizes this collected malware threat data, and that provides this data to computers or people such that damage associated with these software threats can be quantified and reduced. The present disclosure is also directed to preventing the spread of malware before that malware can damage computers or steal computer data. Methods consistent with the present disclosure may optimize tests performed at different levels of a multi-level threat detection and prevention system. As such, methods consistent with the present disclosure may collect data from various sources that may include endpoint computing devices, firewalls/gateways, or isolated (e.g. “sandbox”) computers. Once this information is collected, it may then be organized, displayed, and analyzed in ways that were not previously possible.


