Cloud Document Security via Inline Proxy Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based phishing attacks pose a significant threat to corporate networks, particularly through the sharing of documents with malicious links from cloud-based storage platforms, which can compromise sensitive data.
Innovation Solution
A system and method that utilize network policies and metadata analysis to determine document ownership, implement an inline proxy to inspect and quarantine potentially malicious links, and apply policy-based rules to control access and sharing of documents within the corporate network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud-based document sharing is enabled for corporate networks, then productivity and collaboration are improved, but security risks from phishing attacks increase
Solution Approach 1:
The patent introduces an intermediary system that sits between cloud document sharing platforms and the corporate network. This intermediary inspects shared documents for malicious content before allowing them into the network, thereby maintaining productivity while blocking phishing attacks. The intermediary acts as a security gatekeeper that enables document sharing without exposing the network to threats.
Solution Approach 2:
The system performs preliminary inspection and analysis of shared documents before they are allowed into the corporate network. By scanning documents for malicious links and content in advance, the system prevents phishing attacks while maintaining seamless document sharing. This preliminary security check ensures that only safe documents are permitted to enter the network.
2Ease of operation
If document sharing links are made accessible to multiple users, then ease of operation is improved, but the risk of data compromise increases
Solution Approach 1:
The patent implements an intermediary security layer that monitors and inspects all document sharing links before they are accessed by users. This intermediary system maintains ease of operation by allowing seamless document access while simultaneously protecting data security through automated malicious content detection and blocking.
Solution Approach 2:
The system incorporates feedback mechanisms that continuously monitor document sharing activities and automatically respond to potential threats. When malicious content is detected in shared documents, the system provides feedback by blocking access and alerting administrators, thereby maintaining both ease of operation and data security through adaptive security measures.
3Reliability
If cloud-based storage platforms are sanctioned and monitored, then security control is improved, but shadow IT services remain unmonitored and vulnerable
Solution Approach 1:
The patent creates a universal security solution that works across multiple cloud storage platforms and services, including both sanctioned and unsanctioned platforms. The intermediary system can inspect documents from various sources regardless of whether they are approved services, thereby extending security coverage to shadow IT while maintaining control over sanctioned platforms.
4Reliability
If malicious links in shared documents are blocked, then security is improved, but legitimate document sharing may be disrupted
Solution Approach 1:
The patent applies local quality by implementing targeted security measures only where needed - specifically inspecting document links and content for malicious elements while allowing the rest of the document sharing process to proceed uninterrupted. This selective approach blocks only harmful content while maintaining smooth operation of legitimate document sharing activities.
Solution Approach 2:
The system uses feedback mechanisms to distinguish between malicious and legitimate documents. When a document is inspected, the system provides feedback based on its security assessment - blocking malicious documents while allowing legitimate ones to pass through seamlessly. This intelligent feedback system ensures security protection without disrupting legitimate business operations.
Data Source
AI summary
The technology disclosed prevents phishing attacks where a malicious attacker creates a malicious file in a cloud-based store and shares it with endpoint users. A user, opening the shared document, is redirected to a malicious website where a corporation's critical data may be compromised. The cloud-based method applies a set of rules and policies to allow the shared document or block the shared document from the network, based on identifying the ownership or originator of the shared document. Documents from blacklisted websites are blocked. Documents from trusted sources are allowed access to the network. Unknown documents are blocked and threat-scanned to determine if they contain malicious content. If analysis proves a blocked document to be safe, it may be released into the network along with subsequent documents having the same ownership or originator.


