- Patent Title: Detection of undesired computer files using digital certificates
-
Application No.: US14670235Application Date: 2015-03-26
-
Publication No.: US09774607B2Publication Date: 2017-09-26
- Inventor: Steven Michael Fossen , Alexander Douglas MacDonald
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Hamilton, DeSanctis & Cha LLP
- Main IPC: G06F21/64
- IPC: G06F21/64 ; H04L29/06 ; G06F21/56 ; H04L12/58

Abstract:
Methods and systems for detecting undesirable computer files based on scanning and analysis of information contained within an associated digital certificate chain are provided. According to one embodiment, a file having associated therewith a certificate chain is received. A type and structure of the file are identified. A location of the certificate chain is determined based on the identified type and structure. A signature of the file is formed by extracting a targeted subset of information from the certificate chain. The file is evaluated by comparing the signature with a set signatures having a known desirable or undesirable status. The file is classified based on a result of the evaluating into a category of multiple categories, including one indicative of an associated file being an undesired file or a file suspected of being undesired. The file is handled in accordance with a policy associated with the category.
Public/Granted literature
- US20150295937A1 DETECTION OF UNDESIRED COMPUTER FILES USING DIGITAL CERTIFICATES Public/Granted day:2015-10-15
Information query