Invention Grant
- Patent Title: Detection of undesired computer files in damaged archives
- Patent Title (中): 在损坏的档案中检测不需要的计算机文件
-
Application No.: US12899056Application Date: 2010-10-06
-
Publication No.: US08166550B2Publication Date: 2012-04-24
- Inventor: Steven Michael Fossen , Alexander Douglas MacDonald
- Applicant: Steven Michael Fossen , Alexander Douglas MacDonald
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Hamilton, DeSanctis & Cha LLP
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Systems and methods for an anti-virus detection module that can detect known undesired computer files in damaged archives that may be encrypted, compressed and/or password-protected are provided. According to one embodiment, a damaged or incomplete RAR, CAB or ZIP archive is received. Without decrypting or decompressing the contents, an anti-virus detection module identifies the archive as a RAR, CAB or ZIP archive by assuming each of multiple possible archive types in turn and searching all of or certain parts of the archive for content consistent with a current archive type. Based on the identified type, for each contained file, descriptive information is extracted from corresponding local file headers and a threat evaluation is performed by comparing the descriptive information to signatures of known malicious or undesired files. If the threat evaluation concludes a particular contained file is a threat, then appropriate defensive actions are taken in relation to the archive.
Public/Granted literature
- US20110023121A1 DETECTION OF UNDESIRED COMPUTER FILES IN DAMAGED ARCHIVES Public/Granted day:2011-01-27
Information query