File Identification via Source Trust Whitelisting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anti-malware technologies often inaccurately classify files created within an organization as malicious, leading to disruptions in workflow and potential disabling of security programs, as they lack effective methods to identify non-malicious files originating from trusted sources within the organization.

Innovation Solution

The system identifies non-malicious files by determining the source's trustworthiness within the organization through modules that analyze relationships between files and the organization, including user authentication, database verification, and user feedback, ultimately adding trusted files to a whitelist for access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional anti-malware technology analyzes all files to identify malicious content, then security detection capability is improved, but false positive rate increases and workflow efficiency deteriorates

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidworkflow efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments file analysis into two distinct pathways: (1) files from untrusted external sources undergo full security scanning, and (2) files from trusted internal organizational sources are automatically whitelisted without scanning. This segmentation resolves the contradiction by applying rigorous security checks only where necessary while enabling efficient access to trusted internal files.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary classification of files based on their origin before security analysis. Files created within the organization are pre-identified as trusted and added to a whitelist in advance, so they bypass subsequent security scanning. This preliminary action eliminates unnecessary analysis steps for trusted files, maintaining workflow efficiency while preserving security for external files.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional anti-malware technology blocks files from untrusted sources, then security protection is improved, but access to legitimate organizational files deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidfile access capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of blocking files by default and requiring proof of safety, the system inverts the approach for internal files: files created within the organization are automatically trusted and granted access by default. This inversion resolves the contradiction by making legitimate organizational files easily accessible while maintaining security blocks for external files that lack organizational provenance.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system introduces an intermediary mechanism - a whitelist - that mediates between security protection and file access. Files from trusted internal sources are added to this intermediary whitelist, which then facilitates their access without requiring security intervention. This intermediary structure resolves the contradiction by providing a clear pathway for legitimate files while maintaining protective blocks for untrusted files.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If users disable anti-malware programs due to workflow disruptions, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveworkflow smoothnessVSAvoidsecurity defense capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary identification and whitelisting of trusted internal files before users encounter workflow disruptions. By pre-classifying files from organizational sources as safe, the system eliminates the need for users to interact with or disable security programs, maintaining both workflow smoothness and security defense capability simultaneously.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The anti-malware system provides self-service by automatically identifying and trusting files created within the organization without requiring user intervention or configuration. This self-service capability resolves the contradiction by making the security system adaptive to organizational context, maintaining protection while eliminating workflow disruptions that would otherwise cause users to disable security programs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10169584B1Systems and methods for identifying non-malicious files on computing devices within organizations
Publication Date: 2019.01.01 CA TECH INC
  • US10169584B1 patent drawing
  • US10169584B1 patent drawing
  • US10169584B1 patent drawing

AI summary

The disclosed computer-implemented method for identifying non-malicious files on computing devices within organizations may include (1) identifying a file on at least one computing device within multiple computing devices managed by an organization, (2) identifying a source of the file based on examining a relationship between the file and the organization, (3) determining that the source of the file is trusted within the organization, and then (4) concluding, based on the source of the file being trusted within the organization, that the file is not malicious. Various other methods, systems, and computer-readable media are also disclosed.