Malware Detection via Virtual Inspection and Aggregated Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection and mitigation solutions are ineffective against sophisticated, coordinated attacks, particularly in virtual and cloud infrastructures, due to their reliance on rigid hardware-based systems and legacy methods that fail to detect armored or multi-component malware, leading to increased resolution time, costs, and alert overload.
Innovation Solution
A system and method for monitoring malware events in a computer networking environment, involving data collection, inspection, analysis, and mitigation using a distributed network with inspection services, analytical algorithms, and infection verification packs (IVPs) to categorize threats and prioritize mitigation, capable of operating across multiple platforms and environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rigid hardware based solutions are used, then security detection capability is improved, but multi-site deployments become impractical and virtual/cloud infrastructure protection is unavailable
Solution Approach 1:
The patent creates virtual copies of security inspection capabilities through virtual machine instances that can be deployed across multiple sites and cloud infrastructures. These virtual instances replicate the security detection functionality without requiring physical hardware at each location, enabling widespread deployment while maintaining detection capability.
Solution Approach 2:
The patent replaces rigid hardware-based security systems with software-based virtual machine instances that run on general-purpose computing infrastructure. This substitution eliminates the need for specialized physical hardware while maintaining security detection capabilities, enabling flexible deployment across diverse environments including cloud infrastructures.
2Measurement precision
If legacy security solutions with structured processes are used, then analysis of agent behavior is improved, but time to resolution increases and alert overload occurs
Solution Approach 1:
The patent implements self-service capabilities where the security system automatically performs inspection, analysis, and mitigation actions without requiring manual intervention. Virtual machine instances autonomously execute security protocols, analyze threats, and implement countermeasures, significantly reducing resolution time while maintaining analysis accuracy.
Solution Approach 2:
The patent performs preliminary security inspections and threat assessments automatically as part of the virtual machine operation lifecycle. By conducting security analysis in advance and maintaining ready-to-deploy mitigation packages, the system reduces resolution time when actual threats are detected while preserving thorough analysis capabilities.
3Reliability
If legacy security solutions are used, then structured security processes are maintained, but cost increases due to overprovisioned appliances consuming 20-30% of security budget
Solution Approach 1:
The patent replaces expensive physical security appliances with virtual machine instances that can be deployed on existing infrastructure. This copying approach eliminates the need for overprovisioned hardware while maintaining security process reliability, significantly reducing the portion of budget consumed by security infrastructure.
Solution Approach 2:
The patent creates universal security virtual machine instances that can serve multiple functions across different sites and infrastructures. A single virtual machine image can be deployed to protect diverse environments, eliminating the need for specialized hardware at each location and reducing overall security infrastructure costs while maintaining reliable security processes.
Data Source
AI summary
Systems and methods for monitoring malware events in a computer networking environment are described. The systems and methods including the steps of identifying suspect objects; transmitting the suspect objects to an inspection service, wherein the inspection service inspects the suspect objects using a plurality of inspection methods to create digital information about the nature of the potential threat posed by the suspect objects; transmitting said digital information to an analytical service operating, wherein the analytical service performs a plurality of analytical algorithms to categorize the suspect objects with one or more scores for each suspect object based on their security threat; transmitting said one or more scores to a correlation facility which aggregates a plurality of scores; and generating an infection verification pack comprising routines which, when run on an end-point machine within the computer networking environment, will mitigate a suspected security threat.


