Network File Access Security via Test Open Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computers in a network environment are vulnerable to malicious code infections through file shares, as traditional firewalls do not protect against infections from computers lacking effective malicious code scanning means, and existing solutions impose a high administrative burden in tracking and protecting vulnerable systems.
Innovation Solution
A method where a first computer determines the safety of communicating with a second computer by initiating a test open of a file, assessing the second computer's malicious code scanning capabilities through a dummy file with a globally unique identifier and updated definition date, and relying on the second computer's scanning if it meets acceptability criteria, or performing a scan itself if criteria are not met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a firewall is programmed to allow communication between computers with authorized file shares, then file sharing functionality is improved, but the computer becomes vulnerable to malicious code entering through those file shares
Solution Approach 1:
The system performs preliminary malicious code scanning on files before allowing them to be accessed over the network. The scanning means checks files for malicious code content before the file share operation completes, preventing infection before it can occur. This preliminary security check resolves the contradiction by maintaining file sharing functionality while blocking malicious code in advance.
2Reliability
If traditional malicious code scanning solutions are implemented across all network computers, then security protection is improved, but administrative burden increases significantly
Solution Approach 1:
The system implements self-service security where the server automatically performs malicious code scanning on files requested for network access. The scanning means is triggered automatically by file access requests, and the system self-manages the security checks without requiring manual intervention. This resolves the contradiction by providing reliable security protection while eliminating the need for administrators to manually track and protect each vulnerable system.
3Reliability
If malicious code scanning is performed on every file access request, then security detection capability is improved, but processing time increases
Solution Approach 1:
The system applies different scanning strategies based on local conditions: it performs full malicious code scanning only when necessary (when security risk is detected or scanning results are uncertain), and allows rapid access when files are confirmed safe through previous scanning or trusted sources. This localized quality approach resolves the contradiction by providing high security detection capability only where needed, while maintaining fast processing for safe files.
Data Source
AI summary
Computer implement methods, apparati, and computer-readable media for enabling a first computer (12) to determine that it is safe to communicate with a second computer (10) coupled to the first computer (12) over a network (15). In a method embodiment of the present invention, the first computer (12) detects (21) that the second computer (10) has initiated a test open of a file (14) associated with the first computer (12). When the test open is followed by an actual open command by which the second computer (10) seeks to actually open the same file (14), the first computer (12) determines (23) that it is safe to communicate with the second computer (10).


