IP Library Granted Patent US 10,452,853
Granted Patent B2
US 10,452,853 · App. 15/926,878 · Granted Oct 22, 2019

Disarming malware in digitally signed content

Inventor: Aviv Grafi (Ramat Gan, IL)
Assignee: VOTIRO CYBERSEC LTD.
G06F21/577G06F21/10G06F21/316G06F21/53G06F21/55G06F21/564H04L9/006H04L9/14H04L9/30H04L9/3226H04L9/3247H04L63/145H04L63/1425H05K999/99H04L63/0236H04L63/1416H04L63/1466H04L63/308
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,853
App. No.
15/926,878
Granted
Oct 22, 2019
Kind
B2
Abstract

Systems and methods for disarming malicious code in digitally-signed content are provided. An example method includes determining that content is associated with a first digital signature, modifying at least a portion of digital values of the content to disable any malicious code included in the content, thereby creating modified content, and signing the modified content with a second digital signature, thereby creating signed modified content, the signed modified content including a data element corresponding to the first digital signature.

Claims (34)

1. A system for disarming malicious code in digitally-signed content, the system comprising:

means for determining that content is associated with a first digital signature;

means for creating modified content by modifying at least a portion of digital values of the content to disable any malicious code included in the content; and

means for signing the modified content with a second digital signature, thereby creating signed modified content, the signed modified content including a data element corresponding to the first digital signature.

2. The system of claim 1 , further comprising enabling access to the modified content by an intended recipient.

3. The system of claim 1 , further comprising means for verifying authenticity of the first digital signature.

4. The system of claim 3 , further comprising means for receiving an indication from a trusted third party indicative of the authenticity of the first digital signature.

5. The system of claim 3 , further comprising means for approving the first digital signature based on a policy.

6. The system of claim 5 , wherein the policy enables approval of the first digital signature based on a characteristic of a certificate associated with the first digital signature.

7. The system of claim 3 , further comprising means for receiving an indication from an administrator indicating approval of the digital signature.

8. The system of claim 2 , further comprising means for providing a notification to the intended recipient that the first digital signature of the content has been verified.

9. The system of claim 8 , wherein the notification is included in content of the modified content.

10. The system of claim 8 , wherein the notification is included in a communication associated with the modified content.

11. The system of claim 10 , wherein the communication is an electronic message including the modified content attached thereto.

12. The system of claim 2 , wherein the second digital signature is associated with a security gateway in the network.

13. The system of claim 2 , further comprising:

means for storing the content in association with the first digital signature in a dedicated storage area; and

means for enabling access to the content by the intended recipient according to a policy.

14. A method for disarming malicious code in a computer system having a processor, the method comprising:

determining that input content associated with a recipient in a network is signed with a first digital signature;

verify authenticity of the first digital signature;

generating modified input content by modifying at least a portion of digital values of the input content to disable any malicious code included in the input content; and

signing the modified input content with a second digital signature, the signed modified input content including one or more elements indicative of the authenticity of the first digital signature.

15. The method of claim 14 , wherein the generating is performed without first detecting malicious code in the input content.

16. The method of claim 14 , further comprising:

storing the input content in association with the first digital signature in a dedicated storage area of the computer system; and

enabling access to the input content by the recipient according to a policy of the computer system.

17. The method of claim 14 , further comprising inserting the one or more content elements into the modified input content.

18. The method of claim 14 , further comprising inserting the one or more content elements into the second digital signature.

19. A non-transitory computer-readable medium comprising instructions that when executed by a processor are configured for carrying out the method of claim 14 .

20. A non-transitory computer-readable medium comprising instructions that when executed by a processor cause the processor to:

determine that content is associated with a first digital signature;

create modified content by modifying at least a portion of digital values of the content to disable any malicious code included in the content; and

sign the modified content with a second digital signature, thereby creating signed modified content, the signed modified content including a data element corresponding to the first digital signature.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2018
From: GRAFI, AVIV
To: VOTIRO CYBERSEC LTD.
Reel/Frame 045293/0835 →
Continuity (5)
Continuation 15795021 · Oct 26, 2017
Provisional Application 62473902 · Mar 20, 2017
Provisional Application 62450605 · Jan 26, 2017
Provisional Application 62442452 · Jan 5, 2017
Related Publication 20180276390A1 · Sep 27, 2018
Cited By (7)
US 12,197,398 US 12,242,455 US 12,248,434 US 12,248,435 US 12,367,108 US 12,517,874 US 12,627,681