I/O Filter Driver Content Analysis for File Circumvention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for preventing unwanted files from being saved on network servers, such as virus scanners and name mask scanners, can be circumvented, leading to the need for a more effective solution to exclude files based on content rather than just file names.
Innovation Solution
A system and method that intercepts file write operations, captures file identifiers, and examines file data to match against content signatures, using a combination of I/O Filter Driver, Policy Database, Signature Processing, and Signature Database to enforce storage policies by scanning the file content for prohibited types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If name mask scanners are used to block files by extension, then file saving can be prevented for common unauthorized types, but users can easily circumvent by using alternative extensions
Solution Approach 1:
The system performs preliminary scanning of file content during the write operation, before the file is fully saved. The I/O filter driver intercepts the write operation and examines the file data in real-time, identifying unauthorized content types before they are completely written to disk, thus preventing circumvention through alternative extensions.
Solution Approach 2:
The patent replaces the mechanical file name matching system with a content-based analysis system. Instead of relying on file extensions or names, the system uses the I/O filter driver to scan the actual binary content of files being written, identifying content types through data analysis rather than metadata, making circumvention extremely difficult.
2Reliability
If file content is scanned to identify unauthorized types, then circumvention is prevented, but system performance and storage speed are reduced
Solution Approach 1:
The I/O filter driver performs partial scanning of file content during write operations. Rather than scanning the entire file, the system examines portions of the data stream in real-time, which provides sufficient information to identify content types while minimizing the performance impact on storage operations.
Solution Approach 2:
The system uses rapid content analysis techniques that allow the I/O filter driver to quickly scan through file data during the write operation. By implementing efficient scanning algorithms and processing data in streams rather than loading entire files into memory, the system maintains storage operation speed while still performing content verification.
3Reliability
If I/O filter driver intercepts all file write operations for content analysis, then unauthorized files are identified, but system complexity and resource consumption increase
Solution Approach 1:
The I/O filter driver is designed as a universal component that handles multiple file types and content analysis tasks through a single unified interface. The driver intercepts all file write operations regardless of source or destination, applying the same content scanning logic across different scenarios, which simplifies the overall system architecture despite the comprehensive monitoring capability.
Solution Approach 2:
The I/O filter driver acts as an intermediary layer between the file system and applications. Rather than requiring modifications to individual applications or the core file system, the driver sits in the middle, transparently intercepting and analyzing file operations. This intermediary approach adds minimal complexity while providing comprehensive content-based file identification.
Data Source
AI summary
A system and method for excluding certain types of files from being saved to a system by examining file data. The file data is examined by: mapping the circular queue to memory; reading the file identifiers from the circular queue (a named mutex is locked until all file identifiers have been read from the queue); using the file identifier to open the file; scanning the opened file to create a file signature; comparing the file signature to each entry on a list of signature criteria; and performing a storage policy if there is a match.


