Cloud Malware Protection via File Filter Driver Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing devices are vulnerable to malware attacks originating from endpoint computing devices, which can access and transmit sensitive information, compromising security and leading to unauthorized access and infections.

Innovation Solution

Implementing a system that uses a file filter driver to intercept malicious attempts to access encrypted files, performing multifactor authentication, file integrity monitoring, and user and entity behavior analytics to identify abnormal access patterns, and taking second security actions such as further encryption or access denial when authentication fails or unauthorized changes are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud computing devices store and process information, then productivity and accessibility are improved, but vulnerability to malware attacks increases

Engineering Contradiction:
Improveinformation processing capabilityVSAvoidmalware attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security actions by implementing multifactor authentication before allowing access to encrypted files, and conducting file integrity monitoring to detect unauthorized changes before malware can exfiltrate data. This proactive approach prevents attacks rather than merely responding to them.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer between the endpoint device and cloud service that intercepts file access attempts, performs authentication, and monitors file integrity. This intermediary mechanism blocks malicious communication channels while allowing legitimate cloud operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If endpoint devices access cloud storage, then ease of operation is improved, but risk of unauthorized access increases

Engineering Contradiction:
Improvecloud access convenienceVSAvoidunauthorized access prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security actions by implementing multifactor authentication before allowing access to encrypted files, and conducting file integrity monitoring to detect unauthorized changes before malware can exfiltrate data. This proactive approach prevents attacks rather than merely responding to them.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors file access patterns and provides feedback through behavior analytics to detect abnormal activities. When suspicious patterns are detected, the system responds by blocking access or alerting users, creating a closed-loop security mechanism that adapts to emerging threats while maintaining legitimate access.

Inventive Principle:
Principle #23Feedback

3Reliability

If sensitive information is stored in encrypted files, then security is improved, but accessibility and processing speed may be reduced

Engineering Contradiction:
Improveinformation securityVSAvoidfile access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system applies different security measures to different files based on their sensitivity and access patterns. File integrity monitoring and behavior analytics are selectively applied to encrypted files containing sensitive information, while less sensitive files can be accessed more quickly without these overhead mechanisms.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11411968B1Systems and methods for protecting a cloud computing device from malware
Publication Date: 2022.08.09 CA TECH INC
  • US11411968B1 patent drawing
  • US11411968B1 patent drawing
  • US11411968B1 patent drawing

AI summary

The disclosed computer-implemented method for protecting a cloud computing device from malware may include (i) intercepting, at a computing device, a malicious attempt by the malware to (A) access sensitive information in an encrypted file stored on the computing device and (B) send the sensitive information to the cloud computing device and (ii) performing, responsive to the attempt to access the encrypted file, a security action. Various other methods, systems, and computer-readable media are also disclosed.