File Cluster Whitelisting for Trusted Software Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and quantity of software can make whitelisting problematic, as updates to trusted software packages may introduce additional files that are not initially whitelisted, triggering security events and interfering with system functionality.

Innovation Solution

A method for whitelisting file clusters by identifying trusted and additional files that co-exist on computing systems, determining they represent portions of a single trusted software package, merging these clusters, and then whitelisting the merged cluster, allowing for automated updates and efficient operation without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software packages are updated with additional files, then software functionality is improved, but security alerts are triggered because the new files are not whitelisted

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidsecurity alerts
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the trusted file cluster with additional file clusters that co-exist on the same system, creating an expanded whitelist that includes both original trusted files and newly added files from software updates. This combining approach allows updates to proceed without triggering security alerts while maintaining system security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system acts as an intermediary by automatically analyzing additional files, determining their trustworthiness through co-existence relationships, and seamlessly integrating them into the whitelist. This intermediary process prevents security alerts without requiring manual intervention or compromising security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual whitelisting of each file is performed, then security accuracy is improved, but time consumption increases

Engineering Contradiction:
Improvewhitelist accuracyVSAvoidwhitelist maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically identifying additional file clusters, analyzing their relationships with trusted files, determining their reliability, and adding them to the whitelist without human intervention. This automation maintains high whitelist accuracy while eliminating time-consuming manual processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of additional files before they can trigger security alerts, pre-determining their trustworthiness based on co-existence relationships with known trusted files. This preliminary action ensures accurate whitelist updates occur proactively, preventing security events before they happen.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If security scans are performed on all files, then detection accuracy is improved, but system efficiency decreases

Engineering Contradiction:
Improvefile detection accuracyVSAvoidsystem efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system segments files into trusted file clusters and additional file clusters, applying different processing approaches to each. Trusted files are whitelisted without scanning, while additional files undergo automated analysis based on their relationships with trusted files. This segmentation maintains detection accuracy for critical files while improving overall system efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10089469B1Systems and methods for whitelisting file clusters in connection with trusted software packages
Publication Date: 2018.10.02 GEN DIGITAL INC
  • US10089469B1 patent drawing
  • US10089469B1 patent drawing
  • US10089469B1 patent drawing

AI summary

The disclosed computer-implemented method for whitelisting file clusters in connection with trusted software packages may include (1) identifying a trusted file cluster that includes a set of clean files, (2) identifying an additional file cluster that includes a set of additional files that typically co-exist with the set of clean files included in the trusted file cluster on computing systems, (3) determining that the trusted file cluster and the additional file cluster represent portions of a single trusted software package, and then, in response to determining that the trusted file cluster and the additional file cluster represent portions of the single trusted software package, (4) merging the trusted file cluster and the additional file cluster into a merged file cluster and (5) whitelisting the merged file cluster. Various other methods, systems, and computer-readable media are also disclosed.