Invention Grant
- Patent Title: Detection of undesired computer files in archives
- Patent Title (中): 检测档案中不需要的电脑档案
-
Application No.: US12893094Application Date: 2010-09-29
-
Publication No.: US08151355B2Publication Date: 2012-04-03
- Inventor: Steven Michael Fossen , Alexander Douglas MacDonald
- Applicant: Steven Michael Fossen , Alexander Douglas MacDonald
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Hamilton, DeSanctis & Cha LLP
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Systems and methods that can detect known undesired computer files in protected archives are provided. According to one embodiment, an archive file in transit across a network as an attachment to an email message destined for a client workstation is scanned, without decrypting or decompressing contents of the archive, by an anti-virus detection module running on a network gateway. A type and associated structure of the archive are identified by examining primary or secondary identification bytes of the archive. Based on the type and structure, descriptive information regarding a contained file is obtained. The descriptive information includes a hash value of the contained file in uncompressed format. If the descriptive information matches a signature of a known undesired computer file, then a clean version of the archive is produced by removing the contained file and regenerating the archive. Finally, the clean version of the archive is delivered.
Public/Granted literature
- US20110016530A1 DETECTION OF UNDESIRED COMPUTER FILES IN ARCHIVES Public/Granted day:2011-01-20
Information query