IP Library Granted Patent US 7,203,959
Granted Patent B2
US 7,203,959 · App. 10/388,903 · Granted Apr 10, 2007

Stream scanning through network proxy servers

Assignee: Symantec Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,203,959
App. No.
10/388,903
Granted
Apr 10, 2007
Kind
B2
Abstract

Methods, systems, and computer readable media for managing transmission of a requested computer file ( 140 ) from a remote host compute ( 125 ) to a client computer ( 120 ). A proxy server computer ( 110 ) receives a first chunk ( 315 ) of the requested computer file ( 140 ). The proxy server ( 120 ) generates a hash of the chunk ( 315 ) and compares the hash to a hash of a chunk of previously downloaded file. If the two hashes are identical, the chunk ( 315 ) of the requested computer file ( 140 ) is passed to the client computer ( 120 ).

Claims (47)

1. A method for managing transmission of a requested computer file from a remote host to a client, the method comprising the steps of:

receiving a chunk of the requested computer file from the remote host;

generating a hash of the chunk of the requested computer file;

comparing the hash of the chunk of the requested computer file to a hash of a chunk of a previously downloaded computer file; and

transmitting the chunk of the requested file to the client when the hash of the chunk of the requested computer file is identical to the hash of the chunk of the previously downloaded computer file.

2. The method of claim 1 , further comprising the step of receiving a remainder of the requested computer file when the hash of the chunk of the requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

3. The method of claim 2 , further comprising the step of scanning the requested computer file for the presence of malicious code.

4. The method of claim 3 , further comprising the step of transmitting the requested computer file to the client when the requested computer file is found to be free of malicious code.

5. The method of claim 3 , further comprising the step of generating new hashes of chunks of the requested computer file when the requested computer file is free of malicious code.

6. The method of claim 3 , further comprising the steps of:

determining that the file contains malicious code;

removing the malicious code from the file; and

transmitting the file to the client.

7. The method of claim 6 , further comprising storing a repaired copy of the file in a cache.

8. The method of claim 7 , further comprising:

downloading a chunk of a second requested computer file;

generating a hash of the chunk of the second requested computer file;

comparing the hash of the chunk of the second requested computer file to a hash of a chunk of the previously downloaded computer file; and

transmitting the repaired copy of the file to the client when the hash of the chunk of the second requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

9. The method of claim 1 , further comprising the step of ending a transmission of the requested computer file to the client when the hash of the chunk of the requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

10. The method of claim 1 , wherein the step of comparing the hash of the chunk of the requested computer file to a hash of a chunk of a previously downloaded computer file comprises the sub-steps of:

checking a cache for a hash of a chunk of a computer file corresponding to the requested computer file; and

determining that the hash of the chunk of the requested computer file is not identical to a hash of a chunk of a previously downloaded computer file when the cache does not contain a hash of a chunk of a computer file corresponding to the requested computer file.

11. A system for managing transmission of a requested computer file from a remote host to a client, the system comprising:

a selection module configured to:

receive a chunk of the requested computer file from the remote host;

compare a hash of the chunk of the requested computer file to a hash of a chunk of a previously downloaded computer file; and

transmit the chunk of the requested file to the client when the hash of the chunk of the requested computer file is identical to the hash of the chunk of the previously downloaded computer file; and

a hash generator, coupled to the selection module, and configured to generate a hash of the chunk of the requested computer file.

12. The system of claim 11 , wherein the selection module is further configured to receive a remainder of the requested computer file when the hash of the chunk of the requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

13. The system of claim 12 , further comprising a scanning module, coupled to the selection module, and configured to scan the requested computer file for the presence of malicious code.

14. The system of claim 13 , wherein the selection module is further configured to transmit the requested computer file to the client when the requested computer file is found by the scanning module to be free of malicious code.

15. The system of claim 13 , wherein the hash generator is further configured to generate new hashes of chunks of the requested computer file when the scanning module has scanned the requested computer file and the requested computer file is found by the scanning module to be free of malicious code.

16. The system of claim 11 , wherein the selection module is further configured to end a transmission of the requested computer file when the hash of the chunk of the requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

17. A computer-readable medium containing computer code instructions for managing transmission of a requested computer file from a remote host to a client, the computer code comprising instructions for:

receiving a chunk of the requested computer file from the remote host;

generating a hash of the chunk of the requested computer file;

comparing the hash of the chunk of the requested computer file to a hash of a chunk of a previously downloaded computer file; and

transmitting the chunk of the requested file to the client when the hash of the chunk of the requested computer file is identical to the hash of the chunk of the previously downloaded computer file.

18. The computer readable medium of claim 17 , wherein the instructions for managing transmission of a requested computer file from a remote host to a client further comprise instructions for receiving a remainder of the requested computer file when the hash of the chunk of the requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

19. The computer readable medium of claim 18 , wherein the instructions for managing transmission of a requested computer file from a remote host to a client further comprise instructions for scanning the requested computer file for the presence of malicious code.

20. The computer readable medium of claim 19 , wherein the instructions for managing transmission of a requested computer file from a remote host to a client further comprise instructions for transmitting the requested computer file to the client when the requested computer file is found to be free of malicious code.

21. The computer readable medium of claim 20 , wherein the instructions for managing transmission of a requested computer file from a remote host to a client further comprise instructions for generating new hashes of chunks of the requested computer file when the requested computer file is found to be free of malicious code.

22. The computer readable medium of claim 17 , wherein the instructions for managing transmission of a requested computer file from a remote host to a client further comprise instructions for ending a transmission of the requested computer file to the client when the hash of the chunk of the requested computer file is not identical to the hash of the chunk of the previously downloaded computer file.

23. The computer readable medium of claim 17 , wherein the instructions for comparing the hash of the chunk of the requested computer file to a hash of a chunk of a previously downloaded computer file comprises instructions for:

checking a cache for a hash of a chunk of a computer file corresponding to the requested computer file; and

determining that the hash of the chunk of the requested computer file is not identical to a hash of a chunk of a previously downloaded computer file when the cache does not contain a hash of a chunk of a computer file corresponding to the requested computer file.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2003
From: NACHENBERG, CAREY S.; GUN, ELIAS
To: SYMANTEC CORPORATION
Reel/Frame 013885/0946 →
Continuity (1)
Related Publication 20040181687A1 · Sep 16, 2004