Social Network Malware Containment via Contact Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Social networks are vulnerable to malware spread due to the lack of effective defense mechanisms against unknown threats and incomplete security installations, which conventional security approaches struggle to address effectively.

Innovation Solution

A method that utilizes social network connections to quarantine affected users by increasing security measures on their contacts, employing a client-side security component, social networking applications, and a backend system to detect and contain malware spread by identifying and anonymizing user identities, and dynamically adjusting security levels based on threat assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security approaches are used to detect and block malware, then known threats can be defended against, but zero day attacks and infections on systems without up-to-date security cannot be prevented

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprotection against unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from traditional single-host security analysis to multi-dimensional network-wide analysis by examining communication patterns across the entire social network. This dimensional shift enables detection of zero-day threats through collective behavioral analysis rather than relying on individual system defenses or known malware signatures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The security system performs multiple functions simultaneously: it monitors individual host security status, analyzes network-wide communication patterns, identifies suspicious behavior, and coordinates quarantine actions across multiple systems. This multi-functional approach allows the system to address both known and unknown threats through a unified mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security software is deployed on individual systems to detect malware, then local infections can be detected, but spread through social networks cannot be effectively contained

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidprevention of widespread infection
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements continuous feedback loops where security clients report status to a central server, which analyzes patterns and sends quarantine instructions back to affected systems. This feedback mechanism enables dynamic response to spreading infections, allowing the network to adapt and contain threats as they propagate rather than relying on static individual defenses.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent merges individual host security detection capabilities with centralized network-wide analysis and coordination. By combining local detection with global pattern recognition and coordinated response, the system achieves both reliable malware detection and effective containment of network-wide spread.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the security level is increased on contacts of infected users to prevent spread, then malware propagation is inhibited, but user convenience and system performance may be degraded

Engineering Contradiction:
Improveprotection levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security system dynamically adjusts protection levels based on real-time threat assessment rather than maintaining static high-security states. Contacts experience increased security measures only when and where threats are detected, allowing the system to maintain user convenience while providing targeted protection during active threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies different security measures to different users based on their specific risk levels. Rather than uniformly increasing security for all contacts, the system tailors protection measures to individual risk assessments, maintaining ease of operation for low-risk users while providing enhanced protection where needed.

Inventive Principle:
Principle #3Local quality

4Loss of information

If anonymized identities are used to protect privacy during threat analysis, then user privacy is preserved, but tracking and response effectiveness may be reduced

Engineering Contradiction:
Improveprivacy protectionVSAvoidthreat tracking accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The system introduces anonymized identifiers as an intermediary between user identity and threat analysis. These intermediaries preserve privacy by decoupling personal information from security data, while the centralized server maintains the ability to track and coordinate responses through the anonymized identifiers without requiring access to sensitive personal information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9124617B2Social network protection system
Publication Date: 2015.09.01 WITHSECURE CORP (A K A WITHSECURE OYJ)
  • US9124617B2 patent drawing
  • US9124617B2 patent drawing
  • US9124617B2 patent drawing

AI summary

A method of inhibiting the spread of malware across a network of interconnected computer terminals. The method includes detecting malware or suspicious behavior at a first computer terminal and inspecting the first computer terminal, before and/or after said step of detecting malware or suspicious behavior, to identify contacts forming part of a social network. Identities of the identified contacts are sent to a backend security system, and at the backend security system, said identities are received and instructions sent to one or more second computer terminals associated with respective identities to cause those second computer terminals to implement an increased level of security.