Malware Spread Detection in Shared Cloud Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malware can spread through shared data storage in cloud environments without being detected, as administrators may lack visibility across multiple tenants, leading to continued malware dissemination among computing devices.
Innovation Solution
A processor-based system determines whether malware has spread from shared data storage by analyzing detection alerts from multiple computing devices within a predefined time frame, outputs notifications, and implements remedial measures such as blocking communications or running anti-malware programs to prevent further spread.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators rely on traditional anti-malware signature matching in multi-tenant cloud environments, then individual device security is maintained, but malware spread through shared data storage remains undetected
Solution Approach 1:
The patent combines security monitoring across multiple tenant boundaries by collecting and analyzing malware detection data from multiple computing devices that access the same shared data storage. This merging approach enables centralized detection of malware patterns that spread across tenants, resolving the visibility problem while maintaining individual device security through coordinated response.
Solution Approach 2:
The system implements a universal monitoring mechanism that functions across all tenants accessing shared data storage, regardless of organizational boundaries. This multi-tenant security layer provides universal detection capabilities while allowing each tenant to maintain their own security policies and individual device protection measures.
2Ease of operation
If shared data storage is accessed by multiple computing devices without centralized monitoring, then data accessibility is maintained, but malware can disseminate undetected
Solution Approach 1:
The system implements feedback mechanisms where malware detection alerts from individual computing devices are collected and analyzed to identify patterns indicating shared data storage compromise. When malware spread is detected, the system provides feedback by generating notifications to administrators and automatically responding to block further spread, thus maintaining data accessibility while preventing malware dissemination.
Solution Approach 2:
The patent introduces an intermediary security system that sits between multiple computing devices and the shared data storage infrastructure. This intermediary collects security events, analyzes patterns, and coordinates responses without interfering with normal data access operations, thus maintaining ease of operation while detecting and preventing malware spread.
3Measurement precision
If multi-tenant security monitoring is implemented, then malware spread detection capability is improved, but system complexity increases
Solution Approach 1:
The patent segments the security monitoring function into distinct modular components: event collection from individual devices, pattern analysis for malware spread detection, notification generation, and automated response execution. This segmentation allows each component to be independently implemented and managed, reducing overall system complexity while maintaining precise malware spread detection capability across multi-tenant environments.
Data Source
AI summary
According to examples, an apparatus may include machine-readable instructions that may cause the processor to determine that a first malware was detected on a first computing device and to determine whether a second malware was detected on a second computing device within a predefined period of time of when the first malware was detected on the first computing device, in which the first computing device and the second computing device are associated with a shared data storage that is remote from the first and second computing devices. The instructions may also cause the processor to, based on a determination that the second malware was detected within the predefined period of time, output a notification that the first malware was likely spread to the first computing device and/or that the second malware was likely spread to the second computing device through the shared data storage.


