IP Library Granted Patent US 8,856,930
Granted Patent B2
US 8,856,930 · App. 13/435,101 · Granted Oct 7, 2014

Download control

Inventor: Timo Hirvonen (Espoo, FI)
Assignee: F-Secure Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,856,930
App. No.
13/435,101
Granted
Oct 7, 2014
Kind
B2
Abstract

Download control is disclosed. An apparatus includes one or more processors, and one or more memories including computer program code. The one or more memories and the computer program code configured to, with the one or more processors, cause the apparatus at least to perform: obtain one or more cryptographic hash values of a target file to be downloaded; cause transmission of the one or more cryptographic hash values to a trusted source; obtain reputation data relating to the target file originated from the trusted source in response to the transmission of the one or more cryptographic hash values; and control download of the target file on the basis of the reputation data.

Claims (62)

1. An apparatus comprising

one or more processors, and

one or more memories including computer program code,

the one or more memories and the computer program code configured to, with the one or more processors, cause the apparatus at least to perform:

obtain one or more cryptographic hash values of a target file to be downloaded;

cause transmission of the one or more cryptographic hash values to a trusted source;

obtain reputation data relating to the target file originated from the trusted source in response to the transmission of the one or more cryptographic hash values; and

control download of the target file on the basis of the reputation data,

wherein the one or more memories and the computer program code are further configured to, with the one or more processors, cause the apparatus further to perform:

obtain the one or more cryptographic hash values of the target file to be downloaded by at least one of the following: read the one or more cryptographic hash values from a torrent file, read the one or more cryptographic hash values from a magnet link.

2. The apparatus of claim 1 , wherein the reputation data indicates at least one of the following: a computer security status of the target file, a malware status of the target file, a result of an antivirus software analysis of the target file.

3. The apparatus of claim 1 , wherein the reputation data has been generated in the trusted source by checking the one or more cryptographic hash values against a database including reputation data of a plurality of hash values.

4. The apparatus of claim 1 , wherein the one or more memories and the computer program code are further configured to, with the one or more processors, cause the apparatus further to perform:

transform the reputation data into a download decision data of the target file to be downloaded; and

control the download of the target file on the basis of the reputation data according to the download decision data.

5. The apparatus of claim 1 , wherein the one or more memories and the computer program code are further configured to, with the one or more processors, cause the apparatus to perform the obtaining of the one or more cryptographic hash values, the transmission of the one or more cryptographic hash values, and the obtaining of the reputation data before starting the download of the target file to be downloaded, whereupon the download of the target file is controlled on the basis of the reputation data.

6. The apparatus of claim 1 , wherein the one or more memories and the computer program code are further configured to, with the one or more processors, cause the apparatus further to perform at least one of the following:

control the download of the target file on the basis of the reputation data such that if the reputation data indicates that the target file to be downloaded is clean, download is allowed, or if the reputation data indicates that the target file to be downloaded is malicious, download is not allowed;

if the download of the target file has been initiated before the obtaining of the reputation data, control the download of the target file on the basis of the reputation data such that the download is interrupted if the reputation data indicates that the target file is not safe or the download is continued if the reputation data indicates that the target file is safe; or

if the download of the target file has been completed before the obtaining of the reputation data, control the download of the target file on the basis of the reputation data such that the downloaded target file is discarded if the reputation data indicates that the target file is not safe or the downloaded target file is forwarded for further processing if the reputation data indicates that the target file is safe.

7. A method comprising:

obtaining one or more cryptographic hash values of a target file to be downloaded;

causing transmission of the one or more cryptographic hash values to a trusted source;

obtaining reputation data relating to the target file originated from the trusted source in response to the transmission of the one or more cryptographic hash values; and

controlling download of the target file on the basis of the reputation data,

wherein the obtaining the one or more cryptographic hash values of the target file to be downloaded comprises at least one of the following:

reading the one or more cryptographic hash values from a torrent file;

reading the one or more cryptographic hash values from a magnet link.

8. The method of claim 7 , wherein the reputation data indicates at least one of the following: a computer security status of the target file, a malware status of the target file, a result of an antivirus software analysis of the target file.

9. The method of claim 7 , wherein the reputation data has been generated in the trusted source by checking the one or more cryptographic hash values against a database including reputation data of a plurality of hash values.

10. The method of claim 7 , further comprising:

transforming the reputation data into a download decision data of the target file to be downloaded; and

controlling the download of the target file on the basis of the reputation data according to the download decision data.

11. The method of claim 7 , wherein the obtaining of the one or more cryptographic hash values, the transmission of the one or more cryptographic hash values, and the obtaining of the reputation data are performed before starting the download of the target file to be downloaded, whereupon the download of the target file is controlled on the basis of the reputation data.

12. The method of claim 7 , further comprising at least one of the following:

controlling the download of the target file on the basis of the reputation data such that if the reputation data indicates that the target file to be downloaded is clean, download is allowed, or if the reputation data indicates that the target file to be downloaded is malicious, download is not allowed;

if the download of the target file has been initiated before the obtaining of the reputation data, controlling the download of the target file on the basis of the reputation data such that the download is interrupted if the reputation data indicates that the target file is not safe or the download is continued if the reputation data indicates that the target file is safe;

if the download of the target file has been completed before the obtaining of the reputation data, controlling the download of the target file on the basis of the reputation data such that the downloaded target file is discarded if the reputation data indicates that the target file is not safe or the downloaded target file is forwarded for further processing if the reputation data indicates that the target file is safe.

13. A non-transitory computer readable medium comprising a set of instructions, which, when executed on an apparatus cause the apparatus to perform:

obtaining one or more cryptographic hash values of a target file to be downloaded;

causing transmission of the one or more cryptographic hash values to a trusted source;

obtaining reputation data relating to the target file originated from the trusted source in response to the transmission of the one or more cryptographic hash values; and

controlling download of the target file on the basis of the reputation data, the non-transitory computer readable medium, comprising a set of further instructions, which, when executed on the apparatus cause the apparatus to obtain the one or more cryptographic hash values of the target file to be downloaded by at least one of the following:

reading the one or more cryptographic hash values from a torrent file;

reading the one or more cryptographic hash values from a magnet link.

14. The non-transitory computer readable medium of claim 13 , wherein the reputation data indicates at least one of the following: a computer security status of the target file, a malware status of the target file, a result of an antivirus software analysis of the target file.

15. The non-transitory computer readable medium of claim 13 , wherein the reputation data has been generated in the trusted source by checking the one or more cryptographic hash values against a database including reputation data of a plurality of hash values.

16. The non-transitory computer readable medium of claim 13 , comprising a set of further instructions, which, when executed on the apparatus cause the apparatus to further perform:

transforming the reputation data into a download decision data of the target file to be downloaded; and

controlling the download of the target file on the basis of the reputation data according to the download decision data.

17. The non-transitory computer readable medium of claim 13 , wherein the obtaining of the one or more cryptographic hash values, the transmission of the one or more cryptographic hash values, and the obtaining of the reputation data are performed before starting the download of the target file to be downloaded, whereupon the download of the target file is controlled on the basis of the reputation data.

18. The non-transitory computer readable medium of claim 13 , comprising a set of further instructions, which, when executed on the apparatus cause the apparatus to further perform at least one of the following:

controlling the download of the target file on the basis of the reputation data such that if the reputation data indicates that the target file to be downloaded is clean, download is allowed, or if the reputation data indicates that the target file to be downloaded is malicious, download is not allowed;

if the download of the target file has been initiated before the obtaining of the reputation data, controlling the download of the target file on the basis of the reputation data such that the download is interrupted if the reputation data indicates that the target file is not safe or the download is continued if the reputation data indicates that the target file is safe;

if the download of the target file has been completed before the obtaining of the reputation data, controlling the download of the target file on the basis of the reputation data such that the downloaded target file is discarded if the reputation data indicates that the target file is not safe or the downloaded target file is forwarded for further processing if the reputation data indicates that the target file is safe.

19. An apparatus comprising:

means for obtaining one or more cryptographic hash values of a target file to be downloaded;

means for causing transmission of the one or more cryptographic hash values to a trusted source;

means for obtaining reputation data relating to the target file originated from the trusted source in response to the transmission of the one or more cryptographic hash values; and

means for controlling download of the target file on the basis of the reputation data,

wherein the means for obtaining are configured to obtain the one or more cryptographic hash values of the target file to be downloaded by at least one of the following: read the one or more cryptographic hash values from a torrent file, read the one or more cryptographic hash values from a magnet link.

20. The apparatus of claim 1 , wherein the one or more cryptographic hash values of the target file to be downloaded are obtained from a file that is separate and distinct from the target file to be downloaded, and are not part of the target file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2012
From: HIRVONEN, TIMO
To: F-SECURE CORPORATION
Reel/Frame 028132/0339 →
Continuity (1)
Related Publication 20130262851A1 · Oct 3, 2013