Sandboxed Application Service Blocking for Malware Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Sandboxed computing environments, designed to secure user and system data, often hinder security software's ability to effectively terminate, quarantine, or uninstall malicious applications, creating a vulnerability window where malware can negatively impact devices.

Innovation Solution

A system and method that identifies potential security risks within sandboxed environments, prompts users to remediate threats, and blocks malicious applications from launching services until a recommended security action is taken, thereby securing the device during the vulnerability window.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sandboxed environment isolates application data and code execution, then security of user and system data is improved, but security software's ability to terminate, quarantine, or uninstall malicious applications deteriorates

Engineering Contradiction:
Improvesecurity of user and system dataVSAvoidability of security software to terminate, quarantine, or uninstall applications
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary mechanism that allows security software to communicate with and control application services even when applications are sandboxed. The security software can identify application services, determine their security risk, and block or terminate them through coordinated system-level permissions, thus resolving the contradiction between sandbox isolation and security software effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If sandboxed environment prevents automatic security actions, then application isolation is maintained, but vulnerability window where malware can impact device increases

Engineering Contradiction:
Improveapplication isolationVSAvoidvulnerability window
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having security software proactively identify and block malicious application services before they can execute harmful operations. The system preemptively terminates or quarantines suspicious services, eliminating the vulnerability window while preserving sandbox isolation through controlled system-level interventions.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If security software cannot automatically terminate malicious applications, then user control is preserved, but device protection during remediation period deteriorates

Engineering Contradiction:
Improveuser controlVSAvoiddevice protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by implementing automated blocking and termination of malicious application services as a preemptive measure. This temporary automated intervention protects the device during the vulnerability window, while still allowing users to review and control the ultimate remediation actions, thus balancing device protection with user control.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3692440B1Systems and methods for preventing malicious applications from exploiting application services
Publication Date: 2022.09.28 GEN DIGITAL INC
  • EP3692440B1 patent drawingFigure 1
  • EP3692440B1 patent drawingFigure 2
  • EP3692440B1 patent drawingFigure 3

AI summary

The disclosed computer-implemented method for preventing malicious applications from exploiting application services may include (i) identifying an attempt by an application, executing within a sandboxed environment that isolates the application's data and code execution from at least one other application executing within an operating system on the computing device, to launch at least one application service, (ii) determining that the application represents a potential security risk, (iii) prompting a user of the computing device to remediate the potential security risk posed by the application by performing a recommended security action, and (iv) while waiting for the user to perform the recommended security action, securing the computing device by blocking the attempt by the application to launch the application service. Various other methods, systems, and computer-readable media are also disclosed.