Reputation-Based Malware Signature Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security software relies on manual signature development for malware detection, which is time-consuming and ineffective in promptly addressing malicious infections, allowing malware to disrupt computers before detection and remediation.

Innovation Solution

A reputation-based analysis method that monitors application activity, generates reputation information, and determines a malicious signature from unreputed portions of this activity to detect and identify malware variants across computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual signature development is used for malware detection, then detection accuracy can be achieved, but the process is time-consuming and allows malware to disrupt computers before detection

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidtime for signature development
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary monitoring and collection of application activity data from multiple computers before malware detection is needed. By continuously gathering side effect information and building reputation profiles in advance, the system prepares detection capabilities proactively rather than reactively, reducing the time needed when actual malware threats appear.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically generates malicious signatures by analyzing unreputed side effects from monitored application activity without requiring manual security analyst intervention. The automated process collects data, identifies patterns, and produces detection signatures independently, eliminating the time-consuming manual operations previously required.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual operations are used for signature development, then signature quality can be maintained, but the process is not automatic and requires significant manual effort

Engineering Contradiction:
Improvesignature qualityVSAvoidsignature development automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically analyzing application activity data, identifying unreputed side effects, and generating malicious signatures without human intervention. The automated analysis process maintains reliability by using consistent algorithms to evaluate side effect reputations and identify malicious patterns, eliminating variability in manual operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical operations with automated computational processes. Instead of security analysts manually examining malware and creating signatures, the system uses automated monitoring, reputation analysis, and pattern recognition algorithms to generate signatures, significantly increasing automation while maintaining quality through systematic analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If reputation-based analysis is used to automatically generate signatures, then detection speed is improved, but the system complexity increases

Engineering Contradiction:
Improvesignature generation speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the signature generation process into distinct modular components: monitoring application activity, collecting side effect data, evaluating reputation scores, identifying unreputed portions, and generating signatures. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while maintaining high productivity through efficient parallel processing of discrete tasks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8839432B1Method and apparatus for performing a reputation based analysis on a malicious infection to secure a computer
Publication Date: 2014.09.16 GEN DIGITAL INC
  • US8839432B1 patent drawing
  • US8839432B1 patent drawing
  • US8839432B1 patent drawing

AI summary

A method and apparatus for performing a reputation based analysis on a malicious infection to secure a computer. In one embodiment, the method includes monitoring application activity occurring at computers, generating reputation information associated with the application activity, in response to a malicious infection to at least one of the computers, examining the reputation information to access unreputed portions of the application activity that occurred at the at least one of the computers and determining a malicious signature based on the unreputed portions of the application activity.