IP Library Granted Patent US 7,383,580
Granted Patent B1
US 7,383,580 · App. 10/341,734 · Granted Jun 3, 2008

Computer virus detection and prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,383,580
App. No.
10/341,734
Granted
Jun 3, 2008
Kind
B1
Abstract

A system ( 140 ) prevents the spread of viruses in a network ( 100 ). The system ( 140 ) receives a hash value from a remote device ( 130 ), compares the hash value to a group of hash values associated with data messages including viruses, and generates a first message when the hash value matches one of the group of hash values. The first message instructs the remote device ( 130 ) to discard a received data message. The system ( 140 ) also generates a second message when the hash value does not match one of the group of hash values. The second message instructs the remote device ( 130 ) to forward the received data message to a user of the remote device ( 130 ).

Claims (75)

1. A method for preventing a spread of electronic viruses in a network, comprising:

receiving a data message at a first device;

hashing the data message to obtain a hash value;

transmitting the hash value to a remote device;

determining, at the remote device, whether the data message contains a virus using the hash value;

transmitting an action message from the remote device to the first device based on the determining, the action message commanding the first device to perform at least one of discarding the data message and making the data message available to a user of the first device; and

processing the data message at the first device based on the action message.

2. The method of claim 1 wherein the data message includes an electronic mail message.

3. The method of claim 1 wherein the determining includes:

comparing the hash value to a plurality of stored hash values, the plurality of stored hash values being associated with viruses,

generating the action message to command the first device to discard the data message when the hash value matches one of the plurality of stored hash values, and

generating the action message to command the first device to make the data message available to a user of the first device when the hash value does not match any of the plurality of stored hash values.

4. The method of claim 1 wherein the hashing includes:

using one of a Message Digest 4 (MD4), MD5, Secure Hashing Algorithm 1 (SHA-1), Hashed Message Authentication Code (HMAC, Data Encryption Standard (DES), and RACE Integrity Primitives Evaluation Message Digest 160 (RIPEMD-160) hash function to hash the data message.

5. A computer-readable medium that is associated with a first device, the medium having tangibly embodied thereon instructions for controlling at least one processor included in the first device to perform a method for preventing a spread of viruses in a network, the method comprising:

receiving in the first device a hash value from a remote device;

comparing the hash value to a plurality of hash values associated with data messages including viruses;

generating a first message when the hash value matches one of the plurality of hash values;

transmitting the first message from the first device to the remote device, the first message instructing the remote device to discard a received data message; and

generating a second message when the hash value does not match one of the plurality of hash values; and

transmitting the second message from the first device to the remote device, the second message instructing the remote device to forward the received data message to a user of the remote device.

6. The computer-readable medium of claim 5 wherein the hash value is associated with the data message.

7. The computer-readable medium of claim 5 further comprising:

transmitting one of the first and second messages to the remote device.

8. A method for preventing a spread of viruses in a network, comprising:

receiving a hash value in a first device;

comparing the received hash value to a plurality of hash values associated with data messages including viruses;

creating a first message when the hash value matches one of the plurality of hash values;

transmitting the first message from the first device to the remote device, the first message instructing the remote device to discard a received data message; and

creating a second message when the hash value does not match one of the plurality of hash values; and

transmitting the second message from the first device to the remote device, the second message instructing the remote device to forward the received data message to a user of the remote device.

9. The method of claim 8 wherein the received hash value is associated with the data message.

10. The method of claim 8 further comprising:

transmitting one of the first and second messages to the remote device.

11. A system for preventing a spread of viruses in a network, comprising:

means for receiving at least one data message;

means for hashing the at least one data message to obtain a hash value;

means for comparing the hash value to a plurality of hash values associated with viruses;

means for generating a first message when the hash value matches one of the plurality of hash values; and

means for transmitting the first message from the first device to the remote device, the first message instructing the remote device to discard a received data message.

12. A first device comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions to:

receive a data message from a remote device,

hash the data message to obtain a hash value, and

transmit a first message from the first device to the remote device, the first message instructing the remote device to discard the data message when the hash value matches one of the plurality of hash values.

13. The first device of claim 12 wherein the processor is further configured to:

transmit a second message from the first device to the remote device, the second message instructing the remote device to forward the received data message to a user of the remote device when the hash value does not match one of the plurality of hash values.

14. A first device comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions to:

receive a hash value from a remote device,

compare the received hash value to a plurality of hash values associated with data messages including viruses,

generating a first message when the received hash value matches one of the plurality of hash values, and

transmit the first message from the first device to the remote device, the first message instructing the remote device to discard a data message associated with the hash value.

15. The first device of claim 14 wherein the processor is further configured to:

generate a second message when the received hash value does not match any of the plurality of hash values, the second message instructing the remote device to forward the data message to a user.

16. The first device of claim 15 wherein the processor is further configured to:

receive at least one data message including a virus,

hash the at least one data message, and

store the at least one hashed data message.

17. The first device of claim 16 wherein the at least one data message is receive at a predetermined time interval.

18. The first device of claim 16 wherein the at least one data message is received in response to an update request from the processor.

19. A system comprising:

a first device configured to:

receive a data message,

hash the data message to obtain a hash value, and

transmit the hash value; and

a second device configured to;

receive the hash value from the first device,

compare the hash value to a plurality of stored hash values,

generate a first message when the hash value matches one of the plurality of stored hash values,

the first message commanding the first device to delete the data message,

generate a second message when the hash value does not match any of the plurality of stored hash values, the second message commanding the first device to forward the data message to a user of the first device, and

transmit the first or second message to the first device.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2014
From: VERIZON CORPORATE SERVICES GROUP INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 033421/0403 →
CHANGE OF NAME Recorded Jun 11, 2010
From: BBN TECHNOLOGIES CORP.
To: RAYTHEON BBN TECHNOLOGIES CORP.
Reel/Frame 024523/0625 →
RELEASE OF SECURITY INTEREST Recorded Oct 27, 2009
From: BANK OF AMERICA, N.A. (SUCCESSOR BY MERGER TO FLEET NATIONAL BANK)
To: BBN TECHNOLOGIES CORP. (AS SUCCESSOR BY MERGER TO BBNT SOLUTIONS LLC)
Reel/Frame 023427/0436 →
MERGER Recorded Jun 7, 2006
From: BBNT SOLUTIONS LLC
To: BBN TECHNOLOGIES CORP.
Reel/Frame 017751/0049 →
PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jun 9, 2004
From: BBNT SOULTIONS LLC
To: FLEET NATIONAL BANK, AS AGENT
Reel/Frame 014718/0294 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2004
From: BBNT SOLUTIONS LLC
To: BBNT SOLUTIONS LLC; VERIZON CORPORATE SERVICES GROUP INC.
Reel/Frame 014634/0525 →
JOINT ASSIGNMENT Recorded May 4, 2004
From: BBNT SOLUTIONS LLC
To: VERIZON CORPORATE SERVICES GROUP INC.; BBNT SOLUTIONS LLC
Reel/Frame 014601/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2003
From: FRENTZ, MICHAEL JOSEPH
To: BBNT SOLUTIONS LLC
Reel/Frame 013666/0573 →