IP Library Granted Patent US 12,712,888
Granted Patent B2
US 12,712,888 · App. 18/887,786 · Granted Aug 18, 2026

Reassembly free deep packet inspection for peer to peer networks

Inventors: Hui Ling (Shanghai, CN); Cuiping Yu (Shanghai, CN); Zhong Chen (Fremont, CA)
Assignee: SONICWALL US HOLDINGS INC.
H04L63/1408H04L63/0254H04L63/168H04L63/0245H04L63/1416H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,888
App. No.
18/887,786
Filed
Sep 17, 2024
Granted
Aug 18, 2026
Kind
B2
Art Unit
2408
USPC
726/23
Abstract

The present disclosure relates to a system, a method, and a non-transitory computer readable storage medium for deep packet inspection scanning at an application layer of a computer. A method of the presently claimed invention may scan pieces of data received out of order without reassembly at an application layer from a first input state generating one or more output states for each piece of data. The method may then identify that the first input state includes one or more characters that are associated with malicious content. The method may then identify that the data set may include malicious content when the first input state combined with one or more output states matches a known piece of malicious content.

Claims (39)

1 . A method for scanning computer data, the method comprising:

scanning a first out-of-order block of a dataset at an application layer in a peer-to-peer network, wherein the first out-of-order block is scanned for one or more sets of malware;

generating an output state based on the scan of the first out-of-order block;

performing one or more subsequent scans of other blocks of the dataset including a second out-of-order block that precedes the first out-of-order block;

generating output states for each of the subsequent scans;

storing in memory the output states for the first out-of-order block and the output states for the other blocks, wherein the output states are correlated to identified input states, wherein the output state for the first out-of-order block reduces a number of the identified input states used when scanning the second out-of-order block; and

identifying that the dataset includes a set of malware when the output states for the first out-of-order block and the output states for the other blocks match a pattern associated with the identified set of malware.

2 . The method of claim 1 , further comprising eliminating one or more of the sets of malware in accordance with the output state limiting one or more possible input states.

3 . The method of claim 1 , wherein scanning the first out-of-order block is based on an input state associated with the identified set of malware.

4 . The method of claim 3 , wherein the input state associated with the identified set of malware corresponds to an identified input set of an empty string.

5 . The method of claim 3 , wherein the input state indicates that one or more characters in a sequence of characters match the identified set of malware.

6 . The method of claim 1 , wherein the generated output state requires a subsequent portion to end with one or more characters of a string associated with the identified set of malware.

7 . The method of claim 1 , further comprising storing a state mapping in memory that identifies a plurality of states associated with each of the sets of malware.

8 . The method of claim 1 , wherein the output state based on the scan of the first out-of-order block reduces a number of identified input states for the second out-of-order block.

9 . The method of claim 8 , wherein the output state further reduces an amount of the memory used to identify the identified set of malware.

10 . The method of claim 1 , wherein the first out-of-order block is received from a first peer computer of a plurality of peer computers and the second out-of-order block is received from a second peer computer of the plurality of peer computers.

11 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor to implement a method for scanning computer data, the method comprising:

scanning a first out-of-order block of a dataset at an application layer in a peer-to-peer network, wherein the first out-of-order block is scanned for one or more sets of malware;

generating an output state based on the scan of the first out-of-order block;

performing one or more subsequent scans of other blocks of the dataset including a second out-of-order block that precedes the first out-of-order block;

generating output states for each of the subsequent scans;

storing in memory the output states for the first out-of-order block and the output states for the other blocks, wherein the output states are correlated to identified input states, wherein the output state for the first out-of-order block reduces a number of the identified input states used when scanning the second out-of-order block; and

identifying that the dataset includes a set of malware when the output states for the first out-of-order block and the output states for the other blocks match a pattern associated with the identified set of malware.

12 . The non-transitory computer-readable storage medium of claim 11 , further comprising instructions executable to eliminate one or more of the sets of malware in accordance with the output state limiting one or more possible input states.

13 . The non-transitory computer-readable storage medium of claim 11 , wherein scanning the first out-of-order block is based on an input state associated with the identified set of malware.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the input state associated with the identified set of malware corresponds to an identified input set of an empty string.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein the input state indicates that one or more characters in a sequence of characters match the identified set of malware.

16 . The non-transitory computer-readable storage medium of claim 11 , wherein the generated output state requires a subsequent portion to end with one or more characters of a string associated with the identified set of malware.

17 . The non-transitory computer-readable storage medium of claim 11 , further comprising instructions executable to store a state mapping in memory that identifies a plurality of states associated with each of the sets of malware.

18 . The non-transitory computer-readable storage medium of claim 11 , wherein the output state based on the scan of the first out-of-order block reduces a number of identified input states for the second out-of-order block.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein the output state further reduces an amount of the memory used to identify the identified set of malware.

20 . A system for scanning computer data, the system comprising:

a communication interface that communicates over a communication network with one or more computers in a peer-to-peer network, wherein the communication interface receives a plurality of blocks of a dataset;

a processor that executes instructions stored in memory, wherein the processor executes the instructions to:

scan a first out-of-order block of the dataset at an application layer in the peer-to-peer network, wherein the first out-of-order block is scanned for one or more sets of malware,

generate an output state based on the scan of the first out-of-order block,

perform one or more subsequent scans of other blocks of the dataset including a second out-of-order block that precedes the first out-of-order block, and

generate output states for each of the subsequent scans; and

memory that stores the output states for the first out-of-order block and the output states for the other blocks, wherein the output states are correlated to identified input states, wherein the output state for the first out-of-order block reduces a number of the identified input states used when scanning the second out-of-order block, wherein the processor identifies that the dataset includes a set of malware when the output states for the first out-of-order block and the output states for the other blocks match a pattern associated with the identified set of malware.

Assignments (4)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2024
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 069180/0472 →
CHANGE OF NAME Recorded Oct 17, 2024
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 069180/0579 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2024
From: LING, HUI; YU, CUIPING; CHEN, ZHONG
To: DELL SOFTWARE INC.
Reel/Frame 068924/0282 →
Continuity (6)
Continuation 18215669 · Jun 28, 2023
Continuation 17174182 · Feb 11, 2021
Continuation 16853360 · Apr 20, 2020
Continuation 15860623 · Jan 2, 2018
Continuation 14965866 · Dec 10, 2015
Related Publication 20250016178A1 · Jan 9, 2025
References Cited (112)
US 6961783B1 · Cook et al. · 2005 [cited by applicant]
US 7206765B2 · Gilliam et al. · 2007 [cited by applicant]
US 7849502B1 · Bloch et al. · 2010 [cited by applicant]
US 7849507B1 · Bloch et al. · 2010 [cited by applicant]
US 7984149B1 · Grayson · 2011 [cited by applicant]
US 8316446B1 · Campbell et al. · 2012 [cited by applicant]
US 8320372B2 · Menten · 2012 [cited by applicant]
US 8352998B1 · Kougiouris et al. · 2013 [cited by applicant]
US 8578489B1 · Dubrovsky et al. · 2013 [cited by applicant]
US 8782771B2 · Chen et al. · 2014 [cited by applicant]
US 8813221B1 · Dubrovsky et al. · 2014 [cited by applicant]
US 8826443B1 · Raman et al. · 2014 [cited by applicant]
US 8850567B1 · Hsieh et al. · 2014 [cited by applicant]
US 8856869B1 · Brinskelle · 2014 [cited by applicant]
US 9031937B2 · Guha · 2015 [cited by applicant]
US 9350750B1 · Aval et al. · 2016 [cited by applicant]
US 9438699B1 · Shetty et al. · 2016 [cited by applicant]
US 9557889B2 · Raleigh et al. · 2017 [cited by applicant]
US 9723027B2 · Vazquez Carames · 2017 [cited by applicant]
US 9860259B2 · Ling et al. · 2018 [cited by applicant]
US 9923870B2 · Dusi et al. · 2018 [cited by applicant]
US 10277610B2 · Dubrovsky et al. · 2019 [cited by applicant]
US 10491566B2 · Carames · 2019 [cited by applicant]
US 10630697B2 · Ling et al. · 2020 [cited by applicant]
US 11005858B2 · Ling et al. · 2021 [cited by applicant]
US 11695784B2 · Ling et al. · 2023 [cited by applicant]
US 12095779B2 · Ling et al. · 2024 [cited by applicant]
US 20040179477A1 · Lincoln · 2004 [cited by applicant]
US 20050108518A1 · Pandya · 2005 [cited by applicant]
US 20050286526A1 · Sood · 2005 [cited by examiner]
US 20060233101A1 · Luft et al. · 2006 [cited by applicant]
US 20070041402A1 · Sekaran et al. · 2007 [cited by applicant]
US 20070064702A1 · Bates et al. · 2007 [cited by applicant]
US 20070192861A1 · Varghese et al. · 2007 [cited by applicant]
US 20070226362A1 · Johnson · 2007 [cited by examiner]
US 20080062879A1 · Sivakumar · 2008 [cited by examiner]
US 20080127349A1 · Ormazabal et al. · 2008 [cited by applicant]
US 20080141358A1 · Lin · 2008 [cited by examiner]
US 20080219169A1 · Sargor et al. · 2008 [cited by applicant]
US 20080235755A1 · Blaisdell et al. · 2008 [cited by applicant]
US 20080262991A1 · Kapoor et al. · 2008 [cited by applicant]
US 20080320582A1 · Chen et al. · 2008 [cited by applicant]
US 20090164560A1 · Fiatal · 2009 [cited by applicant]
US 20090260087A1 · Ishida et al. · 2009 [cited by applicant]
US 20090316698A1 · Menten · 2009 [cited by applicant]
US 20100005118A1 · Sezer · 2010 [cited by applicant]
US 20100027565A1 · Gupta · 2010 [cited by examiner]
US 20100172257A1 · Yu · 2010 [cited by applicant]
US 20110013527A1 · Varadarajan et al. · 2011 [cited by applicant]
US 20110035469A1 · Smith et al. · 2011 [cited by applicant]
US 20110125748A1 · Wood et al. · 2011 [cited by applicant]
US 20110153802A1 · Steiner et al. · 2011 [cited by applicant]
US 20110211586A1 · Zhu · 2011 [cited by applicant]
US 20110219426A1 · Kim et al. · 2011 [cited by applicant]
US 20110231924A1 · Devdhar et al. · 2011 [cited by applicant]
US 20120144061A1 · Song · 2012 [cited by applicant]
US 20120167150A1 · Le Scouarnec · 2012 [cited by examiner]
US 20120230200A1 · Wentink · 2012 [cited by applicant]
US 20120240185A1 · Kapoor et al. · 2012 [cited by applicant]
US 20120291087A1 · Agrawal · 2012 [cited by applicant]
US 20120324099A1 · Perez Martinez et al. · 2012 [cited by applicant]
US 20130074177A1 · Varadhan et al. · 2013 [cited by applicant]
US 20130128742A1 · Yu · 2013 [cited by applicant]
US 20130167192A1 · Hickman et al. · 2013 [cited by applicant]
US 20130286860A1 · Dorenbosch et al. · 2013 [cited by applicant]
US 20130291107A1 · Marck et al. · 2013 [cited by applicant]
US 20140053239A1 · Narayanswamy · 2014 [cited by applicant]
US 20140157405A1 · Joll · 2014 [cited by examiner]
US 20140181972A1 · Karta et al. · 2014 [cited by applicant]
US 20140258456A1 · Lee et al. · 2014 [cited by applicant]
US 20140304766A1 · Livne · 2014 [cited by applicant]
US 20140359764A1 · Dubrovsky et al. · 2014 [cited by applicant]
US 20150058488A1 · Backholm · 2015 [cited by applicant]
US 20150058916A1 · Rostami-Hesarsorkh et al. · 2015 [cited by applicant]
US 20150088897A1 · Sherman et al. · 2015 [cited by applicant]
US 20150278798A1 · Lerch et al. · 2015 [cited by applicant]
US 20150312220A1 · Crawford · 2015 [cited by applicant]
US 20150326613A1 · Devarajan et al. · 2015 [cited by applicant]
US 20150350231A1 · Dubrovsky · 2015 [cited by examiner]
US 20150373167A1 · Murashov et al. · 2015 [cited by applicant]
US 20160036833A1 · Ardeli et al. · 2016 [cited by applicant]
US 20160056927A1 · Liu et al. · 2016 [cited by applicant]
US 20160057185A1 · Zhang · 2016 [cited by applicant]
US 20160119198A1 · Kfir et al. · 2016 [cited by applicant]
US 20160127305A1 · Droms et al. · 2016 [cited by applicant]
US 20160164825A1 · Riedel et al. · 2016 [cited by applicant]
US 20160182537A1 · Tatourian et al. · 2016 [cited by applicant]
US 20160205072A1 · Dusi et al. · 2016 [cited by applicant]
US 20170048260A1 · Peddemors et al. · 2017 [cited by applicant]
US 20170099310A1 · Di Pietro et al. · 2017 [cited by applicant]
US 20170134428A1 · Vazquez Carames · 2017 [cited by applicant]
US 20170171222A1 · Ling et al. · 2017 [cited by applicant]
US 20170302628A1 · Vazquez Carames · 2017 [cited by applicant]
US 20180198804A1 · Ling et al. · 2018 [cited by applicant]
US 20180270197A1 · Subramanian · 2018 [cited by examiner]
US 20200213278A1 · Vazquez Carames · 2020 [cited by applicant]
US 20200351280A1 · Ling et al. · 2020 [cited by applicant]
US 20210234873A1 · Ling et al. · 2021 [cited by applicant]
US 20230336570A1 · Ling et al. · 2023 [cited by applicant]
EP 2901391 · 2018 [cited by applicant]
WO WO2006052714 · 2006 [cited by applicant]
DoU.S. Appl. No. 14/965,866 Office Action May 18, 2017. [cited by applicant]
U.S. Appl. No. 15/860,623 Office Action Jun. 13, 2019. [cited by applicant]
U.S. Appl. No. 15/860,623 Final Office Action Nov. 27, 2018. [cited by applicant]
U.S. Appl. No. 15/860,623 Office Action May 3, 2018. [cited by applicant]
U.S. Appl. No. 17/174,182 Office Action Aug. 15, 2022. [cited by applicant]
U.S. Appl. No. 18/215,669 Office Action Feb. 1, 2024. [cited by applicant]
U.S. Appl. No. 15/636,148 Office Action Feb. 19, 2019. [cited by applicant]
U.S. Appl. No. 15/636,148 Final Office Action Jul. 26, 2018. [cited by applicant]
U.S. Appl. No. 15/636,148 Office Action Feb. 22, 2018. [cited by applicant]
U.S. Appl. No. 16/697,082 Final Office Action Jan. 19, 2021. [cited by applicant]
U.S. Appl. No. 16/697,082 Office Action Oct. 6, 2020. [cited by applicant]