Virus Intrusion Route Identification via Operation History Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for determining computer virus infection routes are limited, as they can only specify whether infection occurred via a central device or another device, failing to account for various infection routes such as email attachments, removable media, or website browsing, and struggle with temporary files and complex infection pathways.
Innovation Solution
A device and method that utilizes an operation history storage unit to backtrack virus infection routes by analyzing operation histories, including file operations, web browsing, and removable media interactions, to provide detailed information on the virus's movement route.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If only file transmission time and date are monitored, then central device can detect viruses in transmitted files, but it is impossible to determine specific infection routes (email, removable media, website) or detect viruses in files not transmitted via central device
Solution Approach 1:
The patent transitions from monitoring only file transmission time (one dimension) to comprehensively analyzing operation history across multiple dimensions including file operations, web browsing, email client usage, and removable media access. This multi-dimensional approach enables precise identification of specific infection routes such as email attachments, removable media, and website downloads without requiring complex additional hardware
2Reliability
If virus detection is performed only by central device on transmitted files, then central device can identify infected files, but it cannot perform virus detection or route determination for files not transmitted via central device
Solution Approach 1:
The patent enables terminal devices to autonomously analyze their own operation histories to determine infection routes. The terminal device's operation history storage unit stores comprehensive operation records, and the determination unit analyzes these records to identify infection sources such as email clients, web browsers, or removable media, eliminating the need for centralized virus detection on all files
3Loss of information
If only transmission time and date are used for route determination, then simple binary determination (via central device or another device) is achieved, but detailed infection pathways (email, removable media, website browsing) cannot be identified
Solution Approach 1:
The patent implements preliminary recording of comprehensive operation histories including file operations, web browsing activities, email client usage, and removable media access before virus infection occurs. This pre-collected data enables post-infection analysis to accurately trace infection routes through email attachments, removable media, or website downloads without requiring real-time monitoring of the infection process
Data Source
AI summary
The invention aims to backtrack a virus infection route with more detail than in the conventional case. CPUs of client devices respectively monitor operations, and cause storage devices to store operation histories. The CPU determines, upon detecting a virus, the time and date at which the virus was first saved in the client device based on the operation history stored in the storage device, and determines a virus intrusion route based on the operation content that was executed at the determined time and date.


