Reputation-Based Malware Signature Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security software relies on manual signature development for malware detection, which is time-consuming and ineffective in promptly addressing malicious infections, allowing malware to disrupt computers before detection and remediation.
Innovation Solution
A reputation-based analysis method that monitors application activity, generates reputation information, and determines a malicious signature from unreputed portions of this activity to detect and identify malware variants across computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual signature development is used for malware detection, then detection accuracy can be achieved, but the process is time-consuming and allows malware to disrupt computers before detection
Solution Approach 1:
The system performs preliminary monitoring and collection of application activity data from multiple computers before malware detection is needed. By continuously gathering side effect information and building reputation profiles in advance, the system prepares detection capabilities proactively rather than reactively, reducing the time needed when actual malware threats appear.
Solution Approach 2:
The system automatically generates malicious signatures by analyzing unreputed side effects from monitored application activity without requiring manual security analyst intervention. The automated process collects data, identifies patterns, and produces detection signatures independently, eliminating the time-consuming manual operations previously required.
2Reliability
If manual operations are used for signature development, then signature quality can be maintained, but the process is not automatic and requires significant manual effort
Solution Approach 1:
The system performs self-service by automatically analyzing application activity data, identifying unreputed side effects, and generating malicious signatures without human intervention. The automated analysis process maintains reliability by using consistent algorithms to evaluate side effect reputations and identify malicious patterns, eliminating variability in manual operations.
Solution Approach 2:
The system replaces manual mechanical operations with automated computational processes. Instead of security analysts manually examining malware and creating signatures, the system uses automated monitoring, reputation analysis, and pattern recognition algorithms to generate signatures, significantly increasing automation while maintaining quality through systematic analysis.
3Productivity
If reputation-based analysis is used to automatically generate signatures, then detection speed is improved, but the system complexity increases
Solution Approach 1:
The system segments the signature generation process into distinct modular components: monitoring application activity, collecting side effect data, evaluating reputation scores, identifying unreputed portions, and generating signatures. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while maintaining high productivity through efficient parallel processing of discrete tasks.
Data Source
AI summary
A method and apparatus for performing a reputation based analysis on a malicious infection to secure a computer. In one embodiment, the method includes monitoring application activity occurring at computers, generating reputation information associated with the application activity, in response to a malicious infection to at least one of the computers, examining the reputation information to access unreputed portions of the application activity that occurred at the at least one of the computers and determining a malicious signature based on the unreputed portions of the application activity.


