Malware Relevance Mapping Through Domain-Object Relationships
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security analysts lack the ability to effectively determine the relevance of malware to specific fields, leading to insufficient measures against cyber threats.
Innovation Solution
An information search method and device that calculate and output the level of relevance of malware to various fields by analyzing domain and relationship objects in a database, using type and label information to determine first and second levels of relevance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security analysts manually investigate malware using IoC information, then they can identify cyber threats, but they cannot effectively determine the relevance of malware to specific fields
Solution Approach 1:
The patent introduces an automated information search device as an intermediary between security analysts and malware data. This device calculates relevance levels by querying databases and analyzing relationships between malware and fields, thereby providing precise relevance determination without requiring analysts to manually perform complex assessments.
Solution Approach 2:
The patent replaces the manual mechanical process of field relevance assessment with an automated computational system. The information search device uses algorithms to calculate relevance levels based on database queries and relationship analysis, substituting human manual evaluation with automated mechanical computation to achieve both precision and operational ease.
2Productivity
If security analysts investigate all malware without field relevance information, then they can maintain comprehensive security coverage, but they cannot implement targeted and effective measures
Solution Approach 1:
The patent performs preliminary action by pre-calculating and storing relevance level information in the database before security incidents occur. The information search device queries this pre-computed data to quickly provide field relevance information, enabling security analysts to immediately implement targeted measures without losing critical relevance knowledge during incident response.
Solution Approach 2:
The patent establishes a feedback mechanism where the information search device continuously queries the database for relevance level information and provides this feedback to security analysts. This feedback loop ensures that analysts always have access to current field relevance knowledge, enabling them to implement effective targeted security measures while maintaining comprehensive coverage.
3Measurement precision
If the database stores detailed label information for all domain objects, then relevance calculation accuracy improves, but the device complexity increases
Solution Approach 1:
The patent segments the database structure into distinct components: domain objects with type information, separate label information fields, and relationship objects. This segmentation allows the system to maintain detailed label information for accurate relevance calculation while managing complexity through structured organization. Each segment serves a specific function, making the overall system more manageable despite the detailed data storage requirements.
Data Source
AI summary
An information search method includes: calculating, for each of one or more non-malware-type domain objects, a first level of relevance between the non-malware-type domain object and each of a plurality of fields (a first relevance level calculation process); calculating one or more relevant non-malware-type domain objects for each of one or more malware-type domain objects (a relevant domain object calculation process); calculating, for each of the one or more malware-type domain objects, a second level of relevance between the malware-type domain object and each of the plurality of fields (a second relevance level calculation process); and outputting the second level of the relevance of at least one malware-type domain objects to an external device.


