Proactive Malware Protection via Aggregated Security Knowledge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computers are vulnerable to malware attacks during the vulnerability window between the release of new malware and the availability of updates, as existing anti-malware systems struggle to detect polymorphic malware and address unknown vulnerabilities, leading to potential system infections and significant costs for disinfection and repair.
Innovation Solution
A system and method that aggregates the knowledge base of multiple anti-malware services and event detection systems to proactively protect computers by observing suspicious events, determining if they satisfy a predetermined threshold, and implementing a restrictive security policy to block network traffic and limit resource access, thereby preventing malware infection and spread.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional antivirus software with signature-based detection is used, then known malware can be detected, but polymorphic malware and unknown vulnerabilities cannot be detected during the vulnerability window
Solution Approach 1:
The system performs preliminary actions by proactively applying restrictive security policies before malware is confirmed or during the vulnerability window. Instead of waiting for signature-based detection, the system pre-establishes protective measures that limit malware execution and propagation capabilities in advance, addressing the gap between malware release and antivirus update.
Solution Approach 2:
The system dynamically adjusts security policies based on observed suspicious events and aggregated knowledge from multiple sources. Security restrictions are not static but adapt in real-time to emerging threats, allowing the system to respond to polymorphic and unknown malware variants that static signature-based approaches cannot detect.
2Reliability
If restrictive security policies are applied proactively, then malware infection risk is reduced, but system accessibility and user convenience may be degraded
Solution Approach 1:
The system applies partial restrictive policies rather than complete isolation. Instead of blocking all network traffic and resource access, it selectively applies restrictions based on aggregated threat intelligence and observed suspicious events, maintaining sufficient system accessibility while providing adequate protection during the vulnerability window.
Solution Approach 2:
The system implements feedback mechanisms that continuously monitor system operations and adjust security policies accordingly. By aggregating knowledge from multiple anti-malware services and observing suspicious events, the system receives feedback on actual system behavior and modifies restrictions to balance protection needs with operational convenience, preventing both over-restriction and under-protection.
3Measurement precision
If multiple anti-malware services and event detection systems are aggregated, then detection capability improves, but system complexity increases
Solution Approach 1:
The system merges multiple anti-malware services and event detection systems into a unified architecture that aggregates their knowledge bases. By combining detection capabilities from various sources and coordinating their operations through a centralized policy application mechanism, the system achieves enhanced detection precision without proportionally increasing operational complexity.
Solution Approach 2:
The system creates a multi-functional security platform that performs detection, analysis, and policy application across multiple services simultaneously. The aggregated knowledge base serves universal purposes across different detection systems, and the restrictive policy mechanism provides a unified response to threats from any source, reducing the need for separate specialized systems.
Data Source
AI summary
In accordance with the present invention, a system, method, and computer-readable medium for aggregating the knowledge base of a plurality of security services or other event collection systems to protect a computer from malware is provided. One aspect of the present invention is a method that proactively protects a computer from malware by using anti-malware services or other event collection systems to observe suspicious events that are potentially indicative of malware; determining if the suspicious events satisfy a predetermined threshold; and if the suspicious events satisfy the predetermined threshold, implementing a restrictive security policy designed to prevent the spread of malware.


