Vulnerability-Based File Access Control for Antivirus Resource Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Antivirus applications consume significant computer resources due to frequent scanning of files, even after initial scans, as malware becomes increasingly sophisticated, necessitating a system to restrict file access based on application vulnerabilities to conserve resources.
Innovation Solution
A system and method that control file access by determining a file opening policy based on the vulnerability of the source and consumer software applications, using a monitoring module to identify file parameters and vulnerabilities, and applying access and launching policies to restrict resource usage, thereby optimizing resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus applications scan every suspicious file on the computer, then protection quality against malware is improved, but computer resource consumption increases significantly
Solution Approach 1:
The patent applies local quality by differentiating file access control based on specific application vulnerabilities rather than uniformly scanning all files. The system identifies particular vulnerable applications and restricts their file access permissions selectively, rather than applying blanket antivirus scanning to all applications. This targeted approach reduces overall resource consumption while maintaining protection quality for vulnerable applications.
Solution Approach 2:
The patent implements dynamic file access policies that adjust based on the vulnerability status of applications. The system continuously monitors application vulnerabilities and dynamically modifies access permissions accordingly. When vulnerabilities are detected, the system dynamically restricts file access for those specific applications, and can lift restrictions when vulnerabilities are patched, allowing flexible resource management while maintaining security.
2Measurement precision
If antivirus applications perform multiple scans of files after updates, then detection precision of malware is improved, but resource drain on the computer increases
Solution Approach 1:
The patent applies preliminary action by proactively restricting file access for applications known to have vulnerabilities before malware can be executed. Instead of waiting for multiple scans to detect malware, the system preemptively blocks potentially harmful file access based on vulnerability databases. This prevents malware execution at the source, eliminating the need for repeated scanning resources while maintaining high detection precision.
Solution Approach 2:
The patent introduces an intermediary layer (the file access control system) between applications and files. This intermediary monitors application vulnerability status and mediates file access requests accordingly. By inserting this control layer, the system can block malicious file access before it reaches the application, reducing the need for multiple antivirus scans and associated resource consumption while maintaining high detection accuracy.
3Use of energy by moving object
If the system restricts file access based on application vulnerabilities, then resource consumption is reduced, but protection coverage may be limited
Solution Approach 1:
The patent applies universality by creating a comprehensive file access control system that serves multiple functions: it acts as a vulnerability monitor, access policy manager, and security enforcement mechanism all in one. The system universally applies to all applications on the computer, not just vulnerable ones, by implementing a general framework that can dynamically adjust permissions based on any application's vulnerability status. This multi-functional approach ensures broad protection coverage while maintaining efficient resource usage.
Data Source
AI summary
Disclosed are systems and methods for controlling opening of computer files by vulnerable applications. An example method includes: responsive to detecting creation by a source software application of a computer file on the user computer, determining a file access policy associated with the computer file based on one or more parameters of the computer file; responsive to detecting a request from a consumer software application to open the computer file, determining an application launching policy associated with the consumer software application based on one or more vulnerabilities identified for the consumer software application; determining a file opening policy associated with the computer file and the consumer software application based on the file access policy, the application launching policy, and respective priorities amongst the policies; and controlling opening of the computer file by the consumer software application according to the determined file opening policy.


