Security Server Aggregate Detection for Malicious Object Trends
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Protection applications often fail to detect new strains of malicious software objects due to outdated definitions, leading to decreased security on clients, as they may not be able to identify or prevent the installation of malicious objects effectively.
Innovation Solution
A method is implemented to generate aggregate detection information by receiving client state information and new detection events from malware detection applications, which are then mapped and stored in a database to provide analytical data to an administrative client, enabling better protection against malicious objects by identifying trends and vulnerabilities in protection applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If protection applications use outdated definitions to monitor malicious objects, then device complexity is reduced, but detection reliability deteriorates
Solution Approach 1:
The patent implements feedback by collecting detection events from multiple clients and feeding them back to generate aggregate detection information. This feedback mechanism allows the system to identify trends and update protection definitions based on real-world detection data, thereby improving detection reliability without requiring each individual protection application to maintain complex updated definitions
Solution Approach 2:
The patent introduces an intermediary system that aggregates detection events from multiple clients and generates comprehensive detection information. This intermediary layer consolidates the complexity of maintaining updated definitions centrally, while individual protection applications can operate with simpler local definitions, resolving the contradiction between reliability and complexity
2Measurement precision
If protection applications monitor all active processes on clients, then detection precision is improved, but loss of time increases
Solution Approach 1:
The patent applies partial action by having individual protection applications perform localized monitoring with simpler definitions, while the aggregate system performs comprehensive analysis across multiple clients. This division allows precise detection without requiring every single application to execute time-consuming comprehensive checks, thus reducing overall detection time while maintaining precision
Solution Approach 2:
The patent merges detection events from multiple clients into aggregate detection information, combining partial observations into a comprehensive view. This merging approach achieves high detection precision through collective intelligence while reducing the time burden on individual protection applications, as each only needs to report local findings rather than perform exhaustive analysis
Data Source
AI summary
A security server tracks malicious objects detected by malware detection applications that scan for malicious objects on clients. The security server also receives client information from the clients indicating client states. The client state describes one or more protection applications executing on the client that seek to identify and prevent malicious objects from taking malicious actions based on real-time monitoring. Thus, the security server may identify when the protection application fails to detect a malicious object. In addition, the security server maps detection events of malicious objects with corresponding client states to generate aggregate detection information for a population of clients. Analytical data can be derived from the aggregate detection information to identify trends useful for evaluating different types of protection applications. Furthermore, the security server may initiate automated actions based on the identified trends to improve detection and remediation of the malicious objects on the clients.


