Systems and methods for parallel virus and malware scan between agents in a cloud environment
Disclosed herein are systems and methods for parallel malware scanning in a cloud environment. In one exemplary aspect, a method may comprise identifying a plurality of agents connected to a server, wherein each agent is configured to synchronize data between a different computing device and the server. The method may comprise receiving, from a first agent of the plurality of agents, a request to scan the synchronized data for malware. In response to determining, from the plurality of agents, at least one other agent that comprises the synchronized data, the method may comprise partitioning the synchronized data into a plurality of portions. The method may comprise assigning a first portion for scanning to the first agent and at least one other portion for scanning to the at least one other agent, and aggregating scan results from the first agent and the at least one other agent.
1. A method for parallel malware scanning in a cloud environment, the method comprising:
identifying a plurality of agents connected to a server, wherein each agent of the plurality of agents is configured to synchronize data between a different computing device and the server;
receiving, from a first agent of the plurality of agents, a request to scan an up-to-date version of the synchronized data for malware;
receiving a status identifier from at least one other agent indicating that the at least one other agent has completed downloading or uploading the synchronized data;
in response to determining, from the plurality of agents, that the at least one other agent comprises the up-to-date version of the synchronized data based on the status identifier, partitioning the synchronized data into a plurality of portions;
assigning a first portion for scanning to the first agent and at least one other portion for scanning to the at least one other agent;
aggregating scan results from the first agent and the at least one other agent; and
transmitting the aggregated scan results to the plurality of agents.
2. The method of claim 1 , further comprising:
determining that the aggregated scan results indicate a presence of malware on the synchronized data;
removing the malware from the synchronized data; and
transmitting updated synchronized data to the plurality of agents, wherein the updated synchronized data does not have the malware.
3. The method of claim 1 , wherein identifying the plurality of agents comprises:
detecting requests from at least two agents to establish at least two push notification channels with the server, wherein each channel of the least two push notification channels is established by a respective agent of the at least two agents;
storing identifiers of the at least two push notification channels and the at least two agents; and
identifying the at least two agents as the plurality of agents.
4. The method of claim 1 , wherein determining the at least one other agent that comprises the up-to-date version of the synchronized data comprises:
determining a first plurality of checksums for files in the synchronized data on the server, wherein the server comprises the up-to-date version of the synchronized data;
determining a second plurality of checksums for the files in the synchronized data on the at least one other agent;
comparing the first plurality of checksums and the second plurality of checksums; and
in response to determining a match between the first plurality of checksums and the second plurality of checksums based on the comparing, determining that the at least one other agent comprises the up-to-date version of the synchronized data.
5. The method of claim 1 , wherein the at least one other agent comprises a second agent, and the at least one other portion comprises a second portion and a third portion, further comprising:
assigning the second portion for scanning to the second agent;
determining which of the first agent and the second agent completes scanning first;
in response to determining that the first agent has completed scanning first, assigning the third portion for scanning to the first agent.
6. The method of claim 1 , further comprising:
determining an estimated amount of time to complete scanning of the at least one other portion by the at least one other agent;
in response to determining that (1) an amount of time taken by the at least one other agent has exceeded the estimated amount and (2) the first agent has completed scanning the first portion:
halting scanning by the at least one other agent of the at least one other portion;
retrieving incomplete scan results from the at least one other agent; and
assigning, to the first agent, a first sub-portion of the at least one other portion that has not been scanned.
7. The method of claim 6 , further comprising:
assigning, to a second agent of the at least one other agent, a second sub-portion of the at least one other portion that has not been scanned.
8. A system for parallel malware scanning in a cloud environment, the system comprising:
a hardware processor configured to:
identify a plurality of agents connected to a server, wherein each agent of the plurality of agents is configured to synchronize data between a different computing device and the server;
receive, from a first agent of the plurality of agents, a request to scan an up-to-date version of the synchronized data for malware;
receive a status identifier from at least one other agent indicating that the at least one other agent has completed downloading or uploading the synchronized data;
in response to determining, from the plurality of agents, that the at least one other agent comprises the up-to-date version of the synchronized data based on the status identifier, partition the synchronized data into a plurality of portions;
assign a first portion for scanning to the first agent and at least one other portion for scanning to the at least one other agent;
aggregate scan results from the first agent and the at least one other agent; and
transmit the aggregated scan results to the plurality of agents.
9. The system of claim 8 , wherein the hardware processor is further configured to:
determine that the aggregated scan results indicate a presence of malware on the synchronized data;
remove the malware from the synchronized data; and
transmit updated synchronized data to the plurality of agents, wherein the updated synchronized data does not have the malware.
10. The system of claim 8 , wherein the hardware processor is further configured to identify the plurality of agents by:
detecting requests from at least two agents to establish at least two push notification channels with the server, wherein each channel of the least two push notification channels is established by a respective agent of the at least two agents;
storing identifiers of the at least two push notification channels and the at least two agents; and
identifying the at least two agents as the plurality of agents.
11. The system of claim 8 , wherein the hardware processor is further configured to determine the at least one other agent that comprises the up-to-date version of the synchronized data by:
determining a first plurality of checksums for files in the synchronized data on the server, wherein the server comprises the up-to-date version of the synchronized data;
determining a second plurality of checksums for the files in the synchronized data on the at least one other agent;
comparing the first plurality of checksums and the second plurality of checksums; and
in response to determining a match between the first plurality of checksums and the second plurality of checksums based on the comparing, determining that the at least one other agent comprises the up-to-date version of the synchronized data.
12. The system of claim 8 , wherein the at least one other agent comprises a second agent, and the at least one other portion comprises a second portion and a third portion, wherein the hardware processor is further configured to:
assign the second portion for scanning to the second agent;
determine which of the first agent and the second agent completes scanning first;
in response to determining that the first agent has completed scanning first, assign the third portion for scanning to the first agent.
13. The system of claim 8 , wherein the hardware processor is further configured to:
determine an estimated amount of time to complete scanning of the at least one other portion by the at least one other agent;
in response to determining that (1) an amount of time taken by the at least one other agent has exceeded the estimated amount and (2) the first agent has completed scanning the first portion:
halt scanning by the at least one other agent of the at least one other portion;
retrieve incomplete scan results from the at least one other agent; and
assign, to the first agent, a first sub-portion of the at least one other portion that has not been scanned.
14. The system of claim 13 , wherein the hardware processor is further configured to:
assign, to a second agent of the at least one other agent, a second sub-portion of the at least one other portion that has not been scanned.
15. A non-transitory computer readable medium storing thereon computer executable instructions for parallel malware scanning in a cloud environment, including instructions for:
identifying a plurality of agents connected to a server, wherein each agent of the plurality of agents is configured to synchronize data between a different computing device and the server;
receiving, from a first agent of the plurality of agents, a request to scan an up-to-date version of the synchronized data for malware;
receiving a status identifier from at least one other agent indicating that the at least one other agent has completed downloading or uploading the synchronized data;
in response to determining, from the plurality of agents, that the at least one other agent comprises the up-to-date version of the synchronized data based on the status identifier, partitioning the synchronized data into a plurality of portions;
assigning a first portion for scanning to the first agent and at least one other portion for scanning to the at least one other agent;
aggregating scan results from the first agent and the at least one other agent; and
transmitting the aggregated scan results to the plurality of agents.
16. The non-transitory computer readable medium of claim 15 , further comprising instructions for:
determining that the aggregated scan results indicate a presence of malware on the synchronized data;
removing the malware from the synchronized data; and
transmitting updated synchronized data to the plurality of agents, wherein the updated synchronized data does not have the malware.
17. The non-transitory computer readable medium of claim 15 , wherein an instruction for identifying the plurality of agents further comprises instructions for:
detecting requests from at least two agents to establish at least two push notification channels with the server, wherein each channel of the least two push notification channels is established by a respective agent of the at least two agents;
storing identifiers of the at least two push notification channels and the at least two agents; and
identifying the at least two agents as the plurality of agents.
18. The non-transitory computer readable medium of claim 15 , wherein an instruction for determining the at least one other agent that comprises the up-to-date version of the synchronized data further comprises instructions for:
determining a first plurality of checksums for files in the synchronized data on the server, wherein the server comprises the up-to-date version of the synchronized data;
determining a second plurality of checksums for the files in the synchronized data on the at least one other agent;
comparing the first plurality of checksums and the second plurality of checksums; and
in response to determining a match between the first plurality of checksums and the second plurality of checksums based on the comparing, determining that the at least one other agent comprises the up-to-date version of the synchronized data.