Backward Tracing Timestamped Events for Pestware Origin Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current pestware removal software is inefficient in locating and identifying the origin of pestware, often requiring cumbersome definition creation and struggling to differentiate between wanted and unwanted pestware, while existing technologies fail to effectively trace the source of pestware activity on computers.
Innovation Solution
A system and method that establishes a time of interest for suspected pestware activity, issues a timestamp, and uses recorded historical data to identify indicia of pestware, tracing back to the source through a combination of modules including a research module, heuristics module, and timestamp module, accessing activity logs and file information to determine the origin of pestware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current pestware removal software uses definitions of known pestware to search for and remove files, then pestware detection capability is provided, but the process is slow and cumbersome and difficult to initially locate the pestware origin
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and recording file system activities, registry changes, and process creations in real-time before pestware infections occur. This pre-collection of baseline data enables rapid backward tracing when pestware is detected, eliminating the need for time-consuming manual definition creation and origin location.
Solution Approach 2:
Instead of forward-searching for pestware using predefined definitions, the system inverts the approach by starting from detected pestware indicators and backward-tracing through recorded historical data to identify the origin. This reverse-engineering method quickly locates infection sources and automatically generates definitions without manual intervention.
2Adaptability or versatility
If pestware-detection software tries to handle differences between wanted and unwanted pestware, then user privacy and system performance issues are addressed, but differentiation capability becomes complex
Solution Approach 1:
The system applies local quality by analyzing specific characteristics and behaviors of individual pestware instances rather than applying uniform detection rules. By examining localized patterns in file operations, registry modifications, and network activities, the system can differentiate between malicious and benign software with simpler logic.
Solution Approach 2:
The system implements feedback mechanisms where user interactions and system responses to pestware detections are continuously monitored. This feedback loop enables the system to learn and adapt to differentiate between wanted and unwanted pestware over time, reducing complexity through experience-based differentiation rather than complex predefined rules.
3Measurement precision
If backward researching of time stamped events is implemented to find pestware origin, then source identification accuracy is improved, but data processing complexity increases
Solution Approach 1:
The system segments the complex task of origin identification into distinct chronological phases represented by time-stamped events. By dividing the investigation into discrete temporal segments (file creations, registry changes, process activations), the system achieves high source identification accuracy while managing complexity through structured, phase-by-phase analysis.
Solution Approach 2:
The system performs preliminary organization of time-stamped events and metadata before backward research is initiated. By pre-sorting and indexing activities chronologically with associated metadata, the system enables accurate source identification through simple sequential retrieval rather than complex real-time analysis.
Data Source
AI summary
A system and method for identifying an origin of suspected pestware activity on a computer is described. One embodiment includes establishing a time of interest relating to a suspicion of pestware on the computer; issuing a timestamp in response to the establishing the time of interest; identifying, in response to the issuing the timestamp, indicia of pestware; and accessing at least a portion of a recorded history of sources that the computer received files from so as to identify, based at least in part upon the identified indicia of pestware, a reference to an identity of a source that is suspected of originating pestware.


