Email Attachment URL Replacement for Cloud Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus security measures often fail to detect malicious email attachments immediately due to zero-day vulnerabilities, allowing attackers to bypass initial scans and deliver threats before virus signatures or behavior rules can be updated.
Innovation Solution
Replacing email attachments with URLs allows for a delay in delivery, enabling further scanning on a cloud server with updated virus patterns and behavior rules, which can detect malicious software through static and dynamic scans.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If immediate delivery of email attachments is performed, then user productivity is improved, but security detection capability deteriorates due to insufficient time for virus pattern updates
Solution Approach 1:
The system performs preliminary scanning actions on email attachments before they are delivered to users. By replacing attachments with URLs and conducting scans in advance, the system ensures that security checks are completed beforehand, allowing virus patterns to be updated and applied before the attachment becomes accessible, thus resolving the contradiction between immediate delivery and adequate detection time
Solution Approach 2:
The patent introduces a URL as an intermediary between the email system and the attachment. Instead of directly delivering the attachment, the system provides a URL that users must access separately, creating a buffer that allows time for security scanning and pattern updates without delaying the email delivery itself
2Speed
If attachments are scanned immediately upon receipt, then detection speed is improved, but detection accuracy deteriorates due to zero-day vulnerabilities
Solution Approach 1:
The system performs preliminary scanning actions on email attachments before they are delivered to users. By replacing attachments with URLs and conducting scans in advance, the system ensures that security checks are completed beforehand, allowing virus patterns to be updated and applied before the attachment becomes accessible, thus resolving the contradiction between immediate delivery and adequate detection time
Solution Approach 2:
The system implements periodic scanning at multiple stages: initial scanning upon receipt, followed by additional scanning after pattern updates, and final scanning before allowing attachment access. This multi-stage periodic approach ensures both speed (initial quick scan) and accuracy (follow-up scans with updated patterns)
3Loss of time
If attachments are removed and replaced with URLs, then security scanning time is improved, but user convenience deteriorates
Solution Approach 1:
The patent introduces a URL as an intermediary between the email system and the attachment. Instead of directly delivering the attachment, the system provides a URL that users must access separately, creating a buffer that allows time for security scanning and pattern updates without delaying the email delivery itself
Solution Approach 2:
The system automatically manages the attachment delivery process through the URL mechanism. When users access the URL, the system automatically performs final security checks and delivers the attachment if safe, or blocks it if malicious. This self-service approach minimizes user effort while maintaining security
Data Source
AI summary
An attachment to an e-mail message is replaced with a URL before that message is delivered to an end user, thus providing more time to perform a better scan at a cloud server computer. The attachment is removed from the e-mail message and sent to the cloud server computer for a dynamic scan and a static scan which will likely include updates better able to detect malicious software. The e-mail message with the URL is delivered to the end user and there is a delay before the end user reads the message or attempts to open the attachment. An artificial delay may be introduced at an e-mail gateway before the message is delivered to the end-user. If the attachment is benign then the end user is allowed to download it via the URL; if the attachment is malicious then the end user is only given a warning message.


