Proxy Server Antivirus Scanning Risk Probability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus scanning methods at proxy servers face challenges in balancing thoroughness with time delays, risking incomplete malware detection when reducing scanning intensity for faster content delivery.

Innovation Solution

A computer-implemented apparatus and method that optimizes antivirus scanning by selecting an appropriate algorithm based on the likelihood of malicious code in downloaded data, using a data analysis module to calculate an overall risk probability and selectively apply malware detection techniques of varying computational complexity, ensuring efficient and accurate scanning without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If thorough antivirus scanning is performed at the proxy server, then malware detection accuracy is improved, but content delivery time increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidcontent delivery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts the scanning algorithm selection based on real-time risk probability calculations. The data analysis module continuously evaluates multiple indicia and updates the overall risk probability, allowing the system to adaptively choose between lightweight and comprehensive scanning approaches, thereby optimizing the balance between detection accuracy and delivery speed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of scanning intensity by selecting different algorithms based on calculated risk probability. When risk probability is low, lightweight algorithms are used to minimize delay; when risk probability is high, comprehensive algorithms are applied to ensure thorough detection, thus adjusting the scanning parameter to match the actual threat level

Inventive Principle:
Principle #35Parameter changes

2Loss of time

If antivirus scanning extensiveness is reduced to speed up content delivery, then content delivery time is improved, but malware detection reliability deteriorates

Engineering Contradiction:
Improvecontent delivery timeVSAvoidmalware detection accuracy
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system dynamically adjusts scanning extensiveness based on real-time risk assessment. The data analysis module evaluates multiple indicia including file type, source reputation, and threat intelligence to calculate overall risk probability, allowing the system to flexibly adjust scanning depth - using minimal scanning for low-risk content and full scanning for high-risk content, thus maintaining reliability while improving delivery speed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the scanning parameter (extensiveness) based on calculated risk probability. By selecting from multiple algorithms with varying degrees of thoroughness, the system optimizes the trade-off between detection reliability and delivery speed, applying only the necessary level of scanning for each specific content item

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple malware detection techniques are applied, then malware detection accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the malware detection process into multiple stages with different algorithmic complexities. The data analysis module first evaluates low-complexity indicia and calculates preliminary risk probability, then selectively applies more complex detection techniques only when necessary, dividing the overall detection task into manageable segments based on risk levels

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by selecting only the necessary level of detection thoroughness for each content item. Instead of always applying all available detection techniques, the system applies only enough computational complexity to achieve reliable detection for the given risk level, avoiding excessive computation for low-risk content

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2447876B1System and method for server-based antivirus scan of data downloaded from a network
Publication Date: 2016.09.07 AO KASPERSKY LAB
  • EP2447876B1 patent drawingFigure 1~2
  • EP2447876B1 patent drawingFigure 3
  • EP2447876B1 patent drawingFigure 4

AI summary

Aspect of the invention are directed to antivirus scanning, by a proxy server, of data downloaded from the network onto a PC workstation. The antivirus scanning is optimized for each scan by selecting an algorithm for that scan based on a determined overall likelihood that the downloaded data contains malicious code. Determination of the overall likelihood is augmented by the strength, or confidence, of statistical data relating to malware screening of results of previous downloads having similar parameters to the instant download.