Server-Side Malware Detection via Cluster Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection techniques are resource-intensive, vulnerable to sophisticated malware, and lack automation, leading to inefficiencies in identifying and classifying malware, especially on devices with limited resources, and fail to detect new or intentionally hidden malware instances.

Innovation Solution

A server-side system that collects and analyzes interaction data from networked devices using cluster analysis and pattern recognition methods to identify and classify malware, correlating anomalous behavior with environmental data to determine propagation characteristics and potential response actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional malware detection techniques are used, then malware detection capability is provided, but resource consumption increases and device complexity increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a server-side intermediary system that performs resource-intensive malware detection and classification tasks remotely. Local devices only transmit minimal interaction data to the server, which analyzes the data using cluster analysis and pattern recognition algorithms. This intermediary approach transfers the computational burden from resource-constrained local devices to a centralized server, enabling effective malware detection without consuming excessive local resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual copy of the malware detection process by replicating analysis functions on the server side. Instead of executing full malware scans locally, the system transmits interaction data copies to the server where replicated detection algorithms analyze the data. This copying approach allows comprehensive malware analysis without requiring substantial local computational resources.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional malware detection techniques are used, then malware detection capability is provided, but device complexity increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server-side system acts as an intermediary that manages complex detection algorithms, data collection frameworks, and analysis processing externally. Local devices only need to implement simple data transmission functions, while the server handles the complexity of cluster analysis, pattern recognition, and malware classification. This separation of complexity reduces local device requirements while maintaining sophisticated detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized authority approach is used for malware detection, then detection capability is improved, but loss of information and privacy problems increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidprivacy problems
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system extracts only the essential interaction data needed for malware detection from local devices and transmits minimal information to the server. By taking out only the necessary data elements (such as process interactions, system calls, and behavioral patterns) rather than transmitting complete device state or user activity logs, the system maintains detection effectiveness while minimizing privacy intrusion and information loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by processing data locally at the server-side analysis point rather than collecting all raw data from devices. The server performs targeted analysis on extracted interaction patterns, maintaining privacy by not storing or processing unnecessary local device information. This approach ensures detection capability while preserving user privacy and reducing information loss.

Inventive Principle:
Principle #3Local quality

4Reliability

If traditional malware detection techniques are used, then known malware can be detected, but new or intentionally hidden malware evades detection

Engineering Contradiction:
Improvedetection of known malwareVSAvoiddetection of new malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by continuously collecting and analyzing interaction data from multiple devices to establish baseline behavioral patterns and anomaly profiles. Before encountering new malware, the system pre-processes data to identify deviation patterns that indicate malicious behavior. This preliminary data preparation enables the system to detect new and evolving malware variants by recognizing anomalous interaction patterns rather than relying solely on pre-programmed malware signatures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The server-side system implements feedback mechanisms where detected malware patterns and analysis results are fed back into the system to refine cluster analysis models and pattern recognition algorithms. This continuous feedback loop enables the system to adapt to new malware variants and improve its ability to detect previously unknown threats. The feedback from analyzing interaction data across multiple devices allows the system to update its understanding of malicious behavior patterns dynamically.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9411955B2Server-side malware detection and classification
Publication Date: 2016.08.09 QUALCOMM INC
  • US9411955B2 patent drawing
  • US9411955B2 patent drawing
  • US9411955B2 patent drawing

AI summary

A server-side system that detects and classifies malware and other types of undesirable processes and events operating on network connected devices through the analysis of information collected from said network connected devices. The system receives information over a network connection and collects information that is identified as being anomalous. The collected information is analyzed by system process that can group data based on optimally suited cluster analysis methods. Upon clustering the information, the system can correlate an anomalous event to device status, interaction, and various elements that constitute environmental data in order to identify a pattern of behavior associated with a known or unknown strain of malware. The system further interprets the clustered information to extrapolate propagation characteristics of the strain of malware and determine a potential response action.