Malware Prevention via Command Reconstruction and Image Rendering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote connection methods over IP networks are vulnerable to attacks, especially when transferring data between secured and less secured networks, as traditional security measures fail to detect sophisticated or encrypted malicious activities, leading organizations to adopt costly and impractical solutions like offline operations or dedicated networks.

Innovation Solution

A system that uses a secured server to authenticate users and issue unique IDs, a protection module for validating and reconstructing commands, a rendering processor for generating images of data, and a secured transmission module for transmitting these images via a one-way channel, ensuring secure data exchange by reducing the attack surface and preventing malware infections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (firewalls, IPS, proxies) are used to protect network communications, then network security is improved, but sophisticated encrypted attacks and 0-Day attacks pass undetected

Engineering Contradiction:
Improvenetwork securityVSAvoidundetected malware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the unsecured network and secured network. This gateway performs protocol translation and data reconstruction, acting as a mediator that prevents direct communication while enabling controlled data exchange. The gateway translates unsecured network protocols into secured network protocols, thereby blocking malware transmission paths while allowing legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical security inspection methods (firewall rule matching, signature-based detection) with a fundamental architectural change - protocol translation and data reconstruction. Instead of inspecting and filtering traffic at network layers, the system reconstructs data at the application layer, eliminating the effectiveness of encrypted and obfuscated attack vectors.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If organizations work offline or create dedicated separate networks to prevent malware infections, then security is improved, but network connectivity and operational efficiency deteriorate

Engineering Contradiction:
Improvemalware preventionVSAvoidnetwork connectivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway device serves as an intermediary that enables secured networks to access unsecured networks without direct connectivity. Organizations can maintain their secured network infrastructure while gaining controlled access to external resources through the gateway, which translates and reconstructs data to prevent malware transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network communication into distinct translation and reconstruction stages at the gateway. This segmentation allows the secured network to maintain its isolation while still accessing external resources, as the gateway handles all protocol translation and data reconstruction operations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If dedicated terminal servers and separate networks are created to ensure security, then security is improved, but costs and system complexity increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidnetwork infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device performs multiple functions - protocol translation, data reconstruction, security filtering, and network addressing - within a single system. This multi-functionality eliminates the need for separate dedicated terminal servers and complex network segmentation, reducing overall system complexity while maintaining security isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges protocol translation, security enforcement, and data reconstruction functions into a single gateway device. This consolidation simplifies the network architecture compared to traditional approaches requiring separate dedicated networks and terminal servers, reducing both complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2849407B1Method and system for prevention of malware infections
Publication Date: 2016.11.16 FIREGLASS
  • EP2849407B1 patent drawingFigure 1
  • EP2849407B1 patent drawingFigure 2
  • EP2849407B1 patent drawingFigure 3~4

AI summary

A system and method for prevention of malware infections, the system comprising: a secured server configured to authenticate a user and issue an identifier (ID) uniquely associated with the user, to receive a user input and to send commands based on the received input; a protection module configured to validate transmissions from the secured server, to reconstruct commands based on the commands sent from the secured server, and send the reconstructed commands comprising the unique user ID and a rendering processor configured to receive the reconstructed command from the protection module, to execute the reconstructed command, to acquire data from another machine based on the reconstructed command and to generate an image to represent the acquired data, the image comprising a stamp relating the image to the unique ID, wherein the protection module is placed in a transmission channel connecting between the secured server and the rendering processor.