IP Library Granted Patent US 8,316,446
Granted Patent B1
US 8,316,446 · App. 11/112,033 · Granted Nov 20, 2012

Methods and apparatus for blocking unwanted software downloads

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,316,446
App. No.
11/112,033
Granted
Nov 20, 2012
Kind
B1
Abstract

Methods and systems for blocking unwanted software downloads within a network. Such methods may thereby prevent (i) downloads of spyware from one or more identified locations, and/or (ii) certain outbound communications from the network and/or may also permit software downloads only from specified locations. In general, the policies are defined by rules specified by a network administrator or other user.

Claims (23)

1. A method, comprising:

intercepting at a Uniform Resource Locator (URL) filter module of a network device, an attempted download of a file from a URL;

categorizing by the URL filter module of the network device the URL into a URL category according to a URL database;

analyzing by a file type identifier module of the network device the file to determine its file type, wherein the file type of the file is determined by detecting one or more of a file type signature in the file and a file extension of the file, and identifying the file type of the file based on one or more of the file type signature detected in the file and the file extension of the file; and

blocking or not blocking the attempted download according to a decision output of a blocking decision module of the network device which receives as inputs the URL category and the file type, wherein (i) if the URL category indicates a blacklist, the decision output is to block the download, (ii) if the URL category indicates a whitelist, the decision output is to allow the download, otherwise, the URL category specifies a URL content category indicating a type of content provided by the URL, and the decision output is based on whether files of said file type are permitted for URLs in the URL content category.

2. The method of claim 1 , wherein the detected file extension is one of a .exe, .com, .dll, .cab, .ocx, .bat, .cmd, .vbs, .vb, .pif, .hlp, .msi, .scr, .wsc, .wsh, .wsf, .hta, .class, .jar, .chm, .cpl, and .zip file extension.

3. The method of claim 1 , wherein the URL database is stored remotely.

4. The method of claim 1 , further comprising scanning, by a spyware detection module, outgoing communications for spyware signatures.

5. A network device, comprising:

a processor;

a storage device connected to the processor; and

a set of instructions on the storage device that are executable by the processor, including:

a Uniform Resource Locator (URL) filter software subroutine configured to intercept an attempted download of a file from a URL, and categorize the URL into a URL category according to a URL database;

a file type identifier software subroutine configured to analyze the file to determine its file type, wherein the file type identifier software subroutine is further configured to determine the file type of the file by detecting one or more of a file type signature in the file and a file extension of the file, and identifying the file type of the file based on one or more of the file type signature detected in the file and the file extension of the file; and

a blocking decision software subroutine configured to block or not block the attempted download according to a decision output of the blocking decision software subroutine which receives as inputs the URL category and the file type, wherein (i) if the URL category indicates a blacklist, the decision output is to block the download, (ii) if the URL category indicates a whitelist, the decision output is to allow the download, otherwise, the URL category specifies a URL content category indicating a type of content provided by the URL, and the decision output is based on whether files of said file type are permitted for URLs in the URL content category.

6. The network device of claim 5 , wherein the detected file extension is one of a .exe, .com, .dll, .cab, or .ocx file extension.

7. The network device of claim 5 , further comprising a spyware detection software subroutine configured to scan outgoing communications for spyware signatures.

8. A non-transitory machine-readable storage medium, comprising:

first software instructions that, when executed by a processor, cause the processor to intercept an attempted download of a file from a Uniform Resource Locator (URL); second software instructions that, when executed by the processor, cause the processor to categorize the URL into a URL category according to a URL database;

third software instructions that, when executed by the processor, cause the processor to analyze the file to determine its file type, wherein the file type of the file is determined by detecting one or more of a file type signature in the file and a file extension of the file, and identifying the file type of the file based on one or more of the file type signature detected in the file and the file extension of the file; and

fourth software instructions that, when executed by the processor, cause the processor to block or not block the attempted download according to a decision output of a blocking rule based on the URL category and the file type, wherein (i) if the URL category indicates a blacklist, the decision output is to block the download, (ii) if the URL category indicates a whitelist, the decision output is to allow the download, otherwise, the URL category specifies a URL content category indicating a type of content provided by the URL, and the decision output is based on whether files of said file type are permitted for URLs in the URL content category.

9. The non-transitory machine-readable storage medium of claim 8 , wherein the detected file extension is one of a .exe, .com, .dll, .cab, or .ocx file extension.

10. The non-transitory machine-readable storage medium of claim 8 , further comprising fifth software instructions for detecting outbound communications for spyware signatures.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME TO BLUE COAT SYSTEMS, INC. PREVIOUSLY RECORDED ON REEL 016721 FRAME 0797. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 1, 2011
From: CAMPBELL, ALEXANDER WADE; DOLSEN, LEE THOMAS; OSITIS, VILIS; SMITH, CAMERON CHARLES
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 027306/0870 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2005
From: CAMPBELL, ALEXANDER WADE; DOLSEN, LEE THOMAS; OSITIS, VILIS; SMITH, CAMERON CHARLES
To: BLUE COAT SYSTEMS
Reel/Frame 016721/0797 →