Virus Intrusion Route Identification via Operation History Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for determining computer virus infection routes are limited, as they can only specify whether infection occurred via a central device or another device, failing to account for various infection routes such as email attachments, removable media, or website browsing, and struggle with temporary files and complex infection pathways.

Innovation Solution

A device and method that utilizes an operation history storage unit to backtrack virus infection routes by analyzing operation histories, including file operations, web browsing, and removable media interactions, to provide detailed information on the virus's movement route.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If only file transmission time and date are monitored, then central device can detect viruses in transmitted files, but it is impossible to determine specific infection routes (email, removable media, website) or detect viruses in files not transmitted via central device

Engineering Contradiction:
Improveinfection route specification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from monitoring only file transmission time (one dimension) to comprehensively analyzing operation history across multiple dimensions including file operations, web browsing, email client usage, and removable media access. This multi-dimensional approach enables precise identification of specific infection routes such as email attachments, removable media, and website downloads without requiring complex additional hardware

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If virus detection is performed only by central device on transmitted files, then central device can identify infected files, but it cannot perform virus detection or route determination for files not transmitted via central device

Engineering Contradiction:
Improvevirus detection coverageVSAvoiddetection system operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables terminal devices to autonomously analyze their own operation histories to determine infection routes. The terminal device's operation history storage unit stores comprehensive operation records, and the determination unit analyzes these records to identify infection sources such as email clients, web browsers, or removable media, eliminating the need for centralized virus detection on all files

Inventive Principle:
Principle #25Self-service

3Loss of information

If only transmission time and date are used for route determination, then simple binary determination (via central device or another device) is achieved, but detailed infection pathways (email, removable media, website browsing) cannot be identified

Engineering Contradiction:
Improveinfection route information completenessVSAvoidinfection route analysis complexity
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary recording of comprehensive operation histories including file operations, web browsing activities, email client usage, and removable media access before virus infection occurs. This pre-collected data enables post-infection analysis to accurately trace infection routes through email attachments, removable media, or website downloads without requiring real-time monitoring of the infection process

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10326792B2Virus intrusion route identification device, virus intrusion route identification method, and program
Publication Date: 2019.06.18 CANON DENSHI KK
  • US10326792B2 patent drawing
  • US10326792B2 patent drawing
  • US10326792B2 patent drawing

AI summary

The invention aims to backtrack a virus infection route with more detail than in the conventional case. CPUs of client devices respectively monitor operations, and cause storage devices to store operation histories. The CPU determines, upon detecting a virus, the time and date at which the virus was first saved in the client device based on the operation history stored in the storage device, and determines a virus intrusion route based on the operation content that was executed at the determined time and date.