Output Control Device for Malware Data Transmission Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-virus measures are becoming inadequate in preventing malware invasion, particularly due to the rise of new types of malware, and are increasingly difficult to manage effectively.
Innovation Solution
An output control system and method that includes a user terminal and a rating server, which assesses data characteristics and operational patterns to determine whether to permit or prohibit data output, using characteristic information collection, comparison with stored conditions, and user input to prevent malicious data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional anti-virus programs are used to prevent malware invasion, then malware prevention is provided, but the system becomes increasingly difficult to manage and less effective against new types of malware
Solution Approach 1:
Instead of preventing malware from entering the system (traditional approach), this invention inverts the approach by monitoring and controlling data output from the system. The output control apparatus detects attempts to output data from infected terminals and prohibits such output, thereby preventing malware transmission without requiring complex prevention mechanisms at the input stage.
Solution Approach 2:
The invention introduces an intermediary component (output control apparatus) between the infected terminal and the external network. This intermediary monitors data output attempts, determines whether they originate from infected terminals, and controls whether to permit or prohibit the output, thereby simplifying the overall system architecture while maintaining effective malware prevention.
2Reliability
If traditional anti-virus measures are applied, then malware detection is attempted, but new types of malware can still invade and existing measures become inadequate
Solution Approach 1:
The system performs preliminary detection by monitoring data output attempts before actual malware transmission occurs. By detecting characteristics of data being output from potentially infected terminals and comparing them against stored profiles, the system can identify and prohibit malicious output attempts in advance, providing proactive protection against both known and unknown malware types.
Solution Approach 2:
The invention changes the detection parameter from examining input data characteristics to analyzing output data characteristics. By monitoring what data attempts to leave the system rather than what enters, the approach becomes adaptable to new malware types since it focuses on the behavioral pattern of data exfiltration rather than relying on predefined malware signatures.
3Reliability
If comprehensive malware prevention is implemented, then security is improved, but the complexity of the system increases
Solution Approach 1:
The invention extracts the security control function from the complex ecosystem of traditional anti-virus programs and concentrates it in a dedicated output control apparatus. This separate component specifically handles data output monitoring and control, simplifying the overall system by isolating the security function from general system operations and reducing management complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Provided is an output section that outputs data to outside; a condition storage section that stores an abnormal condition showing at least one of a characteristic of data to be outputted from the output section by means of malicious software and a characteristic of an operational pattern of the output section that results when the malicious software outputs data; and an output control section that prohibits output of data when at least one of a characteristic of data to be outputted from the output section and a characteristic of an operational pattern of the output section satisfies the abnormal condition.