Detecting Silent Spyware via Network-Update Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods are inadequate for detecting surreptitious spyware that does not reveal its presence through apparent browser hijacking or unwanted actions, making it difficult to identify keylogger or website visit tracking spyware without user suspicion.

Innovation Solution

The approach involves monitoring network transmission and user update activities to identify processes that perform network transmissions without substantive user updates, using an activities-to-code or code-by-code method, and grouping related processes to detect and quarantine potential spyware candidates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional spyware detection methods are used, then detection of obvious spyware (browser hijacking, pop-up ads) is achieved, but detection of surreptitious spyware (keyloggers, silent trackers) fails

Engineering Contradiction:
Improvespyware detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments spyware detection into multiple independent monitoring components: network transmission monitoring, user update monitoring, and process identity tracking. Each component independently monitors a specific aspect of system activity, and their combined analysis enables detection of surreptitious spyware that single-method approaches miss.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The detection system performs multiple functions simultaneously: it monitors network transmissions, tracks user interface updates, identifies process identities, and correlates these data streams to detect various types of spyware including keyloggers and silent trackers, making the system universally applicable to diverse spyware threats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If spyware performs network transmissions without user updates, then surreptitious spyware can hide effectively, but detection becomes more difficult

Engineering Contradiction:
Improvespyware hiding capabilityVSAvoidspyware detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system establishes feedback loops where network transmission activity is continuously monitored and fed back for analysis against user update patterns. This feedback mechanism allows the system to detect anomalies where network activity occurs without corresponding user interface updates, revealing hidden spyware operations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent adds a new dimension to spyware detection by monitoring the relationship between network transmission and user update activities. Instead of detecting spyware through a single dimension (e.g., only network activity), the system analyzes the correlation between multiple dimensions (network transmissions vs. user updates), enabling detection of surreptitious behavior patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If spyware is detected through user updates, then apparent spyware is identified, but surreptitious spyware remains undetected

Engineering Contradiction:
Improvespyware identification reliabilityVSAvoidundetected spyware information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary monitoring of network transmission activities before relying solely on user update detection. By establishing a baseline of network activity and process identities in advance, the system can detect surreptitious spyware that hasn't yet manifested through user interface updates, preventing information loss about hidden threats.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8826427B2Detecting surreptitious spyware
Publication Date: 2014.09.02 GULA CONSULTING LLC
  • US8826427B2 patent drawing
  • US8826427B2 patent drawing
  • US8826427B2 patent drawing

AI summary

Tools and techniques are provided for detecting a particular type of spyware. Network activities and user update activities are monitored automatically, and the results are analyzed to identify related processes which perform network transmissions without performing substantive user updates. These processes are identified to a user and/or an administrator as potential spyware, and are then quarantined or otherwise handled based on instructions received from the user or administrator. In some cases, the monitoring and analysis begins with selection of a group of processes to monitor, while in other cases it begins with monitoring of network and/or user update activities in order to narrow the group of suspect processes. Devices, configured media, and method products are also described.