User Expertise-Based Verdict Verification for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection methods in cloud computing environments are inefficient due to the exponential growth of threats, limited capabilities of antivirus companies, and the challenge of differentiating user expertise, leading to delayed threat identification and incorrect verdicts.

Innovation Solution

A system that classifies users based on their expertise in computer security, where high-expertise users' verdicts are directly accepted, and low-expertise users' verdicts are verified, with dynamic allocation of computing resources and configuration settings based on user roles to enhance threat detection and processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all user verdicts are accepted without verification, then processing speed increases, but detection accuracy decreases due to incorrect verdicts from low-expertise users

Engineering Contradiction:
Improvethreat detection speedVSAvoidmalware detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system applies different processing qualities to different users based on their expertise level. High-expertise users receive direct verdict acceptance with minimal processing, while low-expertise users have their verdicts subjected to verification and analysis. This local differentiation of processing quality resolves the contradiction by optimizing the verification depth according to user capability rather than applying a uniform approach to all users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the verification process based on user expertise level. The verification intensity is not static but changes according to the user's demonstrated knowledge and performance. This dynamic adaptation allows the system to maintain high detection accuracy for low-expertise users while preserving fast processing for high-expertise users, thereby resolving the speed-accuracy tradeoff.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If verification processes are applied to all user verdicts, then detection accuracy improves, but processing time increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidverdict processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements localized verification processes tailored to each user's expertise level. High-expertise users bypass extensive verification, while low-expertise users receive targeted verification only when needed. This selective application of verification quality maintains high detection accuracy without uniformly increasing processing time for all users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies verification partially rather than universally. Instead of verifying all verdicts from all users, it applies verification only to verdicts from low-expertise users or in specific contexts where uncertainty exists. This partial action approach maintains detection accuracy while minimizing unnecessary verification overhead and processing time.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of manufacture

If computing resources are allocated uniformly to all users, then resource distribution is simple, but processing efficiency decreases for high-expertise users

Engineering Contradiction:
Improveresource allocation simplicityVSAvoidthreat processing efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The system allocates computing resources with local quality based on user expertise level. High-expertise users receive optimized resource allocation that minimizes verification overhead, while low-expertise users receive enhanced resources for thorough verification. This differentiated resource quality allocation improves overall processing efficiency while maintaining manageable complexity through automated role-based distribution.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The resource allocation system dynamically adjusts computing resource distribution based on user expertise and verification needs. Rather than static uniform allocation, the system flexibly assigns resources according to real-time user performance and verdict reliability, optimizing processing efficiency while the automated nature keeps implementation complexity manageable.

Inventive Principle:
Principle #15Dynamics

4Device complexity

If user expertise levels are not differentiated, then system complexity is low, but detection reliability decreases due to mixed verdict quality

Engineering Contradiction:
Improvesystem structure complexityVSAvoidthreat detection reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments users into different expertise levels (high-expertise and low-expertise groups) based on their verdict accuracy and knowledge demonstration. This segmentation enables the system to apply appropriate verification processes to each group, significantly improving detection reliability. The automated segmentation process keeps system complexity manageable while the differentiated handling of segments ensures high reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of user expertise level from undifferentiated to differentiated states. By introducing expertise level as a variable parameter that affects verification intensity and resource allocation, the system achieves high detection reliability. The automated assessment and dynamic adjustment of this parameter keep implementation complexity acceptable while delivering reliable results.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8214904B1System and method for detecting computer security threats based on verdicts of computer users
Publication Date: 2012.07.03 AO KASPERSKY LAB
  • US8214904B1 patent drawing
  • US8214904B1 patent drawing
  • US8214904B1 patent drawing

AI summary

Disclosed are systems, methods and computer program products for detecting unknown security threats. In one example, a system receives from an antivirus application deployed on a user's computer information about an unknown security event associated with a software executing on the computer and a user's verdict indicating that the software is harmful or clean. The system identifies the user of the computer and a role of the user. The role indicates user's level of expertise in the field of computer security. If the user has a high level of expertise in computer security, the system accepts the user's verdict. If the user has a low level of expertise, the system analyzes the information about the security event to verify that the user's verdict is correct. If the user's verdict was accepted or verified to be correct, the system updates an antivirus database associated with the antivirus application.