Server-Assisted Antimalware Client for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional antimalware solutions face challenges in efficiently detecting and remediating malware on host devices, particularly on resource-constrained mobile devices, due to the high processing and data overhead, and the need for frequent updates, which can degrade performance and be impractical for mobile environments.
Innovation Solution
A server-assisted antimalware system where a thin antimalware client on the host device collaborates with a remote antimalware support system to offload resource-intensive tasks, using a threat intelligence system to provide comprehensive malware detection and remediation, minimizing local processing and updating only necessary data, while the server handles more intensive operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional host-based antimalware tool is installed on the host device, then malware detection and remediation functionality is provided, but processing overhead and resource consumption increase significantly
Solution Approach 1:
The patent extracts resource-intensive antimalware processing functions from the host device and relocates them to a remote server. The host device retains only lightweight client functionality for communication and basic operations, while the server handles complex malware detection, analysis, and remediation tasks. This extraction resolves the contradiction by maintaining malware detection capability while eliminating the processing overhead that would otherwise burden the host device.
Solution Approach 2:
The patent introduces a thin antimalware client as an intermediary between the host device and the remote server. This client acts as a mediator that communicates with the server, transmitting necessary information and receiving instructions, thereby enabling the host device to leverage remote processing power without requiring full antimalware functionality locally. This intermediary approach maintains detection reliability while minimizing local resource consumption.
2Measurement precision
If frequent updates of remediation tools and virus definition files are downloaded to keep the antimalware tool current, then detection accuracy improves, but network bandwidth consumption and device performance degradation increase
Solution Approach 1:
The patent extracts the need for frequent local updates by relocating the malware definition database and remediation tools to the remote server. Instead of downloading updates to the host device, the server maintains current malware intelligence and provides it on-demand to clients. This resolves the contradiction by maintaining high detection accuracy through server-side updates while eliminating the network bandwidth consumption and performance impact of frequent local downloads.
Solution Approach 2:
The server performs preliminary actions by pre-processing and analyzing malware threats, maintaining an up-to-date database of malware signatures and behaviors. When a client needs detection capabilities, it receives pre-processed information from the server rather than requiring its own update mechanism. This preliminary action on the server side ensures detection accuracy is maintained without requiring frequent updates at the client level, thus reducing network bandwidth consumption.
3Productivity
If a thin antimalware client is used on resource-constrained mobile devices, then device performance is preserved, but local malware detection and remediation capability is limited
Solution Approach 1:
The patent extracts the heavy remediation functionality from the thin client and places it on the remote server. The client maintains only lightweight communication and coordination capabilities, while the server performs complex remediation operations such as malware removal, system restoration, and deep scanning. This extraction allows the device to maintain high performance while the server provides comprehensive remediation capability, resolving the contradiction between device performance and remediation effectiveness.
Solution Approach 2:
The thin client creates simplified copies or representations of malware threats and transmits them to the server for analysis. Rather than attempting full local remediation, the client copies relevant threat information to the server, which then performs the actual remediation work. This copying approach enables the thin client to maintain device performance while still achieving effective malware remediation through server assistance.
Data Source
AI summary
A host-based antimalware client can interface with a server-based antimalware support server. A file is identified at a host device. It is determined whether local reputation data for the file is available at the host device for the file. A query is sent to an antimalware support system relating to the file. Particular reputation data is received from the antimalware support system corresponding to the query. It is determined whether to allow the file to be loaded on the host device based at least in part on the particular reputation data.


