Cloud Access Security Broker File Scanning Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based service platforms like Salesforce face challenges in efficiently and reliably scanning files for malicious content, as existing methods may fail to detect threats immediately, allowing malware to spread and compromising network security.

Innovation Solution

A method and apparatus that intercept files between a file service cloud entity and a remote accessing entity, identify potential security threats, and transmit scan tasks to a security cloud entity for analysis, ensuring real-time threat detection and mitigation without impacting performance or user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If files are scanned using cloud resources during upload handling, then security detection capability is improved, but processing time and system performance deteriorate

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs file scanning during the upload process itself, before the file is fully stored and made accessible. By initiating security checks preliminarily during upload handling rather than after storage, the system detects threats early without requiring separate post-upload scanning operations, thus improving security detection while minimizing additional time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a cloud access security broker (CASB) as an intermediary component between users and cloud storage services. The CASB intercepts and scans files during transmission and upload processes, acting as a mediator that performs security checks without requiring direct modification of the core cloud storage system. This intermediary approach enables comprehensive scanning while maintaining efficient file transfer through the broker's optimized processing pipeline.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud access security broker is implemented as HTTPS reverse-proxy gateway, then security interception capability is improved, but system complexity and bypass risk increase

Engineering Contradiction:
Improvesecurity interception capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements the cloud access security broker with multi-functional capabilities that combine HTTPS reverse-proxy gateway functions, file scanning, threat detection, and secure file transfer in a single unified system. By making the CASB universal and multi-functional rather than relying on separate specialized components, the system achieves comprehensive security interception capability while reducing overall system complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If malware scanning is performed on multi-tenant cloud platform, then threat detection reliability is improved, but resource monopolization and performance impact increase

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the malware scanning process into distinct modular components that can be independently executed and managed. By dividing the scanning functionality into separate scan tasks that can be distributed across available computational resources, the system maintains high threat detection reliability while preventing any single scanning operation from monopolizing platform resources. The segmented approach allows parallel processing and better resource utilization across the multi-tenant environment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11019082B2Protection from malicious and/or harmful content in cloud-based service scenarios
Publication Date: 2021.05.25 F SECURE CORP
  • US11019082B2 patent drawing
  • US11019082B2 patent drawing
  • US11019082B2 patent drawing

AI summary

There are provided measures for protection from malicious and/or harmful content in cloud-based service scenarios. Such measures exemplarily include detecting a transmission attempt of a file between a file service cloud entity and a remote accessing entity, identifying said file, checking for presence of a security threat scan result for said file in a scan result memory based on a result of said identifying, and transmitting, based on a result of said checking, a security threat scan task for said file to a security cloud entity connected to said file service cloud entity.