IP Library Granted Patent US 11,762,995
Granted Patent B2
US 11,762,995 · App. 17/327,850 · Granted Sep 19, 2023

Antivirus scanning architecture for uploaded files

Inventors: Darwin Ttito Concha (Walldorf, DE); Mark Waldaukat (Walldorf, DE); Rodrigo Augusto Scheller Boos (Blumenau, BR); Edison Kleiber Ttito Concha (Walldorf, DE)
Assignee: SAP SE
G06F21/565G06F21/53G06F21/54G06F21/554H04L67/06H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,762,995
App. No.
17/327,850
Granted
Sep 19, 2023
Kind
B2
Abstract

Provided is a system and method which perform an antivirus scan of incoming files via a file management application of a file system. Infected files can be prevented from being stored to the file system. In one example, the method may include receiving, via a first application contained in a first data container, a data file that is uploaded for storage to a file system, storing the data file in a temporary storage, transmitting a location of the data file in the temporary storage to a second application contained in a second data container, and receiving, via the first application contained in the first data container, a response from the second application contained in the second container, indicating results of a security scan performed on the data file.

Claims (34)

1. A computing system comprising:

a temporary storage; and

a hardware processor configured to:

receive, via a first application contained in a first data container, a data file that is uploaded for storage to a file system,

store the data file in the temporary storage,

establish a channel between a socket of the first data container and a socket of a second data container that is co-located in a shared pod of a container runtime of the first data container,

transmit, via the first application contained in the first data container, a location of the data file in the temporary storage to a second application contained in the second data container, wherein the first application transmits the location of the data file in the temporary storage to the socket of the second data container via the established channel, and

receive, via the first application contained in the first data container, a response from the second application contained in the second container which includes results of a security scan performed on the data file via the established channel.

2. The computing system of claim 1 , wherein the hardware processor is further configured to detect, via the first application contained in the first data container, that the data file is a zipped data file and unzip the zipped data file, prior to storing the data file in the temporary storage.

3. The computing system of claim 1 , wherein the hardware processor is further configured to retrieve, via the first application contained in the first data container, a file path of the data file from the temporary storage and transmit the file path of the data file to the second application included in the second data container.

4. The computing system of claim 1 , wherein the hardware processor is further configured to determine, via the first application contained in the first container, that the file has a security issue based on the response from the second application, log the security issue via a data log, and return an error notification to an application that uploaded the data file.

5. The computing system of claim 1 , wherein the hardware processor is further configured to determine, via the first application contained in the first container, that the file has no security issues based on the response from the second application and upload the file to the file system.

6. The computing system of claim 1 , wherein the temporary storage comprises a persistent volume (PV) that is shared among the first and second data containers within the shared pod.

7. The computing system of claim 1 , wherein the first application contained in the first container comprises a management application for the file storage and the second application contained in the second container comprises an anti-virus scanning application.

8. A method comprising:

receiving, via a first application contained in a first data container, a data file that is uploaded for storage to a file system;

storing the data file in a temporary storage;

establishing a channel between a socket of the first data container and a socket of a second data container that is co-located in a shared pod of a container runtime of the first data container;

transmitting, via the first application contained in the first data container, a location of the data file in the temporary storage to a second application contained in the second data container, wherein the transmitting comprises transmitting the location of the data file in the temporary storage to the socket of the second data container via the established channel; and

receiving, via the first application contained in the first data container, a response from the second application contained in the second container, indicating results of a security scan performed on the data file via the established channel.

9. The method of claim 8 , wherein the method further comprises detecting, via the first application contained in the first data container, that the data file is a zipped data file and unzipping the zipped data file before storing the data file in the temporary storage.

10. The method of claim 8 , wherein the transmitting further comprises retrieving, via the first application contained in the first data container, a file path of the data file from the temporary storage, and transmitting the file path of the data file to the second application included in the second data container.

11. The method of claim 8 , wherein the method further comprises determining, via the first application contained in the first container, that the file has a security issue based on the response from the second application, logging the security issue via a data log, and returning an error notification to an application that uploaded the data file.

12. The method of claim 8 , wherein the method further comprises determining, via the first application contained in the first container, that the file has no security issues based on the response from the second application, and uploading the file to the file system.

13. The method of claim 8 , wherein the temporary storage comprises a persistent volume (PV) that is shared among the first and second data containers within the shared pod.

14. The method of claim 8 , wherein the first application contained in the first container comprises a management application for the file storage and the second application contained in the second container comprises an anti-virus scanning application.

15. A non-transitory computer-readable storage medium comprising instructions which when executed by a processor cause a computer to perform a method comprising:

receiving, via a first application contained in a first data container, a data file that is uploaded for storage to a file system;

storing the data file in a temporary storage;

establishing a channel between a socket of the first data container and a socket of a second data container that is co-located in a shared pod of a container runtime of the first data container;

transmitting, via the first application contained in the first data container, a location of the data file in the temporary storage to a second application contained in the second data container, wherein the transmitting comprises transmitting the location of the data file in the temporary storage to the socket of the second data container via the established channel; and

receiving, via the first application contained in the first data container, a response from the second application contained in the second container, indicating results of a security scan performed on the data file via the established channel.

16. The non-transitory computer-readable medium of claim 15 , wherein the method further comprises detecting, via the first application contained in the first data container, that the data file is a zipped data file and unzipping the zipped data file before storing the data file in the temporary storage.

17. The non-transitory computer-readable medium of claim 15 , wherein the transmitting further comprises retrieving, via the first application contained in the first data container, a file path of the data file from the temporary storage, and transmitting the file path of the data file to the second application included in the second data container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2021
From: CONCHA, DARWIN TTITO; WALDAUKAT, MARK; BOOS, RODRIGO AUGUSTO SCHELLER; CONCHA, EDISON KLEIBER TTITO
To: SAP SE
Reel/Frame 056324/0398 →
Continuity (1)
Related Publication 20220374517A1 · Nov 24, 2022
Cited By (1)
US 12,619,831