IP Library Granted Patent US 8,607,347
Granted Patent B2
US 8,607,347 · App. 12/239,867 · Granted Dec 10, 2013

Network stream scanning facility

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,607,347
App. No.
12/239,867
Granted
Dec 10, 2013
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for providing a scanning of data associated with a network computer facility. In the process, a request may be received for network content from a content requesting computing facility. A source lookup associated with the request for network content may be performed, where the source lookup may be from a networked source lookup database. The requested network content may then be retrieved, where the type of the content may be determined as a further aid in scanning the content. A checksum of at least a portion of the retrieved network content may then be calculated, and a checksum lookup associated with the portion of the retrieved network content be performed, where the checksum lookup may be from a networked checksum lookup database. Finally, an action may be taken based on at least one of the source lookup and checksum lookup, where the action is associated with protecting the content requesting computing facility from malware.

Claims (35)

1. A method of scanning data comprising:

receiving a request for network content at a scanning facility, the request received from a content requesting computing facility remote from the scanning facility, and the request including a source from which to retrieve the network content;

performing a source lookup for the request at the scanning facility, wherein the source lookup requests data concerning the source of the request from a networked source lookup database, and wherein the networked source lookup database responds with a characterization of the source;

retrieving the network content to the scanning facility;

calculating a checksum of the network content;

performing a checksum lookup on the checksum, wherein the checksum lookup is from a networked checksum lookup database that stores checksums for known malware content; and

when the network content is not identified as malware based upon the checksum lookup, taking an action to protect the content requesting computing facility from malware based on the characterization of the source from the networked source lookup database.

2. The method of claim 1 , wherein the action is blocking the requested network content.

3. The method of claim 1 , wherein the action is sending the requested network content to the content requesting computing facility.

4. The method of claim 1 , wherein the action is providing further scanning of the received network content, wherein the further scanning depends on the characterization of the network content.

5. The method of claim 1 , wherein the action is determined by a policy.

6. The method of claim 1 , wherein the action is determined by a type of the requested network content.

7. The method of claim 1 , wherein the networked source lookup database includes a plurality of characterizations of a plurality of previously identified URLs.

8. The method of claim 1 , wherein the networked source lookup database includes a white list of URLs that are acceptable to access.

9. The method of claim 1 , wherein the networked source lookup database includes a black list of URLs that are unacceptable to access.

10. The method of claim 1 , wherein the result of the source lookup is used in subsequent scanning.

11. The method of claim 1 , further comprising updating the networked source database when a scan of the networked source lookup database with the source of the network content when a scan of the network content identifies malware.

12. The method of claim 1 , wherein the networked checksum lookup database includes checksums generated from the same length of data as the network content.

13. A system comprising:

a network device with on-device malware analysis tools;

a networked source lookup database storing a characterization of a number of URLs, the networked source lookup database configured to respond to a source URL with a corresponding characterization of the source URL;

a networked checksum lookup database storing checksums for known malware content, the networked checksum lookup database configured to respond to a checksum with any malware known to be associated with the checksum; and

a content requesting computing facility configured to request network content through the network device, wherein the network device is configured to protect the content requesting computing facility from malware by sequentially performing a first query of the networked source lookup database and a second query of the networked checksum lookup database, and further configured to conditionally take action according to a result of the first query and the second query.

14. The system of claim 13 , wherein the action is blocking the requested network content.

15. The system of claim 13 , wherein the action is sending the requested network content to the content requesting computing facility.

16. The system of claim 13 , wherein the action is providing further scanning of the received network content.

17. The system of claim 13 , wherein the action is determined by a policy.

18. The system of claim 13 , wherein the action is determined by the type of the requested network content.

19. The system of claim 13 , wherein the networked source lookup database includes a characterization of previously identified URLs.

20. The system of claim 13 , wherein the networked source lookup database includes a white list of URLs that are acceptable to access.

21. The system of claim 13 , wherein the networked source lookup database includes a black list of URLs that are unacceptable to access.

22. The system of claim 13 , wherein a result of the first query is used in subsequent scanning

23. The system of claim 13 , wherein the networked checksum lookup database includes checksums from prior network content identified to contain malware.

24. The system of claim 13 , wherein the networked checksum lookup database includes checksums generated from the same length of data as the network content.

25. The system of claim 13 , wherein the on-device malware analysis tools include a malware scanning facility.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
RELEASE OF SECURITY INTEREST Recorded Jul 28, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: SOPHOS LIMITED
Reel/Frame 053334/0220 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF SECURITY INTEREST Recorded Feb 3, 2014
From: JPMORGAN CHASE BANK, N.A.
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032152/0883 →
CHANGE OF NAME Recorded Apr 11, 2013
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 030194/0299 →
SECURITY INTEREST Recorded May 11, 2012
From: RBC EUROPE LIMITED, AS EXISTING ADMINISTRATION AGENT AND COLLATERAL AGENT
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 028198/0285 →
SECURITY AGREEMENT Recorded Aug 8, 2011
From: SOPHOS LIMITED F/K/A SOPHOS PLC
To: ROYAL BANK OF CANADA EUROPE LIMITED, AS COLLATERAL AGENT
Reel/Frame 026717/0424 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2008
From: HARRIS, MARK D.; THOMAS, ANDREW J.; MAGDIC, MARIO; LYNE, JAMES I.
To: SOPHOS PLC
Reel/Frame 021759/0914 →