Vulnerability-Based File Access Control for Antivirus Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Antivirus applications consume significant computer resources due to frequent scanning of files, even after initial scans, as malware becomes increasingly sophisticated, necessitating a system to restrict file access based on application vulnerabilities to conserve resources.

Innovation Solution

A system and method that control file access by determining a file opening policy based on the vulnerability of the source and consumer software applications, using a monitoring module to identify file parameters and vulnerabilities, and applying access and launching policies to restrict resource usage, thereby optimizing resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus applications scan every suspicious file on the computer, then protection quality against malware is improved, but computer resource consumption increases significantly

Engineering Contradiction:
Improveprotection qualityVSAvoidcomputer resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by differentiating file access control based on specific application vulnerabilities rather than uniformly scanning all files. The system identifies particular vulnerable applications and restricts their file access permissions selectively, rather than applying blanket antivirus scanning to all applications. This targeted approach reduces overall resource consumption while maintaining protection quality for vulnerable applications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic file access policies that adjust based on the vulnerability status of applications. The system continuously monitors application vulnerabilities and dynamically modifies access permissions accordingly. When vulnerabilities are detected, the system dynamically restricts file access for those specific applications, and can lift restrictions when vulnerabilities are patched, allowing flexible resource management while maintaining security.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If antivirus applications perform multiple scans of files after updates, then detection precision of malware is improved, but resource drain on the computer increases

Engineering Contradiction:
Improvemalware detection precisionVSAvoidresource drain
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by proactively restricting file access for applications known to have vulnerabilities before malware can be executed. Instead of waiting for multiple scans to detect malware, the system preemptively blocks potentially harmful file access based on vulnerability databases. This prevents malware execution at the source, eliminating the need for repeated scanning resources while maintaining high detection precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer (the file access control system) between applications and files. This intermediary monitors application vulnerability status and mediates file access requests accordingly. By inserting this control layer, the system can block malicious file access before it reaches the application, reducing the need for multiple antivirus scans and associated resource consumption while maintaining high detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Use of energy by moving object

If the system restricts file access based on application vulnerabilities, then resource consumption is reduced, but protection coverage may be limited

Engineering Contradiction:
Improveresource consumptionVSAvoidprotection coverage
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent applies universality by creating a comprehensive file access control system that serves multiple functions: it acts as a vulnerability monitor, access policy manager, and security enforcement mechanism all in one. The system universally applies to all applications on the computer, not just vulnerable ones, by implementing a general framework that can dynamically adjust permissions based on any application's vulnerability status. This multi-functional approach ensures broad protection coverage while maintaining efficient resource usage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10621356B2System and method of controlling file access of applications based on vulnerabilities of applications
Publication Date: 2020.04.14 AO KASPERSKY LAB
  • US10621356B2 patent drawing
  • US10621356B2 patent drawing
  • US10621356B2 patent drawing

AI summary

Disclosed are systems and methods for controlling opening of computer files by vulnerable applications. An example method includes: responsive to detecting creation by a source software application of a computer file on the user computer, determining a file access policy associated with the computer file based on one or more parameters of the computer file; responsive to detecting a request from a consumer software application to open the computer file, determining an application launching policy associated with the consumer software application based on one or more vulnerabilities identified for the consumer software application; determining a file opening policy associated with the computer file and the consumer software application based on the file access policy, the application launching policy, and respective priorities amongst the policies; and controlling opening of the computer file by the consumer software application according to the determined file opening policy.