Program Integrity Monitoring for Website Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-virus and monitoring software are inadequate in detecting unknown viruses and script viruses, and they struggle with quick investigation and evidence collection during security breaches, especially in environments like websites and Point of Sale Terminals, where comprehensive security protection is challenging due to indiscriminate exclusion rules.
Innovation Solution
A program integrity monitoring and contingency management system that includes a monitoring-notifying module and a contingency management module, featuring a management unit for configuring exclusion and monitoring profiles, an integrity comparison unit for detecting abnormalities, an evidence-collecting unit for storing suspicious files, and a software malicious program detection unit for identifying malware, with automatic recovery capabilities to maintain system integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If whitelist file restriction mechanism is used to prevent hackers from exploiting upload loopholes, then security protection is improved, but the entire directory of the whitelist has to be excluded making it hard to enforce comprehensive and effective security protection
Solution Approach 1:
The patent segments the security monitoring approach by dividing files into different categories: system files (monitored for integrity changes), user upload files (excluded from integrity monitoring), and executable files (subject to hash verification). This segmentation allows the system to apply appropriate security measures to each category without indiscriminately excluding entire directories, thus maintaining comprehensive security protection while avoiding false alarms.
Solution Approach 2:
The patent applies different security monitoring qualities to different file locations and types. System files in protected directories undergo strict integrity monitoring with hash verification, while user upload directories are excluded from such monitoring to avoid false alarms. This local differentiation of security quality enables comprehensive protection where needed without sacrificing adaptability in user-facing areas.
2Measurement precision
If security monitoring software retains a large amount of log information for investigation and evidence collection, then detection capability is improved, but professional analysis is required making it difficult to satisfy the need for quick investigation and evidence collection
Solution Approach 1:
The patent performs preliminary actions by automatically collecting and preserving evidence (malicious files, registry modifications, process information) at the moment of detection. The system pre-configures collection rules and automatically executes evidence gathering when anomalies are detected, eliminating the need for manual evidence collection and professional analysis during incident response, thus enabling quick investigation while maintaining high detection capability.
Solution Approach 2:
The system implements self-service by automatically analyzing collected evidence, identifying malicious patterns, and generating investigation reports without requiring professional analysts. The automated evidence collection and analysis capabilities enable the system to quickly process security incidents independently, reducing both the time loss and dependency on expert personnel.
3Measurement precision
If existing anti-virus software is used to detect viruses, then known virus detection is improved, but it is poor in detecting unknown virus or script virus
Solution Approach 1:
The patent changes the detection parameter from signature-based matching (effective for known viruses) to hash-based integrity verification and behavioral monitoring (effective for unknown viruses). By calculating and comparing file hashes against baseline values, and monitoring file system changes, the system can detect unknown viruses and script viruses that have not been added to virus databases, thus improving adaptability while maintaining detection precision through multiple complementary methods.
Data Source
AI summary
The present disclosure provides a program integrity monitoring and contingency management system and method. The system includes a monitoring-notifying module and a contingency management module. The monitoring-notifying module includes a management unit configuring an exclusion profile and a program integrity monitoring profile, a setup unit establishing a file integrity baseline list according to the program integrity monitoring profile, a notifying unit, and an integrity comparison unit comparing the exclusion profile and the file integrity baseline list with the program integrity file, and generating an abnormality warning when the comparison result is abnormal and instructing the notifying unit to report the same. The contingency management module includes an evidence-collecting unit collecting and storing the program integrity file upon generation of an abnormality warning, and a software malicious program detection unit comparing the program integrity file with virus signatures in a database to determine whether the program integrity file is a software malicious program.


