Removable Media Security via Redirection Code Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices and host devices connected to external media, such as USB flash drives, are vulnerable to malicious code and data transfer risks when outside the enterprise network, lacking the second line of defense provided by network security systems.
Innovation Solution
A method and system that detect removable media devices, authenticate access, inject redirection code, intercept data requests, and apply security policies to filter out malware and ensure secure data transfer, using a mobile security system that acts as a miniature gateway, providing two lines of defense even when outside the enterprise network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices connect to external media outside enterprise network, then device portability and access flexibility are improved, but security protection deteriorates due to loss of network security system defense
Solution Approach 1:
The patent introduces an intermediary security system that acts as a mediator between the mobile device and external media. This security system includes a security module that intercepts data requests, scans for malicious code, and filters content before allowing access, thereby providing security protection without restricting device portability or external media access
2Reliability
If network security system is used within enterprise network, then security protection is improved, but device accessibility outside network deteriorates
Solution Approach 1:
The patent implements a self-service security system where the mobile device itself performs security functions through an installed security module. This module provides local scanning, filtering, and protection capabilities, enabling the device to maintain security protection independently when outside the enterprise network, thus not limiting device accessibility
3Reliability
If security scanning and filtering is performed on all data requests, then malicious code detection is improved, but data transfer speed deteriorates
Solution Approach 1:
The patent applies partial scanning and filtering actions based on risk assessment. The security module prioritizes scanning for high-risk file types and contexts while using less intensive scanning for low-risk data, thereby maintaining malicious code detection capability while minimizing impact on data transfer speed
Data Source
AI summary
A method comprises detecting a removable media device being coupled to an external device port of a digital device having an operating system and a file system, authenticating a password to access the removable media device, causing redirection code to be temporarily generated on the digital device, intercepting with the redirection code a data request, determining to allow the data request based on a security policy, allowing the operating system or file system to provide the data based on the determination, detecting the removable media device being removed from the digital device; and terminating the at least a portion of the redirection code.


