Heuristic Registry Persistence Point Analysis for Spyware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to effectively detect and thwart spyware/adware, which persist on computers without user permission and can be difficult to uninstall, often disguising their presence to extract sensitive information or display unwanted ads, while also risking false-positive declarations.
Innovation Solution
The method involves examining persistence points in a computer's operating system for unusual indicators such as pointers to temporary directories, registry values with excessive path lengths or null characters, and items present in the kernel but not the user interface, to suspect and declare the presence of malicious code, and subsequently block or investigate potential spyware/adware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing detection methods are used to identify spyware/adware, then detection capability is limited, but false-positive declarations increase
Solution Approach 1:
The patent changes the detection parameters from general file scanning to specific registry persistence point analysis. By examining registry keys, values, and their relationships to temporary directories, the system achieves more precise detection with fewer false positives, as these persistence mechanisms are characteristic of spyware/adware behavior.
Solution Approach 2:
The patent replaces traditional mechanical scanning methods with a heuristic analysis system that examines registry structures and relationships. This substitution enables intelligent detection based on behavioral patterns rather than simple signature matching, improving both precision and reliability.
2Measurement precision
If comprehensive scanning of all system areas is performed to detect malicious code, then detection thoroughness improves, but system performance and user experience deteriorate
Solution Approach 1:
The patent extracts and focuses analysis on specific high-value persistence points in the registry system rather than scanning all system areas. By targeting registry keys, values, and temporary directory relationships where spyware/adware commonly persist, the system achieves thorough detection with minimal performance impact.
Solution Approach 2:
The patent segments the detection process into specific registry areas (persistence points) rather than performing monolithic full-system scanning. This segmentation allows targeted examination of critical areas while leaving other system operations unaffected, maintaining productivity.
3Productivity
If spyware/adware detection is made more aggressive to catch all malicious code, then detection rate improves, but false-positive declarations increase
Solution Approach 1:
The patent implements feedback through heuristic analysis that evaluates multiple registry indicators together. By examining the combination of registry persistence points, temporary directory relationships, and behavioral patterns, the system achieves high detection rates while maintaining reliability through contextual validation rather than single-criterion detection.
4Ease of operation
If manual uninstallation methods are used for spyware/adware, then user control is maintained, but ease of removal deteriorates
Solution Approach 1:
The patent performs preliminary detection and identification of spyware/adware persistence mechanisms before removal is attempted. By pre-identifying registry keys, values, and temporary files associated with malicious code, the system prepares a targeted removal strategy that simplifies the uninstallation process while maintaining user control over the action.
Data Source
AI summary
Methods, apparati, and computer-readable media for detecting the presence of malicious computer code in a computer. In a method embodiment, persistence points in an operating system of the computer are examined (31). When a pointer to a temporary directory is found (32) at a persistence point, a declaration is made (34) of a suspicion of malicious code being present in the computer. Second and third method embodiments are used when the computer has a native operating system (14) controlling hardware (11) functions and a user-interface operating system (12) built on top of the native operating system (14). A fourth method embodiment is used when the computer has an operating system comprising a kernel (20) and a user interface (21).


