IP Library Granted Patent US 12712888
Granted Patent B2
US 12712888 · App. 18/887,786 · Granted Aug 18, 2026

Reassembly free deep packet inspection for peer to peer networks

Inventors: Hui Ling (Shanghai, CN); Cuiping Yu (Shanghai, CN); Zhong Chen (Fremont, CA)
Assignee: SONICWALL US HOLDINGS INC.
H04L63/1408H04L63/0254H04L63/168H04L63/0245H04L63/1416H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712888
App. No.
18/887,786
Granted
Aug 18, 2026
Kind
B2
Abstract

The present disclosure relates to a system, a method, and a non-transitory computer readable storage medium for deep packet inspection scanning at an application layer of a computer. A method of the presently claimed invention may scan pieces of data received out of order without reassembly at an application layer from a first input state generating one or more output states for each piece of data. The method may then identify that the first input state includes one or more characters that are associated with malicious content. The method may then identify that the data set may include malicious content when the first input state combined with one or more output states matches a known piece of malicious content.

Claims (39)

1 . A method for scanning computer data, the method comprising:

scanning a first out-of-order block of a dataset at an application layer in a peer-to-peer network, wherein the first out-of-order block is scanned for one or more sets of malware;

generating an output state based on the scan of the first out-of-order block;

performing one or more subsequent scans of other blocks of the dataset including a second out-of-order block that precedes the first out-of-order block;

generating output states for each of the subsequent scans;

storing in memory the output states for the first out-of-order block and the output states for the other blocks, wherein the output states are correlated to identified input states, wherein the output state for the first out-of-order block reduces a number of the identified input states used when scanning the second out-of-order block; and

identifying that the dataset includes a set of malware when the output states for the first out-of-order block and the output states for the other blocks match a pattern associated with the identified set of malware.

2 . The method of claim 1 , further comprising eliminating one or more of the sets of malware in accordance with the output state limiting one or more possible input states.

3 . The method of claim 1 , wherein scanning the first out-of-order block is based on an input state associated with the identified set of malware.

4 . The method of claim 3 , wherein the input state associated with the identified set of malware corresponds to an identified input set of an empty string.

5 . The method of claim 3 , wherein the input state indicates that one or more characters in a sequence of characters match the identified set of malware.

6 . The method of claim 1 , wherein the generated output state requires a subsequent portion to end with one or more characters of a string associated with the identified set of malware.

7 . The method of claim 1 , further comprising storing a state mapping in memory that identifies a plurality of states associated with each of the sets of malware.

8 . The method of claim 1 , wherein the output state based on the scan of the first out-of-order block reduces a number of identified input states for the second out-of-order block.

9 . The method of claim 8 , wherein the output state further reduces an amount of the memory used to identify the identified set of malware.

10 . The method of claim 1 , wherein the first out-of-order block is received from a first peer computer of a plurality of peer computers and the second out-of-order block is received from a second peer computer of the plurality of peer computers.

11 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor to implement a method for scanning computer data, the method comprising:

scanning a first out-of-order block of a dataset at an application layer in a peer-to-peer network, wherein the first out-of-order block is scanned for one or more sets of malware;

generating an output state based on the scan of the first out-of-order block;

performing one or more subsequent scans of other blocks of the dataset including a second out-of-order block that precedes the first out-of-order block;

generating output states for each of the subsequent scans;

storing in memory the output states for the first out-of-order block and the output states for the other blocks, wherein the output states are correlated to identified input states, wherein the output state for the first out-of-order block reduces a number of the identified input states used when scanning the second out-of-order block; and

identifying that the dataset includes a set of malware when the output states for the first out-of-order block and the output states for the other blocks match a pattern associated with the identified set of malware.

12 . The non-transitory computer-readable storage medium of claim 11 , further comprising instructions executable to eliminate one or more of the sets of malware in accordance with the output state limiting one or more possible input states.

13 . The non-transitory computer-readable storage medium of claim 11 , wherein scanning the first out-of-order block is based on an input state associated with the identified set of malware.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the input state associated with the identified set of malware corresponds to an identified input set of an empty string.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein the input state indicates that one or more characters in a sequence of characters match the identified set of malware.

16 . The non-transitory computer-readable storage medium of claim 11 , wherein the generated output state requires a subsequent portion to end with one or more characters of a string associated with the identified set of malware.

17 . The non-transitory computer-readable storage medium of claim 11 , further comprising instructions executable to store a state mapping in memory that identifies a plurality of states associated with each of the sets of malware.

18 . The non-transitory computer-readable storage medium of claim 11 , wherein the output state based on the scan of the first out-of-order block reduces a number of identified input states for the second out-of-order block.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein the output state further reduces an amount of the memory used to identify the identified set of malware.

20 . A system for scanning computer data, the system comprising:

a communication interface that communicates over a communication network with one or more computers in a peer-to-peer network, wherein the communication interface receives a plurality of blocks of a dataset;

a processor that executes instructions stored in memory, wherein the processor executes the instructions to:

scan a first out-of-order block of the dataset at an application layer in the peer-to-peer network, wherein the first out-of-order block is scanned for one or more sets of malware,

generate an output state based on the scan of the first out-of-order block,

perform one or more subsequent scans of other blocks of the dataset including a second out-of-order block that precedes the first out-of-order block, and

generate output states for each of the subsequent scans; and

memory that stores the output states for the first out-of-order block and the output states for the other blocks, wherein the output states are correlated to identified input states, wherein the output state for the first out-of-order block reduces a number of the identified input states used when scanning the second out-of-order block, wherein the processor identifies that the dataset includes a set of malware when the output states for the first out-of-order block and the output states for the other blocks match a pattern associated with the identified set of malware.