Restricted User Account Directory Traversal for Virus Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virus detection software often fails to prevent the spread of computer viruses before they cause irreparable damage due to the broad access authorities granted to user accounts, allowing viruses to infect and spread across various resources within a computer system.

Innovation Solution

The method involves creating a restricted user account with limited access authorities, confining applications to run within this account, and configuring the directory system to allow directory traversing without performing directory traverse checking, thereby reducing the scope of access and potential damage caused by viruses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user accounts are granted broad access authorities to resources, then applications can access and use most system resources, but computer viruses can spread to any resource that the application accesses causing irreparable damage

Engineering Contradiction:
Improveapplication access capabilityVSAvoidvirus spread risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the user account into a restricted user account with limited access authorities. The application runs under this segmented account identity, which divides the broad system access into controlled portions, allowing the application to function while limiting virus propagation paths to only those resources explicitly permitted by the restricted account's access authorities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by granting different access authorities to different resources based on the application's actual needs. The restricted user account is configured with specific access authorities that provide just enough permission for the application to function locally, rather than granting universal access. This localized permission approach maintains necessary functionality while containing potential virus damage to specific resource areas.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional virus detection software is used, then virus scanning can be performed, but the software cannot stop the spread of viruses before they do irreparable damage

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidresponse time to virus threat
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring the restricted user account with limited access authorities before the application runs. This preventive measure is established in advance, creating inherent access barriers that stop virus propagation before it can spread widely. The restricted account structure is set up beforehand to automatically limit what resources any process running under it can access, eliminating the need for reactive virus detection and response.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If a restricted user account is created with limited access authorities, then viral vulnerabilities are reduced, but the account must be carefully configured to maintain necessary application functionality

Engineering Contradiction:
Improveviral vulnerabilityVSAvoidaccount configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that manages the configuration of access authorities for the restricted user account. This intermediary layer handles the complexity of configuring appropriate permissions, translating application requirements into specific access authority settings. By using this intermediary approach, the system reduces viral vulnerability through restricted accounts while managing configuration complexity through automated or assisted permission management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8627068B1Selecting access authorities
Publication Date: 2014.01.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8627068B1 patent drawing
  • US8627068B1 patent drawing
  • US8627068B1 patent drawing

AI summary

Group access authorities for a restricted user account group in a directory system are selected to include directory traverse authority. A restricted user account is included in the restricted user account group such that the restricted user account inherits group access authorities. The directory system is configured to allow directory traversing without performing directory traverse checking. An application is confined to run within the restricted user account so that access authorities of the application include group access authorities.