Network File Access Security via Test Open Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computers in a network environment are vulnerable to malicious code infections through file shares, as traditional firewalls do not protect against infections from computers lacking effective malicious code scanning means, and existing solutions impose a high administrative burden in tracking and protecting vulnerable systems.

Innovation Solution

A method where a first computer determines the safety of communicating with a second computer by initiating a test open of a file, assessing the second computer's malicious code scanning capabilities through a dummy file with a globally unique identifier and updated definition date, and relying on the second computer's scanning if it meets acceptability criteria, or performing a scan itself if criteria are not met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a firewall is programmed to allow communication between computers with authorized file shares, then file sharing functionality is improved, but the computer becomes vulnerable to malicious code entering through those file shares

Engineering Contradiction:
Improvefile sharing functionalityVSAvoidmalicious code infection risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary malicious code scanning on files before allowing them to be accessed over the network. The scanning means checks files for malicious code content before the file share operation completes, preventing infection before it can occur. This preliminary security check resolves the contradiction by maintaining file sharing functionality while blocking malicious code in advance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional malicious code scanning solutions are implemented across all network computers, then security protection is improved, but administrative burden increases significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service security where the server automatically performs malicious code scanning on files requested for network access. The scanning means is triggered automatically by file access requests, and the system self-manages the security checks without requiring manual intervention. This resolves the contradiction by providing reliable security protection while eliminating the need for administrators to manually track and protect each vulnerable system.

Inventive Principle:
Principle #25Self-service

3Reliability

If malicious code scanning is performed on every file access request, then security detection capability is improved, but processing time increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidfile access processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies different scanning strategies based on local conditions: it performs full malicious code scanning only when necessary (when security risk is detected or scanning results are uncertain), and allows rapid access when files are confirmed safe through previous scanning or trusted sources. This localized quality approach resolves the contradiction by providing high security detection capability only where needed, while maintaining fast processing for safe files.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7373667B1Protecting a computer coupled to a network from malicious code infections
Publication Date: 2008.05.13 CA TECH INC
  • US7373667B1 patent drawing
  • US7373667B1 patent drawing
  • US7373667B1 patent drawing

AI summary

Computer implement methods, apparati, and computer-readable media for enabling a first computer (12) to determine that it is safe to communicate with a second computer (10) coupled to the first computer (12) over a network (15). In a method embodiment of the present invention, the first computer (12) detects (21) that the second computer (10) has initiated a test open of a file (14) associated with the first computer (12). When the test open is followed by an actual open command by which the second computer (10) seeks to actually open the same file (14), the first computer (12) determines (23) that it is safe to communicate with the second computer (10).