Cloud Malware Protection via File Filter Driver Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing devices are vulnerable to malware attacks originating from endpoint computing devices, which can access and transmit sensitive information, compromising security and leading to unauthorized access and infections.
Innovation Solution
Implementing a system that uses a file filter driver to intercept malicious attempts to access encrypted files, performing multifactor authentication, file integrity monitoring, and user and entity behavior analytics to identify abnormal access patterns, and taking second security actions such as further encryption or access denial when authentication fails or unauthorized changes are detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud computing devices store and process information, then productivity and accessibility are improved, but vulnerability to malware attacks increases
Solution Approach 1:
The system performs preliminary security actions by implementing multifactor authentication before allowing access to encrypted files, and conducting file integrity monitoring to detect unauthorized changes before malware can exfiltrate data. This proactive approach prevents attacks rather than merely responding to them.
Solution Approach 2:
The patent introduces an intermediary security layer between the endpoint device and cloud service that intercepts file access attempts, performs authentication, and monitors file integrity. This intermediary mechanism blocks malicious communication channels while allowing legitimate cloud operations to proceed.
2Ease of operation
If endpoint devices access cloud storage, then ease of operation is improved, but risk of unauthorized access increases
Solution Approach 1:
The system performs preliminary security actions by implementing multifactor authentication before allowing access to encrypted files, and conducting file integrity monitoring to detect unauthorized changes before malware can exfiltrate data. This proactive approach prevents attacks rather than merely responding to them.
Solution Approach 2:
The system continuously monitors file access patterns and provides feedback through behavior analytics to detect abnormal activities. When suspicious patterns are detected, the system responds by blocking access or alerting users, creating a closed-loop security mechanism that adapts to emerging threats while maintaining legitimate access.
3Reliability
If sensitive information is stored in encrypted files, then security is improved, but accessibility and processing speed may be reduced
Solution Approach 1:
The system applies different security measures to different files based on their sensitivity and access patterns. File integrity monitoring and behavior analytics are selectively applied to encrypted files containing sensitive information, while less sensitive files can be accessed more quickly without these overhead mechanisms.
Data Source
AI summary
The disclosed computer-implemented method for protecting a cloud computing device from malware may include (i) intercepting, at a computing device, a malicious attempt by the malware to (A) access sensitive information in an encrypted file stored on the computing device and (B) send the sensitive information to the cloud computing device and (ii) performing, responsive to the attempt to access the encrypted file, a security action. Various other methods, systems, and computer-readable media are also disclosed.


