Malware Detection via Sandbox Intermediary on Remote Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to effectively detect and prevent the spread of malware through portable data storage devices and remote network servers, as they often rely on limiting accessibility rather than direct threat mitigation, and existing anti-virus technologies are inefficient in detecting active malware on remote servers.

Innovation Solution

A method for detecting malicious network content on portable data storage devices and remote network servers involves analyzing data using heuristics and virtual machines to identify suspicious activity, providing real-time warnings and provisional clearance, and actively monitoring remote servers for malware before file downloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current anti-virus technology is used to detect malware on remote network servers, then detection capability is limited, but system complexity and resource consumption increase without effective real-time detection

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a sandbox environment as an intermediary between the remote network server and the user system. The sandbox acts as an isolated testing ground where suspicious files from remote servers can be executed and analyzed without risking the main system. This mediator enables effective malware detection while maintaining system simplicity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary detection by analyzing files in a sandbox environment before they are executed on the main system. By performing detection actions in advance in an isolated environment, the system can identify malware threats proactively, preventing them from reaching the user system and eliminating the need for complex real-time detection mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If accessibility to portable data storage devices is limited, then security is improved, but usability and data transmission efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic malware detection and analysis when portable data storage devices are connected to the system. The sandbox environment automatically analyzes files from USB drives without requiring user intervention or configuration. This self-service approach maintains full usability of portable devices while providing proactive security protection, as the system handles security checks transparently in the background.

Inventive Principle:
Principle #25Self-service

3Speed

If malware analysis is performed in real-time upon device connection, then detection speed is improved, but processing time and system resources increase

Engineering Contradiction:
Improvedetection speedVSAvoidprocessing time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent segments the malware analysis process into distinct phases: initial quick scanning in the sandbox environment, followed by more comprehensive analysis only for suspicious files. This segmentation enables rapid detection of obvious threats while conserving resources for deeper analysis of potentially malicious files, balancing detection speed with processing efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10282548B1Method for detecting malware within network content
Publication Date: 2019.05.07 MAGENTA SECURITY HOLDINGS LLC
  • US10282548B1 patent drawing
  • US10282548B1 patent drawing
  • US10282548B1 patent drawing

AI summary

Systems and methods for detecting malicious content are provided. In an exemplary embodiment, a method for detecting malicious content is described that detects when a client device has access to a remote network server of a communication network. The client device includes one or more processors. Thereafter, a controller being a device separate from the client device, activates one or more security programs within the remote network server. The security programs enable the controller to analyze data stored within or transmitted from the remote network server. Lastly, the controller analyzing the data to determine whether the data includes malware.