Virtual File System Mapping for Inaccessible Vulnerability Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vulnerability inspection tools face difficulties in assessing the effects of vulnerabilities in objects that cannot be directly accessed due to the enormous volume of data, making it impractical to generate digital twins for each object, and thus, proper risk assessment is hindered.
Innovation Solution
An information processing apparatus that extracts first file path information from vulnerability inspection method information, registers it with second file path information for copied files, and constructs a virtual file system to enable vulnerability inspection without direct access to the object, using a virtual file system for assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If a digital twin is generated to enable vulnerability inspection of inaccessible objects, then inspection capability is improved, but data volume becomes enormous making the process impractical
Solution Approach 1:
The patent extracts only the necessary file path information from the vulnerability inspection method information, rather than copying the entire object. By extracting only the metadata about file paths and their corresponding locations in the inaccessible object, the system avoids the enormous data volume issue while still enabling effective vulnerability inspection through the virtual file system mapping.
Solution Approach 2:
The patent creates a virtual copy of the file system structure through the virtual file system, which maps file paths in the inaccessible object to accessible locations. This virtual copying approach allows the vulnerability inspection tool to operate on the copied structure without transferring the actual large volumes of data from the inaccessible object.
2Measurement precision
If all information is copied to generate a digital twin, then inspection accuracy is improved, but the process becomes impractical for huge numbers of objects
Solution Approach 1:
The patent segments the inspection process by separating the vulnerability inspection logic from the actual object data. The virtual file system divides the mapping between file paths in the inaccessible object and accessible locations into manageable segments, allowing efficient processing of huge numbers of objects without requiring complete data copying.
Solution Approach 2:
The patent performs preliminary extraction of file path information before the actual vulnerability inspection. By pre-extracting and registering the mapping relationships between file paths in the inaccessible object and their accessible counterparts, the system prepares the necessary structure in advance, enabling rapid and accurate inspection without repeating the data copying process for each inspection task.
Data Source
AI summary
According to one embodiment, an information processing apparatus includes a hardware processor connected to a memory. The hardware processor extracts first file path information indicating a file path of a file used by a vulnerability inspection tool in vulnerability inspection of an object to be inspected. The file path is a file path in the object to be inspected. The hardware processor registers second file path information and the first file path information in correlation with each other in second management information. The second file path information indicates a file path to a file copied from the object to be inspected by using the first file path information.


