Terminal Safeguarding via Configuration-Based Operation Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies lack flexibility in safeguarding methods, making it difficult to distinguish and protect targeted objects from malicious programs, leading to ineffective defense against threats.

Innovation Solution

A method and apparatus that detect programs operating on terminals, intercept operations, and determine whether they are legitimate or illegitimate based on configuration information, allowing for targeted monitoring and flexible safeguarding settings to differentiate between safeguarded objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a terminal performs general safeguarding on all programs, then security coverage is improved, but the ability to distinguish and protect targeted objects is worsened

Engineering Contradiction:
Improvesecurity coverageVSAvoidtargeted object distinction
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the safeguarding function into two distinct modes: general safeguarding for all programs and targeted safeguarding for specific objects. The safeguarding module switches between these modes based on whether configuration information for a targeted monitored object exists, allowing both broad security coverage and precise targeted protection to coexist without interference

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing different safeguarding treatments to different objects based on their configuration status. Targeted monitored objects receive enhanced protection with operation interception and legitimacy verification, while non-targeted objects receive standard safeguarding, optimizing security resources according to specific needs

Inventive Principle:
Principle #3Local quality

2Reliability

If a terminal intercepts all program operations for security checking, then security detection capability is improved, but system operation efficiency is worsened

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial action by intercepting operations only for targeted monitored objects rather than all programs. The safeguarding module checks configuration information to determine whether to intercept an operation, applying security verification selectively to high-priority objects while allowing normal operation for others, thus maintaining security detection capability while preserving system efficiency

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary action by pre-configuring targeted monitored objects and their protection parameters before runtime. The configuration information is prepared in advance, allowing the safeguarding module to quickly determine whether to intercept operations without performing complex analysis during execution, thereby reducing runtime overhead

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If a terminal provides flexible safeguarding settings for different objects, then adaptability is improved, but system complexity is worsened

Engineering Contradiction:
Improvesafeguarding flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a unified safeguarding module that handles both general and targeted safeguarding through a single configuration-based mechanism. The same module structure processes both types of objects by checking the presence of configuration information, providing flexible adaptability without requiring separate complex subsystems for different safeguarding modes

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11126716B2System security method and apparatus
Publication Date: 2021.09.21 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US11126716B2 patent drawing
  • US11126716B2 patent drawing
  • US11126716B2 patent drawing

AI summary

A safeguarding method, a safeguarding apparatus, and a computer storage medium are provided. The method includes detecting a program operating on a terminal, and intercepting an operation performed by the program; identifying an object on which the program performs the operation; obtaining configuration information of the object on the terminal, and determining, based on the configuration information, that the object is a targeted monitored object. The method further includes determining, based on the configuration information of the targeted monitored object, whether the operation performed by the program on the object is a legitimate operation; and canceling intercepting the operation if the operation is a legitimate operation, and continuously intercepting the operation if the operation is an illegitimate operation.