IP Library Granted Patent US 7,757,298
Granted Patent B2
US 7,757,298 · App. 11/145,125 · Granted Jul 13, 2010

Method and apparatus for identifying and characterizing errant electronic files

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,757,298
App. No.
11/145,125
Granted
Jul 13, 2010
Kind
B2
Abstract

A computer system includes a, server having a memory connected thereto. The server is adapted to be connected to a network to permit remote storage and retrieval of data files from the memory. A file identification application is operative with the server to identify errant files stored in the memory. The file identification application provides the functions of: (1) selecting a file stored in said memory; (2) generating a unique checksum corresponding to the stored file; (3) comparing said unique checksum to each of a plurality of previously generated checksums, wherein the plurality of previously generated checksums correspond to known errant files; and (4) marking the file for deletion from the memory if the unique checksum matches one of the plurality of previously generated checksums.

Claims (38)

1. A computer-implemented method for identifying and characterizing stored electronic files, said method comprising:

under control of one or more configured computer systems:

selecting a file from a plurality of files stored in a computer storage medium, wherein selecting the file is performed according to at least one of:

selecting the file based on the size of the file by determining whether an aggregate size of plural identically-sized files exceeds a predetermined threshold;

selecting the file based on whether content of the file matches a file type indicated by a name of the file; or

selecting the file based on whether the file comprises data beyond an end of data marker for the file;

generating an identification value associated with the selected file, wherein the identification value is representative of at least a portion of the content of the selected file;

comparing the generated identification value to one or more identification values associated with one or more of a plurality of unauthorized files; and

characterizing the file as an unauthorized file if the identification value matches one of the plurality of identification values associated with the unauthorized files.

2. The computer-implemented method of claim 1 , further comprising selecting the file from one of a plurality of sequentially-ordered files in a directory of the computer storage medium.

3. The computer-implemented method of claim 1 , wherein generating an identification value comprises generating a checksum.

4. The computer-implemented method of claim 3 , wherein-generating an identification value comprises generating a first checksum corresponding to a first portion of said stored file and a second checksum corresponding to a second portion of said stored file.

5. The computer-implemented method of claim 3 , wherein generating an identification value comprises generating a first checksum corresponding to a first portion of said stored file and a second checksum corresponding to a larger portion of said stored file that includes the first portion.

6. The computer-implemented method of claim 1 , further comprising processing a plurality of known unauthorized files to generate the plurality of identification values.

7. The computer-implemented method of claim 1 , further comprising presenting the identified unauthorized file for human review prior to disposing of it.

8. The computer-implemented method of claim 1 , further comprising automatically notifying a third party that the file has been identified.

9. The computer-implemented method of claim 1 , further comprising deleting the identified unauthorized file from the computer storage medium.

10. A computer system, comprising:

a server having a memory connected, thereto, said server being adapted to be connected to a network to permit remote storage and retrieval of data files from the memory; and

a file identification application operative with the server to identify unauthorized files stored in the memory, the file identification application providing the functions of:

selecting a file from a plurality of files stored in the memory, wherein selecting the file is performed according to at least one of:

selecting the file by determining whether an aggregate size of plural identically-sized files exceeds a predetermined threshold;

selecting the file based on whether content of the file matches a file type indicated by a name of the file; or

selecting the file based on whether the file comprises data beyond an end of data marker for the file;

generating an identification value associated with the selected file, wherein the identification value is representative of at least a portion of the content of the selected file;

comparing the generated identification value to one or more identification values associated with one or more of a plurality of unauthorized files; and

characterizing the file as an unauthorized file if the identification value matches one of the plurality of identification values associated with the unauthorized files.

11. The system of claim 10 , wherein the application further comprises the function of selecting the file from one of a plurality of sequentially-ordered files in a directory of the computer storage medium.

12. The system of claim 10 , wherein the application further comprises the function of selecting the file from a plurality of files stored in the computer storage medium, based on size of the file.

13. The system of claim 10 , wherein generating an identification value comprises generating a checksum.

14. The system of claim 13 , wherein generating an identification value comprises generating a checksum corresponding to a first portion of the selected file and a second checksum corresponding to a second portion of the selected file.

15. The system of claim 13 , wherein generating an identification value comprises generating a first checksum corresponding to a first portion of the selected file and a second checksum corresponding to a larger portion of the selected file that includes the first portion.

16. A non-transitory computer-readable storage medium having instructions stored thereon that, in response to execution by a computing device, cause the computing device to perform a operations comprising:

selecting a file from a plurality of files stored in a computer storage medium, wherein selecting the file is performed according to at least one of:

selecting the file based on the size of the file by determining whether an aggregate size of plural identically-sized files exceeds a predetermined threshold;

selecting the file based on whether content of the file matches a file type indicated by a name of the file; or

selecting the file based upon whether the file comprises data beyond an end of data marker for the file;

categorizing the selected file as an unauthorized file based on a comparison of an identification value associated with the selected file with one or more identification values associated with one or more of a plurality of unauthorized files.

Assignments (3)
MERGER Recorded May 28, 2013
From: HOSHIKO LLC
To: INTELLECTUAL VENTURES I LLC
Reel/Frame 030494/0397 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 018498 FRAME 0337.ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNEE'S NAME IS HOSHIKO LLC,NOT HOSHIKO,LLC Recorded Sep 13, 2012
From: IDEAFLOOD, INC.
To: HOSHIKO LLC
Reel/Frame 029006/0972 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2006
From: IDEAFLOOD, INC.
To: HOSHIKO, LLC
Reel/Frame 018498/0337 →