Anti-Abuse Scanner for Data Platform Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data platforms face security risks due to the potential for malicious actors to exploit application frameworks, leading to threats such as data exfiltration, account compromise, and intellectual property theft.

Innovation Solution

An anti-abuse scanner is implemented within the data platform to detect and review application packages for malicious content, using a set of analysis rules and scanner tools to generate verdicts and make deployment decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an application framework is provided to allow users to develop and deploy applications, then the platform's functionality and user base expand, but the security risk increases due to potential malicious applications

Engineering Contradiction:
Improveplatform functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security scanning and verification of application packages before they are deployed to the data platform. The system analyzes application metadata, code, and configuration files during the deployment process to detect malicious content, vulnerable dependencies, and security violations before the application becomes operational, thereby preventing security risks while maintaining platform adaptability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security scanning system that acts as a mediator between application submission and platform deployment. This intermediary layer analyzes applications using multiple scanner tools and rules, generating security reports and deployment decisions without directly interfering with the core platform functionality or user application development

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security scanning is performed on all application packages, then security detection capability improves, but processing time and deployment speed decrease

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddeployment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a tiered scanning approach where not all application packages receive the same level of security analysis. The system performs basic scanning on all applications and more intensive analysis only when triggered by specific conditions such as detected vulnerabilities, unusual patterns, or high-risk metadata, thereby reducing average processing time while maintaining high detection capability for malicious applications

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent divides the security scanning process into multiple independent stages including metadata validation, code analysis, dependency checking, and behavioral simulation. Each stage can be executed independently and in parallel where applicable, allowing the system to process different aspects of application security concurrently and reduce overall deployment time while maintaining comprehensive detection

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple scanner tools and analysis rules are used to thoroughly review applications, then security coverage improves, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal scanning architecture where a single security scanning system performs multiple functions using different scanner tools and analysis rules. The system can execute static analysis, dynamic analysis, dependency checking, and metadata validation through a unified interface, managing the complexity of multiple tools while providing comprehensive security coverage through centralized control and coordination

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12314391B2Application trust framework
Publication Date: 2025.05.27 SNOWFLAKE INC
  • US12314391B2 patent drawing
  • US12314391B2 patent drawing
  • US12314391B2 patent drawing

AI summary

An anti-abuse system is provided for a data-platform. An anti-abuse scanner of the data-platform detects a creation of an application package by a provider of content to the data platform where the application package includes a set of files for deployment on the data platform. The anti-abuse scanner performs a review o the set of files to detect malicious content where the review is based on a set of analysis rules and generates a deployment decision for the application package based on a result of the review.