Cloud Access Security Broker File Scanning Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based service platforms like Salesforce face challenges in efficiently and reliably scanning files for malicious content, as existing methods may fail to detect threats immediately, allowing malware to spread and compromising network security.
Innovation Solution
A method and apparatus that intercept files between a file service cloud entity and a remote accessing entity, identify potential security threats, and transmit scan tasks to a security cloud entity for analysis, ensuring real-time threat detection and mitigation without impacting performance or user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If files are scanned using cloud resources during upload handling, then security detection capability is improved, but processing time and system performance deteriorate
Solution Approach 1:
The patent performs file scanning during the upload process itself, before the file is fully stored and made accessible. By initiating security checks preliminarily during upload handling rather than after storage, the system detects threats early without requiring separate post-upload scanning operations, thus improving security detection while minimizing additional time loss.
Solution Approach 2:
The patent introduces a cloud access security broker (CASB) as an intermediary component between users and cloud storage services. The CASB intercepts and scans files during transmission and upload processes, acting as a mediator that performs security checks without requiring direct modification of the core cloud storage system. This intermediary approach enables comprehensive scanning while maintaining efficient file transfer through the broker's optimized processing pipeline.
2Reliability
If cloud access security broker is implemented as HTTPS reverse-proxy gateway, then security interception capability is improved, but system complexity and bypass risk increase
Solution Approach 1:
The patent implements the cloud access security broker with multi-functional capabilities that combine HTTPS reverse-proxy gateway functions, file scanning, threat detection, and secure file transfer in a single unified system. By making the CASB universal and multi-functional rather than relying on separate specialized components, the system achieves comprehensive security interception capability while reducing overall system complexity through consolidation.
3Reliability
If malware scanning is performed on multi-tenant cloud platform, then threat detection reliability is improved, but resource monopolization and performance impact increase
Solution Approach 1:
The patent segments the malware scanning process into distinct modular components that can be independently executed and managed. By dividing the scanning functionality into separate scan tasks that can be distributed across available computational resources, the system maintains high threat detection reliability while preventing any single scanning operation from monopolizing platform resources. The segmented approach allows parallel processing and better resource utilization across the multi-tenant environment.
Data Source
AI summary
There are provided measures for protection from malicious and/or harmful content in cloud-based service scenarios. Such measures exemplarily include detecting a transmission attempt of a file between a file service cloud entity and a remote accessing entity, identifying said file, checking for presence of a security threat scan result for said file in a scan result memory based on a result of said identifying, and transmitting, based on a result of said checking, a security threat scan task for said file to a security cloud entity connected to said file service cloud entity.


