Automated Whitelist Management for Program Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional antivirus software and white list type control methods face challenges in keeping up with the rapid increase in malware types, leading to difficulties in coping with targeted attacks, as they require burdensome operations for updating and registering programs and network access permissions.
Innovation Solution
An information processing apparatus with a detection unit, identification unit, and registration unit that automatically detects program startups and generation, identifies programs based on predetermined criteria, and registers them in white lists or black lists, reducing the need for manual updates and improving security by automating the registration of trusted programs and their updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional antivirus software uses a black list method, then it can detect known malware, but it cannot keep up with the rapid increase in malware types and fails to cope with targeted attacks
Solution Approach 1:
The patent inverts the conventional black list approach by implementing a white list system that automatically generates trusted program information. Instead of maintaining a list of known bad programs, the system proactively creates white list entries for legitimate programs and their updates, enabling the system to adapt to new malware threats while maintaining reliable detection of known threats.
Solution Approach 2:
The system performs self-service by automatically detecting program updates and generating corresponding white list information without requiring manual administrator intervention. The white list management system autonomously monitors program changes, extracts execution files, and updates the white list database, enabling the system to adapt to new software versions and maintain security without external assistance.
2Reliability
If white list type control method is used to prevent targeted attacks, then execution of known programs is allowed, but updater generated execution files are not registered and cannot be started
Solution Approach 1:
The system performs preliminary action by proactively detecting program updates and generating white list information before the updated programs are executed. The white list management system monitors for update operations, automatically creates white list entries for updater-generated files, and ensures they are registered in advance, allowing seamless program updates without manual intervention or execution blocks.
3Reliability
If manual white list updating is performed to maintain security, then trusted programs can be registered, but burdensome operations are required including determining reliability and registering updated programs
Solution Approach 1:
The white list management system performs self-service by automatically detecting program updates, determining their legitimacy through cryptographic verification, and generating white list information without administrator intervention. The system autonomously monitors program changes, verifies update authenticity using digital signatures, extracts execution files, and updates the white list database, eliminating time-consuming manual operations while maintaining high security standards.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring program execution and update operations. When an update is detected, the system automatically verifies its authenticity, generates corresponding white list entries, and updates the database. This closed-loop feedback system ensures the white list remains current with trusted programs while eliminating manual administrative burden.
4Reliability
If white list type network access control is implemented, then network access by known programs is permitted, but updated programs need to be re-registered and newly generated programs require additional registration operations
Solution Approach 1:
The system performs preliminary action by proactively generating white list information for network access control before updated programs require registration. The white list management system monitors program updates, automatically creates white list entries including network access permissions, and ensures updated programs are pre-registered with appropriate network access rights, eliminating the need for manual re-registration operations.
Data Source
AI summary
Startup of a program and generation or change of a program is detected, or a program is searched for. It is determined, based on program information of a program whose startup is detected or a program which is found, whether or not the program meets a predetermined criterion. The program determined to meet the predetermined criterion is registered in a white list or black list.


