Uploaded File Malware Evaluation With Iterative Threat Reassessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face inefficiencies in creating their own file security evaluation systems to identify malicious and/or suspicious code in uploaded files, leading to increased risks of malware propagation.

Innovation Solution

A software-as-a-service (SaaS) provider offers a drop-in service for evaluating files to determine the likelihood of malicious and/or suspicious code, generating reports, and iteratively updating assessments based on changing threat levels, allowing customers to rely on the SaaS provider for security evaluations without maintaining their own systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations create their own file security evaluation systems, then security protection is improved, but system complexity and development effort increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third-party security evaluation system as an intermediary service. Instead of organizations building their own security systems, they use an external SaaS provider's evaluation system to assess file security risks. This mediator approach maintains security protection while significantly reducing the complexity burden on individual organizations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security evaluation system is designed as a universal service that can be applied across multiple organizations and file types. The system handles various file formats and security evaluation scenarios through a single unified platform, eliminating the need for each organization to develop custom security systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If organizations create their own file security evaluation systems, then security protection is improved, but development time and resources increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security evaluation methodology and system framework are pre-developed and validated by the SaaS provider before being made available to organizations. This preliminary action eliminates the need for organizations to spend time on system development, as they can immediately utilize the pre-built evaluation capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By using an external SaaS provider's pre-built security evaluation system as an intermediary, organizations avoid the time-consuming process of developing their own security systems while still achieving the desired security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If organizations maintain their own security evaluation systems, then security control is improved, but operational burden increases

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The SaaS provider's security evaluation system operates as a self-service platform where organizations can upload files for evaluation without needing to manage the underlying security infrastructure. The system automatically performs security assessments, updates its databases, and provides results, eliminating the operational burden of maintaining in-house security systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The external security evaluation system serves as an intermediary that handles all security operations automatically, freeing organizations from the operational burden of maintaining their own security evaluation infrastructure while preserving security control through professional management.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple organizations create their own security evaluation systems, then tailored security solutions are improved, but overall industry efficiency decreases

Engineering Contradiction:
Improvetailored security solutionsVSAvoidindustry efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The SaaS provider develops a universal security evaluation system that serves multiple organizations simultaneously. This single system can be configured to handle different file types and security scenarios, providing tailored security solutions for each organization without requiring each one to build its own system, thereby significantly improving industry efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260017370A1Evaluating files for malicious and/or suspicious code
Publication Date: 2026.01.15 STAIRWELL INC
  • US20260017370A1 patent drawing
  • US20260017370A1 patent drawing
  • US20260017370A1 patent drawing

AI summary

Methods, systems, and storage media for evaluating uploaded files for suspicious code are provided. The method includes to receive a copy of one file from a customer of a software provider, evaluate the copy of the file to determine a likelihood that the copy of the file contains malicious code, generate a report, provide the report to the customer, store the copy of the file and the report in a data store, iteratively evaluate the copy of the file to determine the likelihood that the copy of the file contains malicious code, on at least a portion of the iterations, compare the likelihood that the copy of the file contains malicious code to the stored report to determine whether there has been a change in the likelihood, upon determining that there has been a change in the likelihood, generate and provide a second report.