Detecting Silent Spyware via Network-Update Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods are inadequate for detecting surreptitious spyware that does not reveal its presence through apparent browser hijacking or unwanted actions, making it difficult to identify keylogger or website visit tracking spyware without user suspicion.
Innovation Solution
The approach involves monitoring network transmission and user update activities to identify processes that perform network transmissions without substantive user updates, using an activities-to-code or code-by-code method, and grouping related processes to detect and quarantine potential spyware candidates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional spyware detection methods are used, then detection of obvious spyware (browser hijacking, pop-up ads) is achieved, but detection of surreptitious spyware (keyloggers, silent trackers) fails
Solution Approach 1:
The patent segments spyware detection into multiple independent monitoring components: network transmission monitoring, user update monitoring, and process identity tracking. Each component independently monitors a specific aspect of system activity, and their combined analysis enables detection of surreptitious spyware that single-method approaches miss.
Solution Approach 2:
The detection system performs multiple functions simultaneously: it monitors network transmissions, tracks user interface updates, identifies process identities, and correlates these data streams to detect various types of spyware including keyloggers and silent trackers, making the system universally applicable to diverse spyware threats.
2Adaptability or versatility
If spyware performs network transmissions without user updates, then surreptitious spyware can hide effectively, but detection becomes more difficult
Solution Approach 1:
The system establishes feedback loops where network transmission activity is continuously monitored and fed back for analysis against user update patterns. This feedback mechanism allows the system to detect anomalies where network activity occurs without corresponding user interface updates, revealing hidden spyware operations.
Solution Approach 2:
The patent adds a new dimension to spyware detection by monitoring the relationship between network transmission and user update activities. Instead of detecting spyware through a single dimension (e.g., only network activity), the system analyzes the correlation between multiple dimensions (network transmissions vs. user updates), enabling detection of surreptitious behavior patterns.
3Reliability
If spyware is detected through user updates, then apparent spyware is identified, but surreptitious spyware remains undetected
Solution Approach 1:
The system performs preliminary monitoring of network transmission activities before relying solely on user update detection. By establishing a baseline of network activity and process identities in advance, the system can detect surreptitious spyware that hasn't yet manifested through user interface updates, preventing information loss about hidden threats.
Data Source
AI summary
Tools and techniques are provided for detecting a particular type of spyware. Network activities and user update activities are monitored automatically, and the results are analyzed to identify related processes which perform network transmissions without performing substantive user updates. These processes are identified to a user and/or an administrator as potential spyware, and are then quarantined or otherwise handled based on instructions received from the user or administrator. In some cases, the monitoring and analysis begins with selection of a group of processes to monitor, while in other cases it begins with monitoring of network and/or user update activities in order to narrow the group of suspect processes. Devices, configured media, and method products are also described.


