Automated Whitelist Generation Balancing Security Coverage and Cost
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and quantity of software make manual whitelisting inefficient and unwieldy, as software considered safe in one context may be problematic in another, necessitating an automated solution for creating optimized whitelists across computing systems.
Innovation Solution
An automated method for whitelisting files involves obtaining telemetry information, calculating the cost and coverage impact of including files in the whitelist, and determining their inclusion based on balancing these factors to create a customized whitelist for groups of computing systems, protecting them from undesirable files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual whitelisting is used to ensure security, then security reliability is improved, but the complexity and time required to create and maintain whitelists increases significantly
Solution Approach 1:
The system performs self-service by automatically generating whitelists through telemetry analysis without requiring manual intervention. The computing systems themselves provide the data needed for whitelist creation, and the system autonomously determines which files to include based on coverage thresholds and cost calculations.
Solution Approach 2:
The manual mechanical process of reviewing and adding files to whitelists is replaced with an automated computational system that analyzes telemetry data, calculates costs and coverage, and generates whitelists algorithmically. This substitutes human-operated mechanical processes with automated information processing.
2Reliability
If comprehensive whitelisting is implemented to cover all computing systems, then security coverage is improved, but the cost and resource requirements increase
Solution Approach 1:
The system changes parameters by adjusting the coverage threshold to balance security coverage against cost. By modifying this parameter, the system can generate whitelists at different levels of comprehensiveness, allowing optimization between coverage and resource consumption based on specific needs.
Solution Approach 2:
Instead of implementing complete universal whitelisting, the system applies partial action by covering a specified percentage threshold of computing systems. This partial coverage approach achieves sufficient security protection without the excessive cost of comprehensive coverage across all systems.
3Measurement precision
If context-specific whitelisting is implemented to account for different software roles, then security precision is improved, but the complexity of managing multiple whitelists increases
Solution Approach 1:
The system segments computing systems into groups based on their roles and characteristics, then generates tailored whitelists for each segment. This segmentation allows context-specific security precision while managing complexity through automated grouping rather than manual classification.
Solution Approach 2:
The automated whitelist generation system provides universal functionality that adapts to different computing system contexts. A single system performs multiple functions: analyzing telemetry, grouping systems, calculating costs, and generating context-appropriate whitelists, replacing the need for separate manual processes for each context.
Data Source
AI summary
The disclosed computer-implemented method for automated whitelisting of files may include (1) obtaining telemetry information that identifies files located on a set of computing systems, (2) establishing a whitelist of files for the set of computing systems by, for each file identified by the telemetry information, (A) calculating an amount by which a cost for using the whitelist will increase if the file is included in the whitelist, (B) calculating an amount by which whitelist coverage of files in the set of computing devices will increase if the file is included in the whitelist, (C) determining whether to include the file in the whitelist by balancing the increase in the cost against the increase in whitelist coverage, and (3) using the whitelist to protect the set of computing systems from undesirable files. Various other methods, systems, and computer-readable media are also disclosed.


