Security Server Aggregate Detection for Malicious Object Trends

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Protection applications often fail to detect new strains of malicious software objects due to outdated definitions, leading to decreased security on clients, as they may not be able to identify or prevent the installation of malicious objects effectively.

Innovation Solution

A method is implemented to generate aggregate detection information by receiving client state information and new detection events from malware detection applications, which are then mapped and stored in a database to provide analytical data to an administrative client, enabling better protection against malicious objects by identifying trends and vulnerabilities in protection applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protection applications use outdated definitions to monitor malicious objects, then device complexity is reduced, but detection reliability deteriorates

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback by collecting detection events from multiple clients and feeding them back to generate aggregate detection information. This feedback mechanism allows the system to identify trends and update protection definitions based on real-world detection data, thereby improving detection reliability without requiring each individual protection application to maintain complex updated definitions

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary system that aggregates detection events from multiple clients and generates comprehensive detection information. This intermediary layer consolidates the complexity of maintaining updated definitions centrally, while individual protection applications can operate with simpler local definitions, resolving the contradiction between reliability and complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If protection applications monitor all active processes on clients, then detection precision is improved, but loss of time increases

Engineering Contradiction:
Improvedetection precisionVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by having individual protection applications perform localized monitoring with simpler definitions, while the aggregate system performs comprehensive analysis across multiple clients. This division allows precise detection without requiring every single application to execute time-consuming comprehensive checks, thus reducing overall detection time while maintaining precision

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent merges detection events from multiple clients into aggregate detection information, combining partial observations into a comprehensive view. This merging approach achieves high detection precision through collective intelligence while reducing the time burden on individual protection applications, as each only needs to report local findings rather than perform exhaustive analysis

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10250623B1Generating analytical data from detection events of malicious objects
Publication Date: 2019.04.02 MALWAREBYTES INC
  • US10250623B1 patent drawing
  • US10250623B1 patent drawing
  • US10250623B1 patent drawing

AI summary

A security server tracks malicious objects detected by malware detection applications that scan for malicious objects on clients. The security server also receives client information from the clients indicating client states. The client state describes one or more protection applications executing on the client that seek to identify and prevent malicious objects from taking malicious actions based on real-time monitoring. Thus, the security server may identify when the protection application fails to detect a malicious object. In addition, the security server maps detection events of malicious objects with corresponding client states to generate aggregate detection information for a population of clients. Analytical data can be derived from the aggregate detection information to identify trends useful for evaluating different types of protection applications. Furthermore, the security server may initiate automated actions based on the identified trends to improve detection and remediation of the malicious objects on the clients.