Stub File Security Loader for Data Processing Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security methods for data processing systems are inefficient in monitoring malicious code, particularly executable files, as they require high resource utilization and cannot detect non-activated or dormant malicious code, leading to low security levels and increased system load.

Innovation Solution

A security device and method that utilizes a stub file with a security loader to restore and execute the original executable file, incorporating a monitoring module to detect and block malicious activity during execution, thereby enhancing monitoring efficiency and minimizing system load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security devices randomly examine stored files and compare them with patterns in a database, then the monitoring process can be performed, but the security level is low and time and resources are wasted

Engineering Contradiction:
Improvesecurity levelVSAvoidtime and resources
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by creating a stub file that contains a stub program and original executable file before the actual execution. The stub program is pre-configured to monitor and control the execution of the original executable, enabling security monitoring to be established in advance rather than reacting after malicious code executes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The stub program acts as an intermediary between the user and the original executable file. It intercepts the execution process, monitors operations, and controls what the original executable can do, thereby providing security monitoring without requiring direct examination of all stored files

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional security devices examine all files present in a data processing system at predetermined intervals, then monitoring coverage is improved, but high-level specifications are required and system load increases

Engineering Contradiction:
Improvemonitoring coverageVSAvoidhigh-level specifications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring approach by focusing only on executable files that are actually executed, rather than examining all files in the system. The stub program is attached to specific executable files, creating targeted monitoring segments that reduce the overall complexity and resource requirements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The stub program performs self-service by automatically monitoring and controlling the execution of the original executable file without requiring external security devices to continuously scan the entire file system. The monitoring function is integrated into the execution process itself

Inventive Principle:
Principle #25Self-service

3Reliability

If conventional security devices randomly monitor the security level of files, then monitoring can be performed, but they cannot monitor non-activated or dormant malicious code that initiates malicious functions at specific processing times

Engineering Contradiction:
Improvemonitoring capabilityVSAvoiddetection of dormant malicious code
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The stub program is pre-installed in the stub file before execution, enabling it to monitor and detect dormant malicious code that activates at specific times. The preliminary setup ensures that the monitoring capability is already in place when the original executable runs, capturing malicious actions that would otherwise go undetected

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The stub program provides feedback by monitoring the execution process in real-time and detecting when dormant malicious code activates. It can respond to detected malicious behavior by blocking execution or alerting the user, creating a closed-loop security system that adapts to dynamic threats

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9990493B2Data processing system security device and security method
Publication Date: 2018.06.05 SOFTCAMP
  • US9990493B2 patent drawing
  • US9990493B2 patent drawing
  • US9990493B2 patent drawing

AI summary

Provided is a security device and method that protect a data processing system from various types of malicious code and prevent the divulgence of data and erroneous operation. The security device for a data processing system includes: an execution module configured to be called by a security loader when a stub file, including a security loader formed in a routine form and a stub composed of an original executable file, is executed, and to perform processing so that the original executable file restored from the stub by the security loader is executed; and a monitoring module configured to monitor the operation of the data processing system attributable to the execution of the restored original executable file.