Information Processing Device Malware Detection via Sandbox Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virus testing systems face difficulties in detecting newly generated unknown viruses, even with installed virus detection software.
Innovation Solution
An information processing device that includes a command acquisition unit, a remote control unit, a data transmission unit, an execution history storage unit, and a malware detection unit, which scans electronic data for malware and notifies other devices of infections, while restricting operations until a predetermined period expires.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virus testing software is installed on a computer, then virus detection capability is provided, but unknown viruses generated daily cannot be detected
Solution Approach 1:
The patent introduces a sandbox environment as an intermediary between the user's computer and potentially malicious files. The sandbox acts as a controlled execution space where suspicious files are analyzed without risking the host system. This mediator enables detection of unknown viruses by isolating them in a controlled environment where their behavior can be observed and analyzed by the malware detection unit.
Solution Approach 2:
The system performs preliminary analysis of files before they are executed on the user's computer. By scanning files in advance and analyzing their behavior in the sandbox environment prior to execution, the system can identify and block unknown viruses before they cause harm. This preliminary action includes transferring files to the execution environment for analysis before allowing them to run on the host system.
2Speed
If electronic data is executed directly on the local computer, then operation speed is fast, but virus infection risk increases
Solution Approach 1:
The sandbox environment serves as an intermediary execution layer between the local computer and potentially malicious files. Files are first executed in this isolated environment, which prevents direct infection of the host system while still allowing the files to run. The sandbox acts as a buffer that protects the local computer from virus infections while maintaining execution capability.
Solution Approach 2:
The system creates a virtual copy of the execution environment in the sandbox, allowing files to be executed in an isolated replica rather than on the actual host system. This copying approach enables the file to run with full functionality while the isolation prevents any harmful effects from propagating to the local computer, thus maintaining execution speed without increasing infection risk.
3Measurement precision
If multiple scans are performed during a predetermined period, then malware detection accuracy improves, but processing time increases
Solution Approach 1:
The malware detection unit continuously monitors and scans files within the sandbox environment throughout the predetermined period without interruption. By maintaining continuous scanning activity rather than performing discrete periodic scans, the system maximizes detection accuracy while the automated continuous process minimizes overall processing time compared to multiple separate manual scanning operations.
Solution Approach 2:
The system performs preliminary scanning and analysis actions automatically during the predetermined period before execution is allowed. By conducting multiple scan cycles in advance within the sandbox environment, the system achieves high detection accuracy through repeated verification, while the automated nature of these preliminary actions ensures they complete efficiently without significant time loss.
Data Source
AI summary
The present invention is provided with: a command acquisition unit that acquires a command related to operation of electronic data; a remote control unit that establishes a remotely controllable communication path with an execution environment in which the operation of the electronic data is to be executed, and transmits an execution instruction for executing the operation of the electronic data on the execution environment to the execution environment via the remotely controllable communication path; a data transmission unit that transmits the electronic data or the electronic data converted based on a predetermined algorithm to the execution environment; an execution history storage unit that stores the electronic data or the electronic data converted based on the predetermined algorithm for a predetermined period; and a malware detection unit that scans the electronic data stored or the electronic data converted based on the predetermined algorithm in the execution history storing unit to detect malware.


