Terminal Security Monitoring via Cumulative Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security monitoring systems for terminal systems either overwhelm users with frequent notifications of varying risk levels or fail to detect and remove non-triggered malicious programs, while static scanning requires manual initiation and lacks real-time relevance.

Innovation Solution

A method and apparatus that combine real-time monitoring with static scanning by assigning a risk score to running programs, prompting users only when the cumulative score exceeds a threshold, and performing automatic static scanning and virus killing when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If real-time monitoring is used to capture triggered system events, then sensitivity to detected risks is improved, but the number of popup notifications increases causing user disturbance

Engineering Contradiction:
Improverisk detection sensitivityVSAvoiduser experience
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating notification behavior based on risk level. High-risk events trigger immediate popup notifications, while low-risk events are aggregated and reported periodically. This selective approach ensures that users are promptly informed of critical threats while avoiding disturbance from minor security events, thus resolving the contradiction between detection sensitivity and user experience.

Inventive Principle:
Principle #3Local quality

2Loss of time

If real-time monitoring is used to notify users of malicious behavior, then response time is improved, but the ability to detect non-triggered malicious programs deteriorates

Engineering Contradiction:
Improvenotification response timeVSAvoidcompleteness of threat detection
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent merges real-time monitoring and static scanning into a unified security system. Real-time monitoring continuously detects triggered malicious behaviors and provides immediate notifications, while static scanning periodically performs comprehensive analysis of all programs including non-triggered ones. The combination of both approaches ensures both rapid response to active threats and complete detection of dormant threats, resolving the contradiction between response time and detection completeness.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If static scanning is used to perform comprehensive virus scanning, then scanning capability is improved, but the need for manual initiation reduces automation

Engineering Contradiction:
Improvescanning capabilityVSAvoidautomatic scanning frequency
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements periodic action by scheduling static scanning to execute automatically at predetermined intervals (e.g., daily, weekly). This automated periodic scanning maintains comprehensive threat detection capability without requiring manual user initiation. The system seamlessly integrates this periodic full scan with continuous real-time monitoring, ensuring both high scanning capability and high automation level, thus resolving the contradiction between scanning capability and automation extent.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10540497B2Method and apparatus for monitoring security of terminal system
Publication Date: 2020.01.21 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US10540497B2 patent drawing
  • US10540497B2 patent drawing
  • US10540497B2 patent drawing

AI summary

Disclosed is a method for monitoring security of a terminal system, including the following steps: monitoring a current running program in real time, and determining whether there is a security risk in the current running program; acquiring a corresponding preset risk score according to a type of the security risk, and adding the corresponding preset risk score to an accumulative risk score when there is the security risk in the current running program; and performing a risk prompt and a static scanning prompt when the accumulative risk score is greater than or equal to a risk threshold.