Heuristic Registry Persistence Point Analysis for Spyware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively detect and thwart spyware/adware, which persist on computers without user permission and can be difficult to uninstall, often disguising their presence to extract sensitive information or display unwanted ads, while also risking false-positive declarations.

Innovation Solution

The method involves examining persistence points in a computer's operating system for unusual indicators such as pointers to temporary directories, registry values with excessive path lengths or null characters, and items present in the kernel but not the user interface, to suspect and declare the presence of malicious code, and subsequently block or investigate potential spyware/adware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing detection methods are used to identify spyware/adware, then detection capability is limited, but false-positive declarations increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse-positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent changes the detection parameters from general file scanning to specific registry persistence point analysis. By examining registry keys, values, and their relationships to temporary directories, the system achieves more precise detection with fewer false positives, as these persistence mechanisms are characteristic of spyware/adware behavior.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical scanning methods with a heuristic analysis system that examines registry structures and relationships. This substitution enables intelligent detection based on behavioral patterns rather than simple signature matching, improving both precision and reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive scanning of all system areas is performed to detect malicious code, then detection thoroughness improves, but system performance and user experience deteriorate

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts and focuses analysis on specific high-value persistence points in the registry system rather than scanning all system areas. By targeting registry keys, values, and temporary directory relationships where spyware/adware commonly persist, the system achieves thorough detection with minimal performance impact.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the detection process into specific registry areas (persistence points) rather than performing monolithic full-system scanning. This segmentation allows targeted examination of critical areas while leaving other system operations unaffected, maintaining productivity.

Inventive Principle:
Principle #1Segmentation

3Productivity

If spyware/adware detection is made more aggressive to catch all malicious code, then detection rate improves, but false-positive declarations increase

Engineering Contradiction:
Improvedetection rateVSAvoidfalse-positive rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback through heuristic analysis that evaluates multiple registry indicators together. By examining the combination of registry persistence points, temporary directory relationships, and behavioral patterns, the system achieves high detection rates while maintaining reliability through contextual validation rather than single-criterion detection.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If manual uninstallation methods are used for spyware/adware, then user control is maintained, but ease of removal deteriorates

Engineering Contradiction:
Improveease of removalVSAvoiduninstallation complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent performs preliminary detection and identification of spyware/adware persistence mechanisms before removal is attempted. By pre-identifying registry keys, values, and temporary files associated with malicious code, the system prepares a targeted removal strategy that simplifies the uninstallation process while maintaining user control over the action.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8104086B1Heuristically detecting spyware/adware registry activity
Publication Date: 2012.01.24 GEN DIGITAL INC
  • US8104086B1 patent drawing
  • US8104086B1 patent drawing
  • US8104086B1 patent drawing

AI summary

Methods, apparati, and computer-readable media for detecting the presence of malicious computer code in a computer. In a method embodiment, persistence points in an operating system of the computer are examined (31). When a pointer to a temporary directory is found (32) at a persistence point, a declaration is made (34) of a suspicion of malicious code being present in the computer. Second and third method embodiments are used when the computer has a native operating system (14) controlling hardware (11) functions and a user-interface operating system (12) built on top of the native operating system (14). A fourth method embodiment is used when the computer has an operating system comprising a kernel (20) and a user interface (21).