- Patent Title: Detection of undesired computer files using digital certificates
-
Application No.: US15704304Application Date: 2017-09-14
-
Publication No.: US09992165B2Publication Date: 2018-06-05
- Inventor: Steven Michael Fossen , Alexander Douglas MacDonald
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Hamilton, DeSanctis & Cha LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; H04L29/06 ; H04L12/58

Abstract:
Methods and systems for detecting undesirable computer files based on scanning and analysis of information contained within an associated digital certificate chain are provided. According to one embodiment, a file having associated therewith a certificate chain is received. A type and structure of the file are identified. A location of the certificate chain is determined based on the identified type and structure. A signature of the file is formed by extracting a targeted subset of information from the certificate chain. The file is evaluated by comparing the signature with a set signatures having a known desirable or undesirable status. The file is classified based on a result of the evaluating into a category of multiple categories, including one indicative of an associated file being an undesired file or a file suspected of being undesired. The file is handled in accordance with a policy associated with the category.
Public/Granted literature
- US20180007006A1 DETECTION OF UNDESIRED COMPUTER FILES USING DIGITAL CERTIFICATES Public/Granted day:2018-01-04
Information query