Parallel Malware Ruleset Evaluation via Scanning Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing size and complexity of malware detection rulesets lead to significant computational resource usage and evaluation time, making it challenging to efficiently detect and verify potentially malicious applications and files on client devices, while traditional optimization methods are complex and prolonged, potentially reducing detection quality.

Innovation Solution

A parallel evaluation process is implemented in a networked computer environment where a security server divides malware samples into evaluation lists, distributes them across multiple scanning nodes, and optimizes the ruleset by determining redundant rules, efficient detection methods, and undetected samples, using a cloud-based evaluation server to scale resources and reduce evaluation time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the ruleset size increases to detect more malware variants, then detection coverage is improved, but computational resource usage and evaluation time increase

Engineering Contradiction:
Improvedetection coverageVSAvoidevaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the malware detection ruleset into multiple subsets and distributes them across multiple scanning nodes. Each scanning node evaluates a specific subset of rules against malware samples in parallel, enabling the system to maintain comprehensive detection coverage while reducing the evaluation time and computational load on any single node.

Inventive Principle:
Principle #1Segmentation

2Use of energy by moving object

If traditional sequential optimization methods are used to minimize computational costs, then resource efficiency is improved, but the optimization process becomes complex and prolonged

Engineering Contradiction:
Improvecomputational resource efficiencyVSAvoidoptimization process complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent implements self-service through automatic ruleset optimization where the system evaluates multiple ruleset configurations in parallel across scanning nodes, automatically identifies optimal configurations based on performance metrics, and deploys them without requiring manual intervention. This reduces both the complexity and time required for optimization while improving resource efficiency.

Inventive Principle:
Principle #25Self-service

3Productivity

If more scanning nodes are installed to reduce evaluation time, then processing speed is improved, but system complexity and resource management overhead increase

Engineering Contradiction:
Improveevaluation processing speedVSAvoidsystem management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates scanning nodes that are universal and multi-functional, capable of evaluating different ruleset subsets and handling various malware sample types. Each scanning node is designed to be interchangeable and can perform multiple evaluation tasks, simplifying system management while maintaining high processing speed through parallel operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11520887B2Parallel processing for malware detection
Publication Date: 2022.12.06 MALWAREBYTES INC
  • US11520887B2 patent drawing
  • US11520887B2 patent drawing
  • US11520887B2 patent drawing

AI summary

Client devices detect malware based on a ruleset received from a security server. To evaluate a current ruleset, an administrative client device initiates a ruleset evaluation of the malware detection ruleset. A security server partitions stored malware samples into a group of evaluation lists based on an evaluation policy. The security server then creates scanning nodes on an evaluation server according to the evaluation policy. The scanning nodes scan the malware samples of the evaluation lists using the rulesets and associate each malware sample with a rule of the ruleset based on the detections, if any. The security server analyzes the associations and optimizes the ruleset and stored malware samples. The security server sends the optimized ruleset to client devices such that they more efficiently detect malware samples.