File Cluster Whitelisting for Trusted Software Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and quantity of software can make whitelisting problematic, as updates to trusted software packages may introduce additional files that are not initially whitelisted, triggering security events and interfering with system functionality.
Innovation Solution
A method for whitelisting file clusters by identifying trusted and additional files that co-exist on computing systems, determining they represent portions of a single trusted software package, merging these clusters, and then whitelisting the merged cluster, allowing for automated updates and efficient operation without manual intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software packages are updated with additional files, then software functionality is improved, but security alerts are triggered because the new files are not whitelisted
Solution Approach 1:
The patent merges the trusted file cluster with additional file clusters that co-exist on the same system, creating an expanded whitelist that includes both original trusted files and newly added files from software updates. This combining approach allows updates to proceed without triggering security alerts while maintaining system security.
Solution Approach 2:
The system acts as an intermediary by automatically analyzing additional files, determining their trustworthiness through co-existence relationships, and seamlessly integrating them into the whitelist. This intermediary process prevents security alerts without requiring manual intervention or compromising security protocols.
2Reliability
If manual whitelisting of each file is performed, then security accuracy is improved, but time consumption increases
Solution Approach 1:
The system performs self-service by automatically identifying additional file clusters, analyzing their relationships with trusted files, determining their reliability, and adding them to the whitelist without human intervention. This automation maintains high whitelist accuracy while eliminating time-consuming manual processes.
Solution Approach 2:
The system performs preliminary analysis of additional files before they can trigger security alerts, pre-determining their trustworthiness based on co-existence relationships with known trusted files. This preliminary action ensures accurate whitelist updates occur proactively, preventing security events before they happen.
3Measurement precision
If security scans are performed on all files, then detection accuracy is improved, but system efficiency decreases
Solution Approach 1:
The system segments files into trusted file clusters and additional file clusters, applying different processing approaches to each. Trusted files are whitelisted without scanning, while additional files undergo automated analysis based on their relationships with trusted files. This segmentation maintains detection accuracy for critical files while improving overall system efficiency.
Data Source
AI summary
The disclosed computer-implemented method for whitelisting file clusters in connection with trusted software packages may include (1) identifying a trusted file cluster that includes a set of clean files, (2) identifying an additional file cluster that includes a set of additional files that typically co-exist with the set of clean files included in the trusted file cluster on computing systems, (3) determining that the trusted file cluster and the additional file cluster represent portions of a single trusted software package, and then, in response to determining that the trusted file cluster and the additional file cluster represent portions of the single trusted software package, (4) merging the trusted file cluster and the additional file cluster into a merged file cluster and (5) whitelisting the merged file cluster. Various other methods, systems, and computer-readable media are also disclosed.


