Proxy Server Antivirus Scanning Risk Probability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus scanning methods at proxy servers face challenges in balancing thoroughness with time delays, risking incomplete malware detection when reducing scanning intensity for faster content delivery.
Innovation Solution
A computer-implemented apparatus and method that optimizes antivirus scanning by selecting an appropriate algorithm based on the likelihood of malicious code in downloaded data, using a data analysis module to calculate an overall risk probability and selectively apply malware detection techniques of varying computational complexity, ensuring efficient and accurate scanning without compromising security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If thorough antivirus scanning is performed at the proxy server, then malware detection accuracy is improved, but content delivery time increases
Solution Approach 1:
The system dynamically adjusts the scanning algorithm selection based on real-time risk probability calculations. The data analysis module continuously evaluates multiple indicia and updates the overall risk probability, allowing the system to adaptively choose between lightweight and comprehensive scanning approaches, thereby optimizing the balance between detection accuracy and delivery speed
Solution Approach 2:
The system changes the parameter of scanning intensity by selecting different algorithms based on calculated risk probability. When risk probability is low, lightweight algorithms are used to minimize delay; when risk probability is high, comprehensive algorithms are applied to ensure thorough detection, thus adjusting the scanning parameter to match the actual threat level
2Loss of time
If antivirus scanning extensiveness is reduced to speed up content delivery, then content delivery time is improved, but malware detection reliability deteriorates
Solution Approach 1:
The system dynamically adjusts scanning extensiveness based on real-time risk assessment. The data analysis module evaluates multiple indicia including file type, source reputation, and threat intelligence to calculate overall risk probability, allowing the system to flexibly adjust scanning depth - using minimal scanning for low-risk content and full scanning for high-risk content, thus maintaining reliability while improving delivery speed
Solution Approach 2:
The system changes the scanning parameter (extensiveness) based on calculated risk probability. By selecting from multiple algorithms with varying degrees of thoroughness, the system optimizes the trade-off between detection reliability and delivery speed, applying only the necessary level of scanning for each specific content item
3Reliability
If multiple malware detection techniques are applied, then malware detection accuracy is improved, but computational complexity increases
Solution Approach 1:
The system segments the malware detection process into multiple stages with different algorithmic complexities. The data analysis module first evaluates low-complexity indicia and calculates preliminary risk probability, then selectively applies more complex detection techniques only when necessary, dividing the overall detection task into manageable segments based on risk levels
Solution Approach 2:
The system applies partial action by selecting only the necessary level of detection thoroughness for each content item. Instead of always applying all available detection techniques, the system applies only enough computational complexity to achieve reliable detection for the given risk level, avoiding excessive computation for low-risk content
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Aspect of the invention are directed to antivirus scanning, by a proxy server, of data downloaded from the network onto a PC workstation. The antivirus scanning is optimized for each scan by selecting an algorithm for that scan based on a determined overall likelihood that the downloaded data contains malicious code. Determination of the overall likelihood is augmented by the strength, or confidence, of statistical data relating to malware screening of results of previous downloads having similar parameters to the instant download.