Restricted User Account Directory Traversal for Virus Containment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virus detection software often fails to prevent the spread of computer viruses before they cause irreparable damage due to the broad access authorities granted to user accounts, allowing viruses to infect and spread across various resources within a computer system.
Innovation Solution
The method involves creating a restricted user account with limited access authorities, confining applications to run within this account, and configuring the directory system to allow directory traversing without performing directory traverse checking, thereby reducing the scope of access and potential damage caused by viruses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user accounts are granted broad access authorities to resources, then applications can access and use most system resources, but computer viruses can spread to any resource that the application accesses causing irreparable damage
Solution Approach 1:
The patent segments the user account into a restricted user account with limited access authorities. The application runs under this segmented account identity, which divides the broad system access into controlled portions, allowing the application to function while limiting virus propagation paths to only those resources explicitly permitted by the restricted account's access authorities.
Solution Approach 2:
The patent applies local quality by granting different access authorities to different resources based on the application's actual needs. The restricted user account is configured with specific access authorities that provide just enough permission for the application to function locally, rather than granting universal access. This localized permission approach maintains necessary functionality while containing potential virus damage to specific resource areas.
2Reliability
If conventional virus detection software is used, then virus scanning can be performed, but the software cannot stop the spread of viruses before they do irreparable damage
Solution Approach 1:
The patent implements preliminary action by pre-configuring the restricted user account with limited access authorities before the application runs. This preventive measure is established in advance, creating inherent access barriers that stop virus propagation before it can spread widely. The restricted account structure is set up beforehand to automatically limit what resources any process running under it can access, eliminating the need for reactive virus detection and response.
3Object-affected harmful factors
If a restricted user account is created with limited access authorities, then viral vulnerabilities are reduced, but the account must be carefully configured to maintain necessary application functionality
Solution Approach 1:
The patent introduces an intermediary component that manages the configuration of access authorities for the restricted user account. This intermediary layer handles the complexity of configuring appropriate permissions, translating application requirements into specific access authority settings. By using this intermediary approach, the system reduces viral vulnerability through restricted accounts while managing configuration complexity through automated or assisted permission management.
Data Source
AI summary
Group access authorities for a restricted user account group in a directory system are selected to include directory traverse authority. A restricted user account is included in the restricted user account group such that the restricted user account inherits group access authorities. The directory system is configured to allow directory traversing without performing directory traverse checking. An application is confined to run within the restricted user account so that access authorities of the application include group access authorities.


