IP Library Granted Patent US 7,107,617
Granted Patent B2
US 7,107,617 · App. 09/975,986 · Granted Sep 12, 2006

Malware scanning of compressed computer files

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,107,617
App. No.
09/975,986
Granted
Sep 12, 2006
Kind
B2
Abstract

A malware scanner ( 8 ) operates to scan compressed computer files ( 16 ) by compressing the malware signatures ( 17 ) using the same compression algorithm as used for the compressed computer file and then comparing the compressed malware signatures ( 18 ) with the compressed computer file directly.

Claims (24)

1. A computer program product embodied on a computer readable medium for controlling a computer to scan a compressed computer file for malware, said compressed computer file being compressed using a compression algorithm, said computer program product comprising:

comparison code operable to compare a plurality of compressed malware signatures compressed using said compression algorithm with said compressed computer file to identify malware within said compressed computer file;

detection code operable to detect from a compressed computer file to be scanned what compression algorithm has been used to compress said compressed computer file; and

compression code operable to compress a plurality of uncompressed malware signatures using said detected compression algorithm to generate said plurality of compressed malware signatures.

2. A computer program product as claimed in claim 1 , wherein said detection code reads compression algorithm specifying data from said compressed computer file.

3. A computer program product as claimed in claim 2 , wherein said compression algorithm uses Huffman coding and said compression algorithm specifying data includes a Huffman coding table used to compressed said compressed computer file.

4. A computer program product as claimed in claim 1 , wherein said comparison code uses a Boyer Moore algorithm or an algorithm based upon structuring the signatures in a tree.

5. A computer program product as claimed in claim 1 , wherein said malware includes at least one of computer viruses, Trojans, worms, banned files and e-mails containing banned content.

6. A method of scanning a compressed computer file for malware, said compressed computer file being compressed using a compression algorithm, said method comprising the step of:

comparing a plurality of compressed malware signatures compressed using said compression algorithm with said compressed computer file to identify malware within said compressed computer file;

detecting from a compressed computer file to be scanned what compression algorithm has been used to compress said compressed computer file; and

compressing a plurality of uncompressed malware signatures using said detected compression algorithm to generate said plurality of compressed malware signatures.

7. A method as claimed in claim 6 , wherein said step of detecting reads compression algorithm specifying data from said compressed computer file.

8. A method as claimed in claim 7 , wherein said compression algorithm uses Huffman coding and said compression algorithm specifying data includes a Huffman coding table used to compressed said compressed computer file.

9. A method as claimed in claim 6 , wherein said step of comparing uses a Boyer Moore algorithm or an algorithm based upon structuring the signatures in a tree.

10. A method as claimed in claim 6 , wherein said malware includes at least one of computer viruses, Trojans, worms, banned files and e-mails containing banned content.

11. Apparatus for scanning a compressed computer file for malware, said compressed computer file being compressed using a compression algorithm, said apparatus comprising:

comparison logic operable to compare a plurality of compressed malware signatures compressed using said compression algorithm with said compressed computer file to identify malware within said compressed computer file;

detection logic operable to detect from a compressed computer file to be scanned what compression algorithm has been used to compress said compressed computer file; and

compression logic operable to compress a plurality of uncompressed malware signatures using said detected compression algorithm to generate said plurality of compressed malware signatures.

12. Apparatus as claimed in claim 11 , wherein said detection logic reads compression algorithm specifying data from said compressed computer file.

13. Apparatus as claimed in claim 12 , wherein said compression algorithm uses Huffman coding and said compression algorithm specifying data includes a Huffman coding table used to compressed said compressed computer file.

14. Apparatus as claimed in claim 11 , wherein said comparison code uses a Bayer Moore algorithm or an algorithm based upon structuring the signatures in a tree.

15. Apparatus as claimed in claim 11 , wherein said malware includes at least one of computer viruses, Trojans, worms, banned flies and e-mails containing banned content.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Aug 1, 2005
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 016593/0812 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2001
From: HURSEY, NEIL J.; MCEWAN, WILLIAM A.
To: NETWORKS ASSOCIATES TECHNOLOGY, INC.
Reel/Frame 012254/0137 →