Proactive Malware Protection via Aggregated Security Knowledge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computers are vulnerable to malware attacks during the vulnerability window between the release of new malware and the availability of updates, as existing anti-malware systems struggle to detect polymorphic malware and address unknown vulnerabilities, leading to potential system infections and significant costs for disinfection and repair.

Innovation Solution

A system and method that aggregates the knowledge base of multiple anti-malware services and event detection systems to proactively protect computers by observing suspicious events, determining if they satisfy a predetermined threshold, and implementing a restrictive security policy to block network traffic and limit resource access, thereby preventing malware infection and spread.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional antivirus software with signature-based detection is used, then known malware can be detected, but polymorphic malware and unknown vulnerabilities cannot be detected during the vulnerability window

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidprotection during vulnerability window
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by proactively applying restrictive security policies before malware is confirmed or during the vulnerability window. Instead of waiting for signature-based detection, the system pre-establishes protective measures that limit malware execution and propagation capabilities in advance, addressing the gap between malware release and antivirus update.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts security policies based on observed suspicious events and aggregated knowledge from multiple sources. Security restrictions are not static but adapt in real-time to emerging threats, allowing the system to respond to polymorphic and unknown malware variants that static signature-based approaches cannot detect.

Inventive Principle:
Principle #15Dynamics

2Reliability

If restrictive security policies are applied proactively, then malware infection risk is reduced, but system accessibility and user convenience may be degraded

Engineering Contradiction:
Improveprotection against malwareVSAvoidsystem accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies partial restrictive policies rather than complete isolation. Instead of blocking all network traffic and resource access, it selectively applies restrictions based on aggregated threat intelligence and observed suspicious events, maintaining sufficient system accessibility while providing adequate protection during the vulnerability window.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements feedback mechanisms that continuously monitor system operations and adjust security policies accordingly. By aggregating knowledge from multiple anti-malware services and observing suspicious events, the system receives feedback on actual system behavior and modifies restrictions to balance protection needs with operational convenience, preventing both over-restriction and under-protection.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If multiple anti-malware services and event detection systems are aggregated, then detection capability improves, but system complexity increases

Engineering Contradiction:
Improvesuspicious event detection capabilityVSAvoidsecurity system architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges multiple anti-malware services and event detection systems into a unified architecture that aggregates their knowledge bases. By combining detection capabilities from various sources and coordinating their operations through a centralized policy application mechanism, the system achieves enhanced detection precision without proportionally increasing operational complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a multi-functional security platform that performs detection, analysis, and policy application across multiple services simultaneously. The aggregated knowledge base serves universal purposes across different detection systems, and the restrictive policy mechanism provides a unified response to threats from any source, reducing the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8516583B2Aggregating the knowledge base of computer systems to proactively protect a computer from malware
Publication Date: 2013.08.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8516583B2 patent drawing
  • US8516583B2 patent drawing
  • US8516583B2 patent drawing

AI summary

In accordance with the present invention, a system, method, and computer-readable medium for aggregating the knowledge base of a plurality of security services or other event collection systems to protect a computer from malware is provided. One aspect of the present invention is a method that proactively protects a computer from malware by using anti-malware services or other event collection systems to observe suspicious events that are potentially indicative of malware; determining if the suspicious events satisfy a predetermined threshold; and if the suspicious events satisfy the predetermined threshold, implementing a restrictive security policy designed to prevent the spread of malware.