Mediated Access to Resources via Intermediary Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic message security systems fail to effectively protect against threats embedded in links and resources, as they often rely on outdated rules and signatures, and do not dynamically adapt to user-specific contacts and message archives, leading to inadequate protection and resource overload due to uncontrolled sharing of protected references.
Innovation Solution
A malware detection system that rewrites resource references before delivery, using a pre-delivery threat analysis and intervention system to mediate user access based on updated information, providing warnings and access control through a proxy server, and employing user authorization to ensure only authorized users receive threat protection, thereby reducing resource overload and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security checks are performed on each accessed protected reference, then threat protection is provided to users, but security checking system resources such as processor capacity, memory, or network bandwidth are overwhelmed due to widespread distribution of copies
Solution Approach 1:
The patent introduces a mediator component that sits between the user and the security checking system. When a protected reference is accessed, the mediator intercepts the request, verifies whether the user is authorized to receive threat protection, and only then forwards the request to the security checking system. This intermediary layer prevents unauthorized users from consuming security resources while ensuring authorized users receive proper protection.
Solution Approach 2:
The system implements self-service by attaching authorization information directly to the protected reference itself. When a user accesses the reference, the system automatically checks the embedded authorization data to determine if the user is entitled to threat protection, eliminating the need for continuous external authorization verification and reducing resource overhead.
2Reliability
If rules and signatures are configured by administrators or obtained from security firms, then threat detection capability is provided, but the approach is time-consuming and resource intensive, and rules and signatures are frequently out-of-date
Solution Approach 1:
The system implements feedback mechanisms that automatically monitor and analyze threat patterns from message archives and contact lists. When new threat patterns are detected, the system automatically updates rules and signatures without requiring administrator intervention. This closed-loop feedback system ensures threat detection capabilities remain current while eliminating the time loss associated with manual updates.
Solution Approach 2:
The system performs self-updating of threat detection rules and signatures by automatically analyzing message archives, contact lists, and emerging threat patterns. This self-service capability allows the system to maintain up-to-date threat detection without requiring external input from administrators or security firms, eliminating the time and resource overhead of manual rule configuration.
3Adaptability or versatility
If protected resource references are shared widely, then threat protection benefits are made available to more users, but security checking resources are consumed on each access and the system is overwhelmed
Solution Approach 1:
The mediator component embedded in protected references acts as a gatekeeper that verifies user authorization before allowing access to threat protection services. This enables widespread sharing of protected references while preventing resource exhaustion, as only authorized users can actually consume security checking resources through the mediator's controlled access pathway.
Solution Approach 2:
Protected references contain embedded authorization information that enables them to self-determine whether a user is authorized to receive threat protection. This self-service mechanism allows widespread distribution without requiring central authorization management, as each reference independently verifies user entitlement, preventing unauthorized resource consumption.
Data Source
AI summary
Today's user is facing an ever increasing number of cyber threats from infectious software to scam artist phishing for their passwords and other personal information. Accordingly, a technique is provided to mediate a user's access to electronic resources, which can include malware and sites that trick the user into giving their password. Based on information known about the resource at the time the user accesses it, the technique can warn the user that the resources is suspicious and it is not safe to provide their password. Even if the resource is safe, the technique can warn the user not reuse their password, thereby promoting good password hygiene.


