User Expertise-Based Verdict Verification for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current malware detection methods in cloud computing environments are inefficient due to the exponential growth of threats, limited capabilities of antivirus companies, and the challenge of differentiating user expertise, leading to delayed threat identification and incorrect verdicts.
Innovation Solution
A system that classifies users based on their expertise in computer security, where high-expertise users' verdicts are directly accepted, and low-expertise users' verdicts are verified, with dynamic allocation of computing resources and configuration settings based on user roles to enhance threat detection and processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If all user verdicts are accepted without verification, then processing speed increases, but detection accuracy decreases due to incorrect verdicts from low-expertise users
Solution Approach 1:
The system applies different processing qualities to different users based on their expertise level. High-expertise users receive direct verdict acceptance with minimal processing, while low-expertise users have their verdicts subjected to verification and analysis. This local differentiation of processing quality resolves the contradiction by optimizing the verification depth according to user capability rather than applying a uniform approach to all users.
Solution Approach 2:
The system dynamically adjusts the verification process based on user expertise level. The verification intensity is not static but changes according to the user's demonstrated knowledge and performance. This dynamic adaptation allows the system to maintain high detection accuracy for low-expertise users while preserving fast processing for high-expertise users, thereby resolving the speed-accuracy tradeoff.
2Measurement precision
If verification processes are applied to all user verdicts, then detection accuracy improves, but processing time increases
Solution Approach 1:
The system implements localized verification processes tailored to each user's expertise level. High-expertise users bypass extensive verification, while low-expertise users receive targeted verification only when needed. This selective application of verification quality maintains high detection accuracy without uniformly increasing processing time for all users.
Solution Approach 2:
The system applies verification partially rather than universally. Instead of verifying all verdicts from all users, it applies verification only to verdicts from low-expertise users or in specific contexts where uncertainty exists. This partial action approach maintains detection accuracy while minimizing unnecessary verification overhead and processing time.
3Ease of manufacture
If computing resources are allocated uniformly to all users, then resource distribution is simple, but processing efficiency decreases for high-expertise users
Solution Approach 1:
The system allocates computing resources with local quality based on user expertise level. High-expertise users receive optimized resource allocation that minimizes verification overhead, while low-expertise users receive enhanced resources for thorough verification. This differentiated resource quality allocation improves overall processing efficiency while maintaining manageable complexity through automated role-based distribution.
Solution Approach 2:
The resource allocation system dynamically adjusts computing resource distribution based on user expertise and verification needs. Rather than static uniform allocation, the system flexibly assigns resources according to real-time user performance and verdict reliability, optimizing processing efficiency while the automated nature keeps implementation complexity manageable.
4Device complexity
If user expertise levels are not differentiated, then system complexity is low, but detection reliability decreases due to mixed verdict quality
Solution Approach 1:
The system segments users into different expertise levels (high-expertise and low-expertise groups) based on their verdict accuracy and knowledge demonstration. This segmentation enables the system to apply appropriate verification processes to each group, significantly improving detection reliability. The automated segmentation process keeps system complexity manageable while the differentiated handling of segments ensures high reliability.
Solution Approach 2:
The system changes the parameter of user expertise level from undifferentiated to differentiated states. By introducing expertise level as a variable parameter that affects verification intensity and resource allocation, the system achieves high detection reliability. The automated assessment and dynamic adjustment of this parameter keep implementation complexity acceptable while delivering reliable results.
Data Source
AI summary
Disclosed are systems, methods and computer program products for detecting unknown security threats. In one example, a system receives from an antivirus application deployed on a user's computer information about an unknown security event associated with a software executing on the computer and a user's verdict indicating that the software is harmful or clean. The system identifies the user of the computer and a role of the user. The role indicates user's level of expertise in the field of computer security. If the user has a high level of expertise in computer security, the system accepts the user's verdict. If the user has a low level of expertise, the system analyzes the information about the security event to verify that the user's verdict is correct. If the user's verdict was accepted or verified to be correct, the system updates an antivirus database associated with the antivirus application.


