Vulnerability Protection System for Active Exploit Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security software is passive and lagging in protecting computer vulnerabilities, requiring user-initiated operations for patching and lacking real-time vulnerability protection, leading to ineffective prevention against illegal utilization.

Innovation Solution

A security protection system and method that includes a vulnerability identification device to collect and analyze patch file information, generate vulnerability protection information, and a vulnerability protection device to set and monitor triggering information for intercepting operations that exploit vulnerabilities, providing active and timely protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If conventional security software is used, then basic vulnerability detection is provided, but the protection is passive and lagging, requiring user-initiated operations

Engineering Contradiction:
Improveautomation of vulnerability protectionVSAvoidresponse time to vulnerability exploitation
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting patch file information, identifying vulnerabilities, and generating protection information before actual exploitation occurs. The vulnerability protection device proactively monitors for exploitation attempts and intercepts them before they can cause harm, eliminating the need for user-initiated patching operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security protection system operates autonomously without requiring user intervention. The vulnerability identification device automatically collects patch information and generates protection rules, while the protection device autonomously monitors and intercepts exploitation attempts, providing fully automated vulnerability management.

Inventive Principle:
Principle #25Self-service

2Reliability

If patch files are applied manually, then vulnerabilities are fixed, but real-time protection against exploitation is not achieved

Engineering Contradiction:
Improvevulnerability protection effectivenessVSAvoidsystem complexity for active monitoring
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability protection device acts as an intermediary layer between exploitation attempts and the vulnerable system. It monitors for exploitation behaviors and intercepts them before they reach the vulnerable component, providing reliable protection without requiring complex modifications to the underlying system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates vulnerability management into distinct functional modules: the vulnerability identification device that analyzes patch files and generates protection rules, and the vulnerability protection device that implements monitoring and interception. This segmentation allows each component to specialize in its function while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

3Loss of time

If passive vulnerability detection is used, then existing vulnerabilities are identified, but proactive prevention of exploitation is not provided

Engineering Contradiction:
Improvetime to detect vulnerability exploitationVSAvoidoperational simplicity of security software
Core Design Contradiction:
Loss of timeVSEase of operation

Solution Approach 1:

The system implements continuous feedback loops where the vulnerability protection device monitors system behavior, detects potential exploitation attempts, and immediately intercepts them. This real-time feedback mechanism enables proactive prevention while maintaining operational simplicity through automated response actions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9892259B2Security protection system and method
Publication Date: 2018.02.13 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9892259B2 patent drawing
  • US9892259B2 patent drawing
  • US9892259B2 patent drawing

AI summary

A security protection system is provided. The system includes: a vulnerability identification device, to collect patch file information, identify a vulnerability of a to-be-fixed object corresponding to the patch file information and generate vulnerability protection information according to the vulnerability; and a vulnerability protection device, to protect the vulnerability of the to-be-fixed object corresponding to the patch file information according to the vulnerability protection information. A security protection method is provided in the present disclosure. The present disclosure may provide effective protection to the computer actively and timely and protect the vulnerability of the computer from illegal utilization.