Malware Status Indication in Electronic Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-malware technologies slow down electronic message transmission and consume resources by scanning messages on both sending and receiving devices, necessitating a more efficient method to indicate malware status without re-scanning.

Innovation Solution

Incorporating an indication of the malware status into the electronic message before transmission, allowing the recipient system to determine the status without re-scanning, using modules for determination, scanning, inclusion, and distribution, and potentially encrypting this information for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-malware technologies scan incoming electronic messages for malware, then recipient devices and networks are protected from malware, but transmission time is slowed and computing resources are consumed

Engineering Contradiction:
Improvemalware protectionVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs malware scanning at the sender's device before message transmission, incorporating the scan results into the message itself. This preliminary action eliminates the need for recipient devices to perform time-consuming scans, thus protecting against malware while reducing transmission time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the malware scan status and embeds it within the electronic message as metadata. The recipient system then uses this copied status information instead of performing a new scan, thereby preserving security while saving time and computational resources.

Inventive Principle:
Principle #26Copying

2Reliability

If both sending and receiving devices scan electronic messages for malware, then comprehensive malware detection is achieved, but computing resources are significantly consumed

Engineering Contradiction:
Improvemalware detectionVSAvoidcomputing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges the malware scanning function into a single location (the sender's device) and combines the scan results with the message itself. This eliminates redundant scanning at the recipient end, achieving comprehensive detection while reducing overall computing resource consumption across the system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The electronic message carries its own malware status information self-contained within its metadata. The recipient system can directly use this embedded status without needing to independently verify it through scanning, allowing the message to essentially certify its own security state and reducing the burden on recipient computing resources.

Inventive Principle:
Principle #25Self-service

3Productivity

If malware scan results are included with electronic messages, then recipient systems can determine status without re-scanning, but message structure becomes more complex

Engineering Contradiction:
Improvemessage delivery speedVSAvoidmessage structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent embeds the malware status information as nested metadata within the existing electronic message structure. This allows the scan results to be included without fundamentally altering the core message format, maintaining compatibility while enabling faster delivery through avoided re-scanning.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS9223980B1Systems and methods for indicating malware statuses of electronic messages
Publication Date: 2015.12.29 CA TECH INC
  • US9223980B1 patent drawing
  • US9223980B1 patent drawing
  • US9223980B1 patent drawing

AI summary

The disclosed computer-implemented method for indicating malware statuses of electronic messages may include (1) determining that a user is attempting to distribute an electronic message, (2) scanning the electronic message to determine a malware status of the electronic message, (3) before distributing the electronic message, including, with the electronic message, an indication of the malware status of the electronic message, and (4) after including the indication of the malware status with the electronic message, distributing the electronic message to a recipient system, where the recipient system uses the malware status included with the electronic message to determine the malware status of the electronic message. Various other methods, systems, and computer-readable media are also disclosed.