Thread Pattern Analysis for Adaptive Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in effectively detecting new types of malicious attacks and malware due to their evolving nature, requiring multiple detection processes and techniques.

Innovation Solution

Capturing thread information from computing systems, identifying thread patterns, and comparing them to learned patterns to detect anomalies, with actions taken based on variances from the learned patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple malware detection processes and techniques are used to identify new types of malicious attacks, then detection reliability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoiddetection process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple detection techniques into a unified thread pattern analysis system. Instead of running separate detection processes for different malware types, the system merges them into a single framework that analyzes thread information patterns to detect various malicious attacks simultaneously, thereby reducing overall system complexity while maintaining comprehensive detection capability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The thread pattern analysis system serves as a universal detection mechanism that can identify multiple types of malicious attacks and malware through a single process. The system analyzes thread information patterns to detect different threats without requiring separate specialized detection tools for each threat type, achieving multi-functionality in malware detection

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If traditional malware detection methods are used, then detection precision is maintained for known threats, but adaptability to new malicious attacks deteriorates

Engineering Contradiction:
Improvedetection precisionVSAvoidadaptability to new attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system employs dynamic thread pattern analysis that adapts to new malicious attacks by continuously monitoring and analyzing thread information patterns. Instead of relying on static signature databases, the system dynamically identifies anomalies in thread behavior patterns, enabling it to detect new types of attacks without requiring pre-programmed knowledge of specific threat signatures

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the detection parameter from traditional malware signatures to thread information patterns. By analyzing changes in thread creation, execution, and termination patterns rather than relying on fixed malware signatures, the system maintains precision for known threats while gaining adaptability to detect new attack types through pattern anomaly identification

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12386951B2Using thread patterns to identify anomalous behavior
Publication Date: 2025.08.12 MICRO FOCUS LLC
  • US12386951B2 patent drawing
  • US12386951B2 patent drawing
  • US12386951B2 patent drawing

AI summary

Thread information generated by one or more computing systems is captured. A thread pattern is identified from the captured thread information. The thread pattern is compared to a learned thread pattern. An anomaly is identified in the thread pattern based on a variance from the learned thread pattern. In response to identifying the anomaly in the thread pattern, an action is taken based on the anomalous thread pattern. For example, a user may be notified. The thread patterns may be extended to compare between operating systems, hypervisors, containers, and/or virtual machines.