Software Authentication via Behavior Analysis and Whitelist Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software authentication methods, such as those using electronic signatures and whitelists, are inadequate in distinguishing between safe and malicious software, leading to increased damage from undetected malware like ransomware, and struggle to efficiently authenticate software operations and user behaviors.
Innovation Solution
A safety software authentication system and method that collects and analyzes software operation and user behavior data to determine the authenticity of software, using a processor to detect and register software based on preset technical and social engineering conditions, thereby adding it to a whitelist for safe execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If electronic signature authentication is used for software verification, then software authenticity can be confirmed, but malicious software can also use electronic signatures to disguise itself as normal software
Solution Approach 1:
Instead of only checking if software has an electronic signature (traditional approach), the patent inverts the approach by checking if software is in the whitelist. If software is not in the whitelist, it is automatically blocked regardless of whether it has an electronic signature. This inversion makes it difficult for malicious software to disguise itself, as the default position is blocking rather than allowing.
2Reliability
If a whitelist is used to verify software safety, then safe software can be identified, but it is difficult to include lots of software information in the whitelist and lacks ability to authenticate safety software
Solution Approach 1:
The patent applies preliminary action by pre-collecting software information including operation data, behavior data, and environment data before software execution. This pre-collected information is used to automatically generate whitelist entries, eliminating the need for manual whitelist management and enabling comprehensive software verification without increasing management complexity.
Solution Approach 2:
The system implements self-service by automatically collecting software operation and behavior data, analyzing the data to determine software safety, and automatically adding safe software to the whitelist without requiring manual intervention. This self-service mechanism handles large volumes of software information efficiently.
3Speed
If traditional software authentication methods are used, then execution speed is fast, but they cannot detect ransomware that is not in the whitelist or vaccine database
Solution Approach 1:
The patent performs preliminary collection of software operation data, behavior data, and environment data before execution. This pre-collection enables rapid authentication without requiring real-time analysis during execution, maintaining fast execution speed while improving detection capability through comprehensive pre-gathered information.
Solution Approach 2:
The system implements feedback by continuously monitoring software operation and behavior data, comparing it against safety criteria, and using this feedback to automatically update the whitelist. This feedback mechanism enables the system to adapt to new threats while maintaining fast execution through automated decision-making.
Data Source
AI summary
A safety software authentication terminal and a method thereof are provided, and when a safety software authentication is performed, software executed among a plurality of types of installed software is detected as a white list verification target, and whether or not to register detected verification target software in a white list, and when the verification target software is not registered in the white list, a grade is determined for the verification target software based on the number of satisfying conditions among a plurality of preset conditions, and when the grade can be registered in the white list, the verification target software is added to the whitelist, and the plurality of conditions include at least one of technical conditions that an operating system of the terminal is checkable and social engineering conditions that are checkable based on a behavior of a user.


