Reputation-Based Security Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for detecting security vulnerabilities are retroactive and ineffective in identifying zero-day exploits, which can lead to system performance issues and data breaches.

Innovation Solution

A reputation-based system that assigns trust levels to applications, monitors system behavior, and generates rules to manage access permissions, allowing for real-time detection and mitigation of security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional retroactive analysis methods are used to detect security vulnerabilities, then the detection process is simple to implement, but the detection capability is insufficient for zero-day exploits and occurs too late to prevent damage

Engineering Contradiction:
Improvesecurity vulnerability detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing a reputation system that assigns trust scores to applications before they can exploit vulnerabilities. The system proactively monitors application behavior, system calls, and resource access patterns in advance, maintaining a reputation database that evaluates applications before they can cause harm. This allows the system to detect and respond to potential threats before they become actual security incidents, rather than waiting for retroactive analysis after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by continuously monitoring application behavior and updating reputation scores based on observed actions. The system collects data from multiple sources including system calls, resource access patterns, and behavioral anomalies, then feeds this information back into the reputation evaluation mechanism. This closed-loop feedback system dynamically adjusts trust levels and can automatically respond to changing threat conditions, enabling adaptive security that improves over time rather than relying on static detection rules.

Inventive Principle:
Principle #23Feedback

2Reliability

If proactive reputation-based monitoring is implemented to detect zero-day exploits, then the security detection capability is significantly improved, but the system complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity vulnerability detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent implements local quality by applying different levels of monitoring intensity and reputation evaluation granularity to different applications based on their risk profiles. High-risk applications with lower reputation scores receive more intensive monitoring and resource allocation, while trusted applications with high reputation scores receive minimal monitoring. This localized approach concentrates computational resources where they are most needed for security detection, rather than uniformly monitoring all applications at the same level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements parameter changes by dynamically adjusting monitoring thresholds, sampling rates, and analysis depth based on application reputation scores and current threat levels. When an application's reputation deteriorates or suspicious behavior is detected, the system automatically increases monitoring intensity and resource allocation. Conversely, trusted applications receive reduced monitoring overhead. This dynamic parameter adjustment allows the system to maintain high security detection capability while optimizing resource consumption based on actual risk conditions.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If continuous monitoring of system behavior is performed to assess application reputation, then the accuracy of vulnerability detection is improved, but the time required for analysis and response increases

Engineering Contradiction:
Improvebehavior analysis accuracyVSAvoiddetection and response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements partial action by selectively monitoring only the most relevant system calls, behavior patterns, and resource access events based on application reputation and risk profiles. Rather than analyzing every single system event in detail, the system focuses computational resources on suspicious or high-risk behaviors while using lighter-weight monitoring for trusted applications. This selective partial monitoring maintains high detection accuracy for critical threats while reducing overall analysis time and computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements periodic action by conducting reputation evaluations and detailed behavior analysis at scheduled intervals rather than continuously in real-time. The system uses periodic sampling of application behavior combined with event-triggered analysis when suspicious activities occur. This periodic monitoring approach, supplemented by on-demand deep analysis when needed, maintains measurement precision for detecting vulnerabilities while significantly reducing the average time required for continuous analysis compared to exhaustive real-time monitoring of all behaviors.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3014447B1Techniques for detecting a security vulnerability
Publication Date: 2018.09.26 GEN DIGITAL INC
  • EP3014447B1 patent drawingFigure 1
  • EP3014447B1 patent drawingFigure 2
  • EP3014447B1 patent drawingFigure 3

AI summary

Techniques for detecting security vulnerabilities are disclosed. In one particular embodiment, the techniques may be realized as a method for detecting security vulnerabilities including assigning a reputation to an application, distributing the reputation to a client, receiving monitored system behavior from the client related to the client executing the application, determining whether to change the reputation of the application based on the monitored system behavior, distributing the changed reputation to the client, receiving further monitored system behavior from the client, and determining whether to generate a rule for the application based on the monitored system behavior received from the client.