Removable Storage Security System for Malware Risk Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems are vulnerable to malicious software introduced through removable data storage devices, which can disrupt operations and compromise security without user permission.

Innovation Solution

A security system that monitors removable storage devices, assesses security risks, and controls data transmission based on geographical location and user associations, selectively authorizing or preventing data retrieval to mitigate the risk of malicious software execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If removable data storage devices are allowed to be connected to computer systems for data exchange, then data accessibility and user convenience are improved, but the risk of introducing malicious software increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidmalicious software risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security system performs preliminary scanning and assessment of removable storage devices before allowing data access. The system proactively identifies and blocks malicious software before it can be executed on the computer system, preventing harm while maintaining data accessibility for legitimate devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system acts as an intermediary between the removable storage device and the computer system. It monitors data transmission, assesses security risks, and selectively authorizes or blocks data access based on the presence of malicious software, thereby protecting the system while allowing legitimate operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security scanning and monitoring of removable storage devices is implemented, then security risk detection is improved, but system operation time and processing delay increase

Engineering Contradiction:
Improvesecurity risk detectionVSAvoidsystem operation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security system performs partial scanning by focusing on critical areas and using heuristic analysis to identify suspicious patterns without examining every single file. This approach provides sufficient security detection while minimizing the time penalty compared to exhaustive scanning

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the security system blocks data retrieval from high-risk removable storage devices, then protection against malicious software is improved, but data transmission efficiency decreases

Engineering Contradiction:
Improveprotection against malicious softwareVSAvoiddata transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security system applies different levels of security scrutiny to different removable storage devices based on their individual risk profiles. Low-risk devices experience minimal interference and maintain high transmission efficiency, while only high-risk devices undergo extensive scanning and potential blocking, thereby protecting against malware without unnecessarily reducing overall data transmission efficiency

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11645391B2Protecting computer systems against malicious software stored on removeable data storage devices
Publication Date: 2023.05.09 SAUDI ARABIAN OIL CO
  • US11645391B2 patent drawing
  • US11645391B2 patent drawing
  • US11645391B2 patent drawing

AI summary

In an example method, one or more processors determine that a first data storage device has been communicatively coupled to a first computer system, determine that the first computer system is associated with a first geographical location, determine that the first data storage device is associated with a first user, determine that the first user is associated with one or more additional data storage devices, and determine usage data regarding the one or more additional data storage devices. Further, the one or more processors control a transmission of data between the first data storage device and first computer system based on the first geographical location and the usage data.