Thread Pattern Analysis for Adaptive Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in effectively detecting new types of malicious attacks and malware due to their evolving nature, requiring multiple detection processes and techniques.
Innovation Solution
Capturing thread information from computing systems, identifying thread patterns, and comparing them to learned patterns to detect anomalies, with actions taken based on variances from the learned patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple malware detection processes and techniques are used to identify new types of malicious attacks, then detection reliability is improved, but device complexity increases
Solution Approach 1:
The patent combines multiple detection techniques into a unified thread pattern analysis system. Instead of running separate detection processes for different malware types, the system merges them into a single framework that analyzes thread information patterns to detect various malicious attacks simultaneously, thereby reducing overall system complexity while maintaining comprehensive detection capability
Solution Approach 2:
The thread pattern analysis system serves as a universal detection mechanism that can identify multiple types of malicious attacks and malware through a single process. The system analyzes thread information patterns to detect different threats without requiring separate specialized detection tools for each threat type, achieving multi-functionality in malware detection
2Measurement precision
If traditional malware detection methods are used, then detection precision is maintained for known threats, but adaptability to new malicious attacks deteriorates
Solution Approach 1:
The system employs dynamic thread pattern analysis that adapts to new malicious attacks by continuously monitoring and analyzing thread information patterns. Instead of relying on static signature databases, the system dynamically identifies anomalies in thread behavior patterns, enabling it to detect new types of attacks without requiring pre-programmed knowledge of specific threat signatures
Solution Approach 2:
The system changes the detection parameter from traditional malware signatures to thread information patterns. By analyzing changes in thread creation, execution, and termination patterns rather than relying on fixed malware signatures, the system maintains precision for known threats while gaining adaptability to detect new attack types through pattern anomaly identification
Data Source
AI summary
Thread information generated by one or more computing systems is captured. A thread pattern is identified from the captured thread information. The thread pattern is compared to a learned thread pattern. An anomaly is identified in the thread pattern based on a variance from the learned thread pattern. In response to identifying the anomaly in the thread pattern, an action is taken based on the anomalous thread pattern. For example, a user may be notified. The thread patterns may be extended to compare between operating systems, hypervisors, containers, and/or virtual machines.


