Removable Media Auditing via Secure Check-In and Malware Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Removable media, such as USB drives, pose a significant threat to secure networks as they can introduce viruses and malware, making it challenging to control file access and ensure data integrity when transferring information into and out of protected systems.

Innovation Solution

The implementation of a 'check-in' and 'check-out' process for removable media using Secure Media Exchange (SMX) agents and kiosks, which scans for malware, digitally signs clean files, and modifies the file system to ensure only authorized access within protected systems, while preventing use outside the system when checked-out.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If removable media are used to transfer information into and out of secure networks, then data transfer capability is improved, but security risk increases due to potential introduction of viruses and malware

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by scanning removable media for malware before allowing access to protected systems. The check-in process includes virus scanning and security validation that must be completed before the media can be used, preventing harmful factors from entering the secure network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer between the removable media and the protected system. This includes security agents, scanning mechanisms, and validation protocols that act as a buffer, allowing safe media to pass through while blocking or neutralizing malicious content before it can reach the secure network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access controls are implemented on removable media, then security is improved, but ease of operation deteriorates due to restricted access

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service mechanisms where removable media automatically undergo scanning and validation when inserted into the system. The check-in process occurs automatically without requiring manual security approvals for each media, and the system self-manages the authorization status, reducing operational burden while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access control system is dynamic rather than static. Media can transition between authorized and unauthorized states based on real-time scanning results and security validation. The system adapts its access permissions based on the current security status of the media, allowing legitimate media to access freely while blocking harmful content.

Inventive Principle:
Principle #15Dynamics

3Reliability

If file access auditing is implemented, then security monitoring is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The auditing function is merged with the existing file access and media management operations. The same security agents and access control mechanisms that manage file access also perform auditing, eliminating the need for separate complex auditing infrastructure. The audit trail is generated as a byproduct of normal security operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where audit information is continuously collected and used to improve security monitoring. The audit trail provides feedback about media usage patterns and access behaviors, which can be analyzed to detect anomalies and improve the overall security posture without adding significant complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10643007B2System and method for auditing file access to secure media by nodes of a protected system
Publication Date: 2020.05.05 HONEYWELL INTERNATIONAL INC
  • US10643007B2 patent drawing
  • US10643007B2 patent drawing
  • US10643007B2 patent drawing

AI summary

A method includes detecting a storage device and determining whether the storage device has been checked-in for use with at least a protected node. The method also includes granting access to the storage device in response to determining that the storage device has been checked-in for use with at least the protected node. The method further includes storing data identifying file activity involving the storage device on the storage device. The data could identify all files copied to or from the storage device and all file activity that is blocked from occurring on the storage device. The method may also include copying one or more log files stored at the protected node onto the storage device, and storing the data identifying the file activity may include appending data identifying details of the file activity to the one or more log files.