IP Library Granted Patent US 12,373,571
Granted Patent B2
US 12,373,571 · App. 17/901,309 · Granted Jul 29, 2025

Systems and methods for preventing the spread of malware in a synchronized data network

Inventors: Vladimir Strogov (Singapore, SG); Serg Bell (Singapore, SG); Stanislav Protasov (Singapore, SG)
Assignee: Acronis International GmbH
G06F21/577G06F2221/032G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,571
App. No.
17/901,309
Granted
Jul 29, 2025
Kind
B2
Abstract

Disclosed herein are systems and method for preventing the spread of malware in a synchronized data network, the method including: receiving, at a first time by a server connected to a plurality of computing devices, a file from a first computing device; monitoring for changes to the file stored on the server; in response to detecting a change, generating a record indicative of the change to the file; receiving, at the server from a second computing device, a download request for the file at a second time; determining whether at least one record exists that indicates any change to the file between the first time and the second time; in response to determining that the record exists, scanning the file for malware; and in response to determining that the file stored on the server is associated with malware, denying the download request.

Claims (65)

1. A method for preventing the spread of malware in a synchronized data network, the method comprising:

receiving, at a first time by a server connected to a plurality of computing devices, a file from a first computing device of the plurality of computing devices;

monitoring for changes to the file stored on the server;

in response to detecting a change, generating a record indicative of the change to the file, wherein the record is part of a distributed ledger that stores, in a plurality of records, changes made to files on the server;

receiving, from a second computing device of the plurality of computing devices, a download request to download the file from the server, wherein the download request is received at a second time subsequent to the first time, wherein only when download requests are received are latest changes and scan verdicts, exclusive to files synchronized across the plurality of computing devices, tracked and stored on the distributed ledger, and wherein each record of the plurality of records is verified by the plurality of computing devices;

determining whether at least one record exists in the distributed ledger that indicates any change to the file between the first time and the second time;

in response to determining that the record exists, scanning the file for malware;

in response to determining that the file stored on the server is associated with malware based on the distributed ledger, denying the download request;

in response to determining that the file is not associated with malware based on the distributed ledger, granting the download request and generating another record in the distributed ledger that includes results indicating that the file is not associated with malware;

receiving, from a third computing device, another download request to download the file from the server, wherein the another download request is received at a third time subsequent to the second time; and

in response to determining that the another record is a latest record for the file based on the distributed ledger, granting the another download request without performing another scan of the file.

2. The method of claim 1 , wherein receiving the file comprises:

detecting an upload request to upload the file from the first computing device;

requesting, from the first computing device, a scan verdict indicative of whether the file is associated with malware;

in response to receiving a scan verdict that the file is not associated with malware, granting the upload request and storing the file on the server at the first time.

3. The method of claim 1 , further comprising:

performing a remediation action comprising one or more of:

removing the file from the server,

placing the file in quarantine on the server, and

requesting, from the first computing device, a version of the file that is not associated with malware.

4. The method of claim 1 , further comprising:

in response to determining that the file stored on the server is not associated with malware, transmitting the file to the second computing device.

5. The method of 1 , further comprising:

transmitting the file to the third computing device.

6. A system for preventing the spread of malware in a synchronized data network, the system comprising:

a memory; and

a hardware processor communicatively coupled with the memory and configured to:

receive, at a first time by a server connected to a plurality of computing devices, a file from a first computing device of the plurality of computing devices;

monitor for changes to the file stored on the server;

in response to detecting a change, generate a record indicative of the change to the file, wherein the record is part of a distributed ledger that stores, in a plurality of records, changes made to files on the server;

receive, from a second computing device of the plurality of computing devices, a download request to download the file from the server, wherein the download request is received at a second time subsequent to the first time, wherein only when download requests are received are latest changes and scan verdicts, exclusive to files synchronized across the plurality of computing devices, tracked and stored on the distributed ledger, and wherein each record of the plurality of records is verified by the plurality of computing devices;

determine whether at least one record exists in the distributed ledger that indicates any change to the file between the first time and the second time;

in response to determining that the record exists, scan the file for malware;

in response to determining that the file stored on the server is associated with malware based on the distributed ledger, deny the download request;

in response to determining that the file is not associated with malware based on the distributed ledger, grant the download request and generating another record in the distributed ledger that includes results indicating that the file is not associated with malware;

receive, from a third computing device, another download request to download the file from the server, wherein the another download request is received at a third time subsequent to the second time; and

in response to determining that the another record is a latest record for the file based on the distributed ledger, grant the another download request without performing another scan of the file.

7. The system of claim 6 , wherein the hardware processor is configured to receive the file by:

detecting an upload request to upload the file from the first computing device;

requesting, from the first computing device, a scan verdict indicative of whether the file is associated with malware; and

in response to receiving a scan verdict that the file is not associated with malware, granting the upload request and storing the file on the server at the first time.

8. The system of claim 6 , wherein the hardware processor is further configured to:

perform a remediation action comprising one or more of:

removing the file from the server,

placing the file in quarantine on the server, and

requesting, from the first computing device, a version of the file that is not associated with malware.

9. The system of claim 6 , wherein the hardware processor is further configured to:

in response to determining that the file stored on the server is not associated with malware, transmit the file to the second computing device.

10. The system of claim 6 , wherein the hardware processor is further configured to:

transmit the file to the third computing device.

11. A non-transitory computer readable medium storing thereon computer executable instructions for preventing the spread of malware in a synchronized data network, including instructions for:

receiving, at a first time by a server connected to a plurality of computing devices, a file from a first computing device of the plurality of computing devices;

monitoring for changes to the file stored on the server;

in response to detecting a change, generating a record indicative of the change to the file, wherein the record is part of a distributed ledger that stores, in a plurality of records, changes made to files on the server;

receiving, from a second computing device of the plurality of computing devices, a download request to download the file from the server, wherein the download request is received at a second time subsequent to the first time, wherein only when download requests are received are latest changes and scan verdicts, exclusive to files synchronized across the plurality of computing devices, tracked and stored on the distributed ledger, and wherein each record of the plurality of records is verified by the plurality of computing devices;

determining whether at least one record exists in the distributed ledger that indicates any change to the file between the first time and the second time;

in response to determining that the record exists, scanning the file for malware;

in response to determining that the file stored on the server is associated with malware based on the distributed ledger, denying the download request;

in response to determining that the file is not associated with malware based on the distributed ledger, granting the download request and generating another record in the distributed ledger that includes results indicating that the file is not associated with malware;

receiving, from a third computing device, another download request to download the file from the server, wherein the another download request is received at a third time subsequent to the second time; and

in response to determining that the another record is a latest record for the file based on the distributed ledger, granting the another download request without performing another scan of the file.

12. The non-transitory computer readable medium of claim 11 , wherein an instruction for receiving the file further comprises instructions for:

detecting an upload request to upload the file from the first computing device;

requesting, from the first computing device, a scan verdict indicative of whether the file is associated with malware;

in response to receiving a scan verdict that the file is not associated with malware, granting the upload request and storing the file on the server at the first time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: STROGOV, VLADIMIR; BELL, SERG; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 071562/0837 →
Continuity (2)
Provisional Application 63292219 · Dec 21, 2021
Related Publication 20230195902A1 · Jun 22, 2023
References Cited (4)
US 11526609B1 · Elgaafary · 2022 [cited by examiner]
US 20070136810A1 · Waltermann · 2007 [cited by examiner]
US 20190238565A1 · Wang · 2019 [cited by examiner]
US 20210049277A1 · Mueller-Wicke · 2021 [cited by examiner]