Uploaded File Malware Evaluation With Iterative Threat Reassessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face inefficiencies in creating their own file security evaluation systems to identify malicious and/or suspicious code in uploaded files, leading to increased risks of malware propagation.
Innovation Solution
A software-as-a-service (SaaS) provider offers a drop-in service for evaluating files to determine the likelihood of malicious and/or suspicious code, generating reports, and iteratively updating assessments based on changing threat levels, allowing customers to rely on the SaaS provider for security evaluations without maintaining their own systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations create their own file security evaluation systems, then security protection is improved, but system complexity and development effort increase
Solution Approach 1:
The patent introduces a third-party security evaluation system as an intermediary service. Instead of organizations building their own security systems, they use an external SaaS provider's evaluation system to assess file security risks. This mediator approach maintains security protection while significantly reducing the complexity burden on individual organizations.
Solution Approach 2:
The security evaluation system is designed as a universal service that can be applied across multiple organizations and file types. The system handles various file formats and security evaluation scenarios through a single unified platform, eliminating the need for each organization to develop custom security systems.
2Reliability
If organizations create their own file security evaluation systems, then security protection is improved, but development time and resources increase
Solution Approach 1:
The security evaluation methodology and system framework are pre-developed and validated by the SaaS provider before being made available to organizations. This preliminary action eliminates the need for organizations to spend time on system development, as they can immediately utilize the pre-built evaluation capabilities.
Solution Approach 2:
By using an external SaaS provider's pre-built security evaluation system as an intermediary, organizations avoid the time-consuming process of developing their own security systems while still achieving the desired security protection.
3Reliability
If organizations maintain their own security evaluation systems, then security control is improved, but operational burden increases
Solution Approach 1:
The SaaS provider's security evaluation system operates as a self-service platform where organizations can upload files for evaluation without needing to manage the underlying security infrastructure. The system automatically performs security assessments, updates its databases, and provides results, eliminating the operational burden of maintaining in-house security systems.
Solution Approach 2:
The external security evaluation system serves as an intermediary that handles all security operations automatically, freeing organizations from the operational burden of maintaining their own security evaluation infrastructure while preserving security control through professional management.
4Adaptability or versatility
If multiple organizations create their own security evaluation systems, then tailored security solutions are improved, but overall industry efficiency decreases
Solution Approach 1:
The SaaS provider develops a universal security evaluation system that serves multiple organizations simultaneously. This single system can be configured to handle different file types and security scenarios, providing tailored security solutions for each organization without requiring each one to build its own system, thereby significantly improving industry efficiency.
Data Source
AI summary
Methods, systems, and storage media for evaluating uploaded files for suspicious code are provided. The method includes to receive a copy of one file from a customer of a software provider, evaluate the copy of the file to determine a likelihood that the copy of the file contains malicious code, generate a report, provide the report to the customer, store the copy of the file and the report in a data store, iteratively evaluate the copy of the file to determine the likelihood that the copy of the file contains malicious code, on at least a portion of the iterations, compare the likelihood that the copy of the file contains malicious code to the stored report to determine whether there has been a change in the likelihood, upon determining that there has been a change in the likelihood, generate and provide a second report.


