File Identification via Source Trust Whitelisting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional anti-malware technologies often inaccurately classify files created within an organization as malicious, leading to disruptions in workflow and potential disabling of security programs, as they lack effective methods to identify non-malicious files originating from trusted sources within the organization.
Innovation Solution
The system identifies non-malicious files by determining the source's trustworthiness within the organization through modules that analyze relationships between files and the organization, including user authentication, database verification, and user feedback, ultimately adding trusted files to a whitelist for access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional anti-malware technology analyzes all files to identify malicious content, then security detection capability is improved, but false positive rate increases and workflow efficiency deteriorates
Solution Approach 1:
The system segments file analysis into two distinct pathways: (1) files from untrusted external sources undergo full security scanning, and (2) files from trusted internal organizational sources are automatically whitelisted without scanning. This segmentation resolves the contradiction by applying rigorous security checks only where necessary while enabling efficient access to trusted internal files.
Solution Approach 2:
The system performs preliminary classification of files based on their origin before security analysis. Files created within the organization are pre-identified as trusted and added to a whitelist in advance, so they bypass subsequent security scanning. This preliminary action eliminates unnecessary analysis steps for trusted files, maintaining workflow efficiency while preserving security for external files.
2Reliability
If conventional anti-malware technology blocks files from untrusted sources, then security protection is improved, but access to legitimate organizational files deteriorates
Solution Approach 1:
Instead of blocking files by default and requiring proof of safety, the system inverts the approach for internal files: files created within the organization are automatically trusted and granted access by default. This inversion resolves the contradiction by making legitimate organizational files easily accessible while maintaining security blocks for external files that lack organizational provenance.
Solution Approach 2:
The system introduces an intermediary mechanism - a whitelist - that mediates between security protection and file access. Files from trusted internal sources are added to this intermediary whitelist, which then facilitates their access without requiring security intervention. This intermediary structure resolves the contradiction by providing a clear pathway for legitimate files while maintaining protective blocks for untrusted files.
3Ease of operation
If users disable anti-malware programs due to workflow disruptions, then ease of operation is improved, but security vulnerability increases
Solution Approach 1:
The system performs preliminary identification and whitelisting of trusted internal files before users encounter workflow disruptions. By pre-classifying files from organizational sources as safe, the system eliminates the need for users to interact with or disable security programs, maintaining both workflow smoothness and security defense capability simultaneously.
Solution Approach 2:
The anti-malware system provides self-service by automatically identifying and trusting files created within the organization without requiring user intervention or configuration. This self-service capability resolves the contradiction by making the security system adaptive to organizational context, maintaining protection while eliminating workflow disruptions that would otherwise cause users to disable security programs.
Data Source
AI summary
The disclosed computer-implemented method for identifying non-malicious files on computing devices within organizations may include (1) identifying a file on at least one computing device within multiple computing devices managed by an organization, (2) identifying a source of the file based on examining a relationship between the file and the organization, (3) determining that the source of the file is trusted within the organization, and then (4) concluding, based on the source of the file being trusted within the organization, that the file is not malicious. Various other methods, systems, and computer-readable media are also disclosed.


