Self-Healing Device Malware Recovery via Change Journal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus technologies face challenges in efficiently recovering from malware attacks due to the labor-intensive process of reversing damage, delays in obtaining necessary signatures, and the inability to cover malware variants, especially in devices without updated anti-virus software, leading to potential irreparable damage and indeterminate states of infection.

Innovation Solution

A system and method for analyzing changes on a device to determine the time of infection and restore the device to a previous trusted state using a change journal and disk state interface, allowing for selective recovery of changes and user confirmation, enabling faster and more effective recovery from malware attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based anti-virus technology is used to detect and remove malware, then malware detection capability is improved, but recovery time and effectiveness deteriorate due to labor-intensive reverse engineering and delays in obtaining signatures

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically capturing device state information (registry changes, file system changes, process information) at regular intervals before malware damage occurs. This pre-captured data is stored and ready for immediate use in recovery operations, eliminating the need for time-consuming reverse engineering during the recovery phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of the device state at different points in time through change journals and system state capture mechanisms. These copies include registry hives, file system metadata, and process information that can be restored to reverse the effects of malware, providing a rapid recovery path without needing to analyze the malware itself.

Inventive Principle:
Principle #26Copying

2Measurement precision

If manual reverse engineering of malware is performed to develop removal signatures, then accuracy of malware removal is improved, but productivity deteriorates due to labor-intensive process and delays

Engineering Contradiction:
Improveaccuracy of malware removalVSAvoidrecovery efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables self-service recovery by automatically analyzing captured device state changes to identify and reverse malware effects. The change journal and state capture mechanisms allow the system to autonomously determine what changes occurred and restore them without requiring manual reverse engineering or expert intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring device state changes, comparing current state against baseline information, and automatically identifying malicious modifications. This feedback loop enables the system to adapt to different malware variants and restore device state accurately without manual analysis.

Inventive Principle:
Principle #23Feedback

3Reliability

If existing anti-virus software is used on devices without updated subscriptions, then basic protection is maintained, but adaptability to new malware variants deteriorates

Engineering Contradiction:
Improvebasic protectionVSAvoidcoverage of malware variants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system provides dynamic protection by continuously capturing and analyzing device state changes in real-time, allowing it to adapt to new malware variants as they appear. The change journal mechanism enables the system to learn from new infections and update its recovery capabilities without requiring manual signature updates or subscriptions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system achieves universality through its broad-based state capture and analysis capabilities that work across multiple device types and malware variants. The change journal and state recovery mechanisms provide a universal approach that can handle various malware types without requiring device-specific or variant-specific signatures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of repair

If signature-based removal methods are used, then known malware can be removed, but indeterminate states of infection from back doors and unknown malware cannot be addressed

Engineering Contradiction:
Improverepair of known malwareVSAvoidhandling of indeterminate infection states
Core Design Contradiction:
Ease of repairVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary capture of device state information at regular intervals, creating a historical record of legitimate system states. When infection is detected, this pre-captured data provides a known good state to restore from, enabling recovery even when the current state is contaminated by unknown malware or back doors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of attempting to analyze and remove unknown malware from the current infected state (the conventional approach), the system inverts the approach by restoring the device to a known good previous state captured in the change journal. This inversion bypasses the need to understand or remove the unknown malware entirely.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7624443B2Method and system for a self-heating device
Publication Date: 2009.11.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7624443B2 patent drawing
  • US7624443B2 patent drawing
  • US7624443B2 patent drawing

AI summary

A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.