Transaction Payload Simulation for Malware-Aware Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in effectively detecting and preventing malware attacks due to the exponential increase in malware variants, sophistication, and complexity, making it difficult to block or remove malware from computing systems.
Innovation Solution
A system utilizing simulated analytics and digital twin technology to continuously detect and prevent malware by simulating transactions on client devices, comparing expected and actual payload data for authorization, and providing real-time malware detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional antivirus software is used to block malware, then some malware can be removed, but malware activities continue to increase exponentially due to the diversity and sophistication of malware variants
Solution Approach 1:
The patent creates a digital twin (copy) of the client device that replicates its hardware and software environment. This digital twin is used to simulate transactions and generate expected payload data without affecting the actual device. By copying the device environment, the system can detect malware variants through comparison without being vulnerable to the same malware on the actual device.
Solution Approach 2:
The system performs preliminary simulation of transactions on the digital twin before executing them on the actual client device. By pre-calculating expected payload data and transaction outcomes in advance on the digital twin, the system establishes a baseline for comparison that enables real-time malware detection when actual transaction results differ from simulated results.
2Reliability
If simulated analytics and digital twin technology are used to detect malware, then detection effectiveness improves, but system complexity increases
Solution Approach 1:
The digital twin serves as an intermediary between the actual client device and the malware detection system. Instead of directly analyzing the complex actual device environment, the system interacts with the simplified digital twin representation, which mediates the detection process by providing simulated transaction data for comparison while isolating the complexity from the production system.
3Speed
If continuous simulation and comparison of payload data is performed for every transaction, then real-time malware detection is achieved, but processing time and computational resources increase
Solution Approach 1:
The system pre-simulates transactions on the digital twin and stores expected payload data before actual transactions occur. When a real transaction is executed, the system simply compares the actual payload against the pre-computed expected payload, reducing real-time processing to a fast comparison operation rather than requiring full simulation for each transaction.
Data Source
AI summary
Aspects of the disclosure relate to detecting and preventing malware attacks using simulated analytics and continuous authentication. An application server may receive device information and processing capabilities information of a client device. Based on the device information and the processing capabilities information, the application server may generate analytical output data indicating, for each transaction executed on the client device, a transaction processing time. The application server may receive transaction information associated with a transaction being executed at the client device. Based on the received transaction information and the analytical output data, the application server may simulate the transaction being executed at the client device and determine expected payload data. The application server may receive an authorization request including actual payload data associated with the transaction being executed at the client device. The application server may compare the expected payload data with the actual payload data and send an authorization response.


