Virtual File System Mapping for Inaccessible Vulnerability Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional vulnerability inspection tools face difficulties in assessing the effects of vulnerabilities in objects that cannot be directly accessed due to the enormous volume of data, making it impractical to generate digital twins for each object, and thus, proper risk assessment is hindered.

Innovation Solution

An information processing apparatus that extracts first file path information from vulnerability inspection method information, registers it with second file path information for copied files, and constructs a virtual file system to enable vulnerability inspection without direct access to the object, using a virtual file system for assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If a digital twin is generated to enable vulnerability inspection of inaccessible objects, then inspection capability is improved, but data volume becomes enormous making the process impractical

Engineering Contradiction:
Improvevulnerability inspection capabilityVSAvoiddata volume
Core Design Contradiction:
Difficulty of detecting and measuringVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary file path information from the vulnerability inspection method information, rather than copying the entire object. By extracting only the metadata about file paths and their corresponding locations in the inaccessible object, the system avoids the enormous data volume issue while still enabling effective vulnerability inspection through the virtual file system mapping.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a virtual copy of the file system structure through the virtual file system, which maps file paths in the inaccessible object to accessible locations. This virtual copying approach allows the vulnerability inspection tool to operate on the copied structure without transferring the actual large volumes of data from the inaccessible object.

Inventive Principle:
Principle #26Copying

2Measurement precision

If all information is copied to generate a digital twin, then inspection accuracy is improved, but the process becomes impractical for huge numbers of objects

Engineering Contradiction:
Improveinspection accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the inspection process by separating the vulnerability inspection logic from the actual object data. The virtual file system divides the mapping between file paths in the inaccessible object and accessible locations into manageable segments, allowing efficient processing of huge numbers of objects without requiring complete data copying.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary extraction of file path information before the actual vulnerability inspection. By pre-extracting and registering the mapping relationships between file paths in the inaccessible object and their accessible counterparts, the system prepares the necessary structure in advance, enabling rapid and accurate inspection without repeating the data copying process for each inspection task.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250284821A1Information processing apparatus, information processing method, and computer program product
Publication Date: 2025.09.11 KK TOSHIBA
  • US20250284821A1 patent drawing
  • US20250284821A1 patent drawing
  • US20250284821A1 patent drawing

AI summary

According to one embodiment, an information processing apparatus includes a hardware processor connected to a memory. The hardware processor extracts first file path information indicating a file path of a file used by a vulnerability inspection tool in vulnerability inspection of an object to be inspected. The file path is a file path in the object to be inspected. The hardware processor registers second file path information and the first file path information in correlation with each other in second management information. The second file path information indicates a file path to a file copied from the object to be inspected by using the first file path information.