IP Library Granted Patent US 8,893,277
Granted Patent B2
US 8,893,277 · App. 12/783,899 · Granted Nov 18, 2014

Fingerprint analysis for anti-virus scan

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,893,277
App. No.
12/783,899
Granted
Nov 18, 2014
Kind
B2
Abstract

Disclosed is a method of operating a data identification system. The method comprises identifying a first plurality of changed blocks in a first primary storage volume, processing the first plurality of changed blocks to generate a first plurality of fingerprints, scanning a first plurality of data items stored in a first secondary storage volume within the first primary storage volume corresponding to the first plurality of changed blocks to identify a first infected data item of the first plurality of data items, identifying a first reference fingerprint from the first plurality of fingerprints corresponding to the first infected data item, identifying a second plurality of changed blocks in a second primary storage volume corresponding to a second plurality of data items stored in a second secondary storage volume within the second primary storage volume, processing the second plurality of changed blocks to generate a second plurality of fingerprints, and identifying a first target fingerprint from the second plurality of fingerprints that corresponds to the first reference fingerprint.

Claims (33)

1. A method of operating a data identification system, the method comprising:

identifying a first plurality of changed blocks in a first virtual machine file stored on a physical storage system;

processing the first plurality of changed blocks to generate a first plurality of fingerprints;

scanning a first plurality of data items stored in a first virtual drive within the first virtual machine file to identify a first infected data item of the first plurality of data items, wherein the first infected data item is stored in a portion of the first virtual drive within at least one of the first plurality of changed blocks;

identifying a first reference fingerprint from the first plurality of fingerprints corresponding to the first infected data item;

identifying a second plurality of changed blocks in a second virtual machine file stored on the physical storage system corresponding to a second plurality of data items stored in a second virtual drive within the second virtual machine file;

processing the second plurality of changed blocks to generate a second plurality of fingerprints; and

identifying a first target fingerprint from the second plurality of fingerprints that corresponds to the first reference fingerprint.

2. The method of claim 1 further comprising adding the first reference fingerprint to an infected fingerprint list.

3. The method of claim 2 further comprising scanning a first target data item of a second plurality of data items to identify a second infected data item, wherein the first target data item corresponds to the first target fingerprint of the second plurality of fingerprints.

4. The method of claim 3 further comprising scanning a subset of data items of the second plurality of data items not including the first target data item to identify another infected data item of the subset of data items of the second plurality of data items.

5. The method of claim 4 further comprising adding another fingerprint from the second plurality of fingerprints corresponding to the another infected data item of the subset of data items of the second plurality of files to the infected fingerprint list.

6. The method of claim 4 further comprising adding the second plurality of fingerprints to the infected fingerprint list if the first target fingerprint from the second plurality of fingerprints matches the first reference fingerprint from the first plurality of fingerprints.

7. The method of claim 4 further comprising adding the first plurality of fingerprints not including the first reference fingerprint from the first plurality of fingerprints to a non-infected fingerprint list.

8. The method of claim 7 further comprising comparing each fingerprint of the second plurality of fingerprints to each fingerprint of the non-infected fingerprint list if each fingerprint of the second plurality of fingerprints does not match a fingerprint of the infected fingerprint list.

9. A data identification system, the system comprising:

an interface configured to receive a scan request a scan request; and

a processor in communication with the interface and configured to receive the scan request, identify a first plurality of changed blocks in a first virtual machine file stored on a physical storage system, process the first plurality of changed blocks to generate a first plurality of fingerprints, scan a first plurality of data items stored in a first virtual drive within the first virtual machine file to identify a first infected data item of the first plurality of data items, wherein the first infected data item is stored in a portion of the first virtual drive within at least one of the first plurality of changed blocks, identify a first reference fingerprint from the first plurality of fingerprints corresponding to the first infected data item, identify a second plurality of changed blocks in a second virtual machine file stored on the physical storage system corresponding to a second plurality of data items stored in a second virtual drive within the second virtual machine file, process the second plurality of changed blocks to generate a second plurality of fingerprints, and identify a first target fingerprint from the second plurality of fingerprints that corresponds to the first reference fingerprint.

10. The data identification system of claim 9 the processor further configured to add the first reference fingerprint to an infected fingerprint list.

11. The data identification system of claim 10 the processor further configured to scan a first target data item of a second plurality of data items to identify a second infected data item, wherein the first target data item corresponds to the first target fingerprint of the second plurality of fingerprints.

12. The data identification system of claim 11 the processor further configured to scan a subset of data items of the second plurality of data items not including the first target data item to identify another infected data item of the subset of data items of the second plurality of data items.

13. The data identification system of claim 12 the processor further configured to add another fingerprint from the second plurality of fingerprints corresponding to the another infected data item of the subset of data items of the second plurality of files to the infected fingerprint list.

14. The data identification system of claim 12 the processor further configured to add the second plurality of fingerprints to the infected fingerprint list if the first target fingerprint from the second plurality of fingerprints matches the first reference fingerprint from the first plurality of fingerprints.

15. The data identification system of claim 12 the processor further configured to add the first plurality of fingerprints not including the first reference fingerprint from the first plurality of fingerprints to a non-infected fingerprint list.

16. The data identification system of claim 15 the processor further configured to compare each fingerprint of the second plurality of fingerprints to each fingerprint of the non-infected fingerprint list if each fingerprint of the second plurality of fingerprints does not match a fingerprint of the infected fingerprint list.

17. A non-transitory computer readable medium having program instructions stored thereon for operating a data identification system that, when executed by a data identification system, direct the data identification system to:

identify a first plurality of changed blocks in a first virtual machine file stored on a physical storage system;

process the first plurality of changed blocks to generate a first plurality of fingerprints;

scan a first plurality of data items stored in a first virtual drive within the first virtual machine file to identify a first infected data item of the first plurality of data items, wherein the first infected data item is stored in a portion of the first virtual drive within at least one of the first plurality of changed blocks;

identify a first reference fingerprint from the first plurality of fingerprints corresponding to the first infected data item;

identify a second plurality of changed blocks in a second virtual machine file stored on the physical storage system corresponding to a second plurality of data items stored in a second virtual drive within the second virtual machine file;

process the second plurality of changed blocks to generate a second plurality of fingerprints; and

identify a first target fingerprint from the second plurality of fingerprints that corresponds to the first reference fingerprint.

Assignments (13)
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT AT REEL/FRAME NO. 40473/0378 Recorded Oct 8, 2025
From: PNC BANK, NATIONAL ASSOCIATION, AS AGENT
To: QUANTUM CORPORATION
Reel/Frame 073061/0454 →
TERMINATION AND RELEASE OF AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT AT REEL/FRAME NO. 48029/0525 Recorded Aug 19, 2025
From: PNC BANK, NATIONAL ASSOCIATION, AS AGENT
To: QUANTUM CORPORATION
Reel/Frame 072542/0594 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2025
From: BLUE TORCH FINANCE LLC, AS AGENT FOR THE SECURED PARTIES
To: ALTER DOMUS (US) LLC, AS AGENT FOR THE SECURED PARTIES
Reel/Frame 071019/0850 →
RELEASE OF SECURITY INTEREST Recorded Aug 10, 2021
From: U.S. BANK NATIONAL ASSOCIATION
To: QUANTUM CORPORATION; QUANTUM LTO HOLDINGS, LLC
Reel/Frame 057142/0252 →
SECURITY INTEREST Recorded Aug 5, 2021
From: QUANTUM CORPORATION; QUANTUM LTO HOLDINGS, LLC
To: BLUE TORCH FINANCE LLC, AS AGENT
Reel/Frame 057107/0001 →
SECURITY INTEREST Recorded Jan 8, 2019
From: QUANTUM CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 048029/0525 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2018
From: TCW ASSET MANAGEMENT COMPANY LLC, AS AGENT
To: QUANTUM CORPORATION
Reel/Frame 047988/0642 →
SECURITY INTEREST Recorded Dec 27, 2018
From: QUANTUM CORPORATION, AS GRANTOR; QUANTUM LTO HOLDINGS, LLC, AS GRANTOR
To: U.S. BANK NATIONAL ASSOCIATION, AS AGENT
Reel/Frame 049153/0518 →
RELEASE OF SECURITY INTEREST Recorded Oct 25, 2016
From: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
To: QUANTUM CORPORATION
Reel/Frame 040474/0079 →
SECURITY INTEREST Recorded Oct 25, 2016
From: QUANTUM CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 040473/0378 →
SECURITY INTEREST Recorded Oct 21, 2016
From: QUANTUM CORPORATION
To: TCW ASSET MANAGEMENT COMPANY LLC, AS AGENT
Reel/Frame 040451/0183 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2016
From: WADE, GREGORY L.; HAILE, J. MITCHELL
To: QUANTUM CORPORATION
Reel/Frame 038962/0421 →
SECURITY AGREEMENT Recorded Mar 31, 2012
From: QUANTUM CORPORATION
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 027967/0914 →