Subscription-Based Malware Detection System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection systems face scalability and resource constraints as network traffic increases, leading to decreased performance and the need for costly infrastructure expansions.
Innovation Solution
A subscription-based, cloud-based malware detection system with a multi-tenant architecture that includes a first subsystem for credential checks and access management, and a second subsystem for object evaluation, allowing for scalable and efficient malware detection without the need for extensive capital outlays.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If additional malware detection appliances are installed to handle increased network traffic, then malware detection capability is improved, but capital expenditure and deployment complexity increase
Solution Approach 1:
The patent combines multiple malware detection appliances into a single cloud-based service platform. Multiple tenants share common infrastructure resources (compute, storage, networking) through virtualization, eliminating the need for each organization to deploy and maintain separate physical appliances. This merging approach maintains detection capability while reducing overall infrastructure complexity and capital expenditure.
Solution Approach 2:
The cloud-based malware detection service provides universal functionality that serves multiple tenants simultaneously. A single infrastructure platform delivers malware detection, analysis, and response capabilities to numerous organizations, replacing the need for each to maintain dedicated appliances. This multi-functional approach scales detection capability across many users without proportionally increasing infrastructure complexity.
2Reliability
If malware detection appliances are deployed on-site, then detection performance is improved, but scalability and flexibility are reduced
Solution Approach 1:
The patent introduces a cloud-based service platform as an intermediary between organizations and malware detection capabilities. Instead of requiring on-site appliances, the service acts as a remote intermediary that receives network traffic data, performs detection and analysis in the cloud, and returns results to clients. This approach maintains high detection performance through centralized expertise while dramatically improving deployment flexibility and scalability.
Solution Approach 2:
The patent transitions malware detection from a localized on-premises model to a cloud-based service model, effectively moving the detection function to a different dimensional space (from local infrastructure to remote cloud infrastructure). This dimensional shift enables organizations to access enterprise-grade detection capabilities without deploying physical appliances, thereby improving both scalability and deployment flexibility while maintaining detection performance.
3Measurement precision
If dedicated malware detection appliances are used, then detection accuracy is improved, but resource constraints limit scalability
Solution Approach 1:
The patent fundamentally changes the resource allocation model from dedicated fixed resources per appliance to dynamic shared resources in a cloud environment. The cloud platform pools computational resources (CPU, memory, storage, networking) and dynamically allocates them based on demand, allowing the system to maintain high detection accuracy through centralized processing while scaling to serve multiple tenants without being constrained by individual appliance resource limits.
Data Source
AI summary
A computerized method is described for authenticating access to a subscription-based service to detect an attempted cyber-attack. More specifically, a request is received for a subscription for analysis of objects, which are supplied by a customer to a malware detection system. A customer identifier is assigned to the customer initiating the request for the subscription and a sensor associated with the customer is identified and an identifier of the sensor is associated with the customer identifier. Then, service policy level information pertaining to the subscription is associated with the identifier of the sensor, where the service policy level information includes a set of subscription attributes including object analysis restrictions.


