Centralized SaaS File Evaluation for Iterative Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face inefficiencies in creating their own file security evaluation systems to identify and mitigate malicious and/or suspicious code in file uploads, as existing solutions are repetitive and resource-intensive.

Innovation Solution

A software-as-a-service (SaaS) provider offers a drop-in service for evaluating files to determine the likelihood of malicious and/or suspicious code, generating reports, and iteratively updating assessments based on new data, allowing customers to rely on a centralized system for security threat evaluation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations create their own file security evaluation systems, then they can identify malicious code in their files, but multiple organizations independently creating such systems results in inefficiencies and resource waste

Engineering Contradiction:
Improvefile security evaluation capabilityVSAvoidsystem development efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple independent file security evaluation systems into a single centralized service that multiple organizations can access. Instead of each organization building and maintaining separate evaluation infrastructure, they share a common system that provides file security assessment capabilities to all customers, eliminating redundant development and improving overall efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized file security evaluation system is designed to serve multiple organizations and purposes through a universal platform. The system can evaluate files from different customers, handle various file types, and provide security assessment services to diverse organizations simultaneously, making the system highly adaptable and widely applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If organizations build individual security evaluation systems, then they have control over their security processes, but the complexity of creating and maintaining these systems increases

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsecurity system infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized file security evaluation service as an intermediary between organizations and their file security needs. This intermediary handles the complexity of security evaluation internally while providing simplified access to organizations through an API or service interface, reducing the complexity burden on individual organizations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized system performs security evaluations automatically without requiring individual organizations to maintain their own evaluation infrastructure. The system self-manages the complexity of security analysis, updates, and maintenance internally, while organizations simply submit files for evaluation through the service interface.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12450349B2Evaluating files for malicious and/or suspicious code
Publication Date: 2025.10.21 STAIRWELL INC
  • US12450349B2 patent drawing
  • US12450349B2 patent drawing
  • US12450349B2 patent drawing

AI summary

Methods, systems, and storage media for evaluating uploaded files for suspicious code are provided. The method includes to receive a copy of one file from a customer of a software provider, evaluate the copy of the file to determine a likelihood that the copy of the file contains malicious code, generate a report, provide the report to the customer, store the copy of the file and the report in a data store, iteratively evaluate the copy of the file to determine the likelihood that the copy of the file contains malicious code, on at least a portion of the iterations, compare the likelihood that the copy of the file contains malicious code to the stored report to determine whether there has been a change in the likelihood, upon determining that there has been a change in the likelihood, generate and provide a second report.