Server-Assisted Antimalware Client for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional antimalware solutions face challenges in efficiently detecting and remediating malware on host devices, particularly on resource-constrained mobile devices, due to the high processing and data overhead, and the need for frequent updates, which can degrade performance and be impractical for mobile environments.

Innovation Solution

A server-assisted antimalware system where a thin antimalware client on the host device collaborates with a remote antimalware support system to offload resource-intensive tasks, using a threat intelligence system to provide comprehensive malware detection and remediation, minimizing local processing and updating only necessary data, while the server handles more intensive operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional host-based antimalware tool is installed on the host device, then malware detection and remediation functionality is provided, but processing overhead and resource consumption increase significantly

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts resource-intensive antimalware processing functions from the host device and relocates them to a remote server. The host device retains only lightweight client functionality for communication and basic operations, while the server handles complex malware detection, analysis, and remediation tasks. This extraction resolves the contradiction by maintaining malware detection capability while eliminating the processing overhead that would otherwise burden the host device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a thin antimalware client as an intermediary between the host device and the remote server. This client acts as a mediator that communicates with the server, transmitting necessary information and receiving instructions, thereby enabling the host device to leverage remote processing power without requiring full antimalware functionality locally. This intermediary approach maintains detection reliability while minimizing local resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If frequent updates of remediation tools and virus definition files are downloaded to keep the antimalware tool current, then detection accuracy improves, but network bandwidth consumption and device performance degradation increase

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent extracts the need for frequent local updates by relocating the malware definition database and remediation tools to the remote server. Instead of downloading updates to the host device, the server maintains current malware intelligence and provides it on-demand to clients. This resolves the contradiction by maintaining high detection accuracy through server-side updates while eliminating the network bandwidth consumption and performance impact of frequent local downloads.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server performs preliminary actions by pre-processing and analyzing malware threats, maintaining an up-to-date database of malware signatures and behaviors. When a client needs detection capabilities, it receives pre-processed information from the server rather than requiring its own update mechanism. This preliminary action on the server side ensures detection accuracy is maintained without requiring frequent updates at the client level, thus reducing network bandwidth consumption.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If a thin antimalware client is used on resource-constrained mobile devices, then device performance is preserved, but local malware detection and remediation capability is limited

Engineering Contradiction:
Improvedevice performanceVSAvoidmalware remediation capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the heavy remediation functionality from the thin client and places it on the remote server. The client maintains only lightweight communication and coordination capabilities, while the server performs complex remediation operations such as malware removal, system restoration, and deep scanning. This extraction allows the device to maintain high performance while the server provides comprehensive remediation capability, resolving the contradiction between device performance and remediation effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The thin client creates simplified copies or representations of malware threats and transmits them to the server for analysis. Rather than attempting full local remediation, the client copies relevant threat information to the server, which then performs the actual remediation work. This copying approach enables the thin client to maintain device performance while still achieving effective malware remediation through server assistance.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9614865B2Server-assisted anti-malware client
Publication Date: 2017.04.04 MCAFEE LLC
  • US9614865B2 patent drawing
  • US9614865B2 patent drawing
  • US9614865B2 patent drawing

AI summary

A host-based antimalware client can interface with a server-based antimalware support server. A file is identified at a host device. It is determined whether local reputation data for the file is available at the host device for the file. A query is sent to an antimalware support system relating to the file. Particular reputation data is received from the antimalware support system corresponding to the query. It is determined whether to allow the file to be loaded on the host device based at least in part on the particular reputation data.