Malware Signature Update Scheduling via Peer Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware signature update systems incur significant computational resource expenses for both clients and servers, as they require frequent updates across numerous devices, making it difficult to assess the necessary update frequency for clients based on their exposure to malware threats.
Innovation Solution
A peer-based security engine determines an environmental safety score for clients by analyzing their own safety scores and those of their peer clients, allowing for targeted scheduling of malware signature updates based on the likelihood of exposure to malware threats, thereby reducing unnecessary resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If malware signatures are updated frequently for all clients, then malware detection capability is improved, but computational resource consumption and network traffic increase
Solution Approach 1:
The patent applies local quality by differentiating update frequencies based on individual client risk profiles. Instead of uniform updates for all clients, the system calculates a risk score for each client based on their specific characteristics (such as network connectivity, software versions, and threat intelligence data) and schedules updates accordingly. High-risk clients receive frequent updates while low-risk clients receive less frequent updates, optimizing the balance between detection capability and resource consumption.
Solution Approach 2:
The patent implements dynamics by making the update schedule adaptive and flexible rather than static. The system continuously monitors client environments and adjusts update frequencies dynamically based on changing risk conditions. Clients can transition between different update schedules based on their evolving risk profiles, allowing the system to respond to emerging threats while conserving resources during periods of low risk.
2Reliability
If malware signatures are updated frequently for all clients, then malware detection capability is improved, but network traffic increases
Solution Approach 1:
The patent applies local quality by tailoring network communication patterns to individual client needs. Instead of all clients checking for updates simultaneously, the system schedules updates based on each client's risk score and availability. This reduces overall network traffic while ensuring that high-risk clients maintain current signatures for effective malware detection.
3Use of energy by moving object
If malware signatures are updated less frequently, then computational resource consumption is reduced, but malware detection capability deteriorates
Solution Approach 1:
The patent resolves this contradiction by applying local quality through differentiated service levels. The system evaluates each client's risk profile and assigns appropriate update frequencies accordingly. High-risk clients receive frequent updates to maintain detection capability, while low-risk clients receive less frequent updates that reduce computational overhead. This localized approach ensures that resources are allocated efficiently based on actual risk needs rather than applying uniform standards to all clients.
Data Source
AI summary
Information is received from a set of peer clients associated with a client, the information indicating likelihoods of peer client exposure to malware threats. An environmental safety score associated with the client is determined based, at least in part, on the information received from the set of peer clients, wherein the environmental safety score indicates a likelihood that the client is exposed to malware threats. A set of malware signatures is retrieved from the server at a time determined responsive to the environmental safety score and stored.


