IP Library Granted Patent US 12,547,708
Granted Patent B2
US 12,547,708 · App. 18/444,942 · Granted Feb 10, 2026

Known-deployed file metadata repository and analysis engine

Inventors: Dan E. Summers (Buckley, GB); Jeffrey Texada (Carrollton, TX); Matthew E. Kelly (Chicago, IL); Steven Dimaria (Charlotte, NC)
Assignee: Bank of America Corporation
G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,708
App. No.
18/444,942
Granted
Feb 10, 2026
Kind
B2
Abstract

A known-deployed file metadata repository (KDFMR) and analysis engine enumerates reference lists of files stored on a software delivery point (SDP) and compares the enumerated list of files and associated metadata to previously stored values in the KDFMR. If newly stored or modified files are identified, the analysis engine acquires the files from the SDP. Each file is analyzed to determine whether the file is an atomic file or a container file and metadata is generated or extracted. Each file stored in a container file is recursively extracted and analyzed, where metadata is generated for each extracted file and each container file. The KDFMR periodically analyzes the files stored on the SDP for differences to maintain the currency of the KDFMR data with respect to files stored on the SDP. Storage or modification of files on the SDP triggers analysis of the associated file. KDFMR data is updated with metadata determined based on sandbox detonation of files and/or identified artifacts of known-deployed files.

Claims (48)

1 . A system comprising:

a software distribution point (SDP) computing system storing files for distribution to computing devices on an enterprise network; and

a computing device comprising:

a processor; and

non-transitory memory storing instructions that, when executed by the processor, causes the computing device to:

enumerate available files stored on the SDP computing system;

retrieve, from the SDP computing system via a network, one or more new files based on a comparison of enumerated files to logical paths associated with the SDP computing system;

extract metadata from each of the one or more new files, wherein the metadata is recursively extracted from two or more stored files in a container file;

identify a match of metadata of a file of the one or more new files and metadata stored in a data store comprising information stored of “known-good” files;

update the matched metadata with an indication that the file is “known- deployed” to positively confirm that events associated with the one or more new files are related to deployment activity by the SDP, wherein the indication comprises artifact metadata only available during dynamic execution of a particular entry of an artifact by a known deployed file metadata analysis engine, and wherein the artifact metadata comprises an indication of the SDP computing system and an indication that the file was introduced to a host through methods associated with approved software distribution practices, and wherein artifact file metadata is enriched with labels to identify a functionality associated with the artifact, and wherein the artifact metadata associated with the SDP only available during dynamic execution of a particular entry of the artifact by the known deployed file metadata analysis engine comprises information that is variable based on a user associated with detonation of the one or more files; and

trigger, based on enrichment of the matched metadata, deployment of one or more files by the SDP, wherein the one or more files are associated with metadata indicating the file has a “known-deployed” identifier.

2 . The system of claim 1 , wherein the instructions further cause the computing device to:

calculate a first cryptographic hash of a topmost container of the container file and a second cryptographic hash of an immediate second container adjacent the topmost container; and

halt recursive file extraction and metadata generation for the container file based on an indication of a match between the first cryptographic hash or the second cryptographic hash to metadata stored in the data store.

3 . The system of claim 1 , wherein the instructions further cause the computing device to schedule analysis of the files stored on the SDP on a periodic basis.

4 . The system of claim 1 , wherein the instructions further cause the computing device to trigger analysis of the files stored on the SDP based on an indication that a modified file has been saved.

5 . The system of claim 1 , wherein the instructions further cause the computing device to trigger analysis of the files stored on the SDP based on an indication that a new file has been saved.

6 . The system of claim 5 , wherein the instructions further cause the computing device to trigger analysis of the new file based on the indication that the new file has been saved.

7 . The system of claim 1 , wherein the instructions further cause the computing device to enrich the file metadata stored in the data store with semantic labels to identify whether a file is known to be used for adversary purposes.

8 . The system of claim 1 , wherein the instructions further cause the computing device to enrich the file metadata stored in the data store with semantic labels to identify whether a file serves a specific purpose within an enterprise computing environment corresponding to one of a release purpose or a development purpose.

9 . A method comprising:

enumerating, by a known deployed file metadata analysis engine, files stored on a software distribution point (SDP) computing system;

retrieving, by the known deployed file metadata analysis engine from the SDP computing system via a network, one or more new files based on a comparison of enumerated files to logical paths associated with the SDP computing system;

extracting, by the known deployed file metadata analysis engine, metadata from each of the one or more new files, wherein the metadata is recursively extracted from two or more stored files in a container file;

identifying, by the known deployed file metadata analysis engine, a match of metadata of the one or more new files and metadata stored in a data store comprising information stored of “known-good” files;

updating, by the known deployed file metadata analysis engine, the matched metadata with an indication that the one or more new files is “known-deployed” to positively confirm deployment activity by the SDP, wherein the indication comprises artifact metadata associated with the SDP only available during dynamic execution of a particular entry of an artifact by the known deployed file metadata analysis engine and methods associated with approved software distribution practices, and wherein artifact file metadata is enriched with labels to identify a functionality associated with the artifact, and wherein the artifact metadata associated with the SDP only available during dynamic execution of a particular entry of the artifact by the known deployed file metadata analysis engine comprises information that is variable based on a host endpoint upon which the artifact is deployed; and

triggering, by the known deployed file metadata analysis engine and based on enrichment of the matched metadata, deployment of one or more files by the SDP.

10 . The method of claim 9 , further comprising recursively extracting metadata from each file stored in a container file of the one or more new files by:

calculating a first cryptographic hash of a topmost container of the container file and a second cryptographic hash of an immediate second container adjacent the topmost container; and

halting, by the known deployed file metadata analysis engine, recursive file extraction and metadata generation for the container file based on an indication of a match between the first cryptographic hash or the second cryptographic hash to metadata stored in the data store.

11 . The method of claim 9 , comprising scheduling, by the known deployed file metadata analysis engine, analysis of the files stored on the SDP on a periodic basis.

12 . The method of claim 9 , comprising triggering, by the known deployed file metadata analysis engine, analysis of the files stored on the SDP based on an indication that a modified file has been saved.

13 . The method of claim 9 , comprising triggering, by the known deployed file metadata analysis engine, analysis of the files stored on the SDP based on an indication that a new file has been saved.

14 . The method of claim 13 , comprising triggering analysis of the new file based on the indication that the new file has been saved.

15 . The method of claim 9 , comprising enriching the file metadata stored in the data store with semantic labels to identify whether a file is known to be used for adversary purposes.

16 . The method of claim 9 , comprising enriching the file metadata stored in the data store with semantic labels to identify whether a file serves a specific purpose within an enterprise computing environment, wherein the specific purpose corresponds to a production network for support of released software products.

17 . An apparatus comprising:

a processor; and

non-transitory memory storing instructions that, when executed by the processor, causes the apparatus to:

enumerate available files stored on a software distribution point (SDP) computing system;

retrieve, from the SDP computing system via a network, one or more new files based on a comparison of enumerated files to logical paths associated with the SDP computing system;

extract metadata from each of the one or more new files, wherein the metadata is recursively extracted from two or more stored files in a container file;

identify a match of metadata of a file of the one or more new files and metadata stored in a data store comprising information stored of “known-good” files;

update the matched metadata with an indication that the file is “known-deployed” to positively confirm that events associated with the one or more new files are related to deployment activity by the SDP, wherein the indication comprises artifact metadata only available during dynamic execution of a particular entry of an artifact by a known deployed file metadata analysis engine, and wherein the artifact metadata comprises an indication of the SDP computing system and an indication that the file was introduced to a host through methods associated with approved software distribution practices, and wherein artifact file metadata is enriched with labels to identify a functionality associated with the artifact, and wherein the artifact metadata associated with the SDP only available during dynamic execution of a particular entry of the artifact by the known deployed file metadata analysis engine comprises information that is variable based on one or both of a host endpoint upon which the artifact is deployed and a user associated with detonation of the one or more files; and

trigger, based on enrichment of the matched metadata, deployment of one or more files by the SDP computing system, wherein the one or more files are associated with metadata indicating the file has a “known-deployed” identifier.

18 . The apparatus of claim 17 , wherein the instructions further cause the apparatus to enrich the file metadata stored in the data store with semantic labels identifying a purpose served by an associated file within an enterprise computing environment and wherein the semantic labels correspond to a particular host endpoint.

19 . The apparatus of claim 17 , wherein the instructions further cause the apparatus to trigger analysis of the new file based on the indication that the new file has been saved.

20 . The apparatus of claim 17 , wherein the instructions further cause the apparatus to trigger analysis of the SDP computing system on a periodic basis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2024
From: SUMMERS, DAN E.; TEXADA, JEFFREY; KELLY, MATTHEW E.; DIMARIA, STEVEN
To: BANK OF AMERICA CORPORATION
Reel/Frame 066489/0855 →
Continuity (2)
Continuation 17319299 · May 13, 2021
Related Publication 20240193266A1 · Jun 13, 2024
References Cited (47)
US 7350204B2 · Lambert et al. · 2008 [cited by applicant]
US 7886049B2 · Adelstein et al. · 2011 [cited by applicant]
US 8176336B1 · Mao et al. · 2012 [cited by applicant]
US 8468602B2 · McDougal et al. · 2013 [cited by applicant]
US 9081747B1 · Tabieros et al. · 2015 [cited by applicant]
US 9323513B2 · Pillay et al. · 2016 [cited by applicant]
US 9330197B2 · Wilson et al. · 2016 [cited by applicant]
US 9563460B2 · Fitzgerald et al. · 2017 [cited by applicant]
US 9886443B1 · Gupta et al. · 2018 [cited by applicant]
US 9922033B1 · Odedra · 2018 [cited by examiner]
US 10860717B1 · Edmonds · 2020 [cited by applicant]
US 11240275B1 · Vashisht et al. · 2022 [cited by applicant]
US 11288368B1 · Wesson · 2022 [cited by applicant]
US 11941113B2 · Summers et al. · 2024 [cited by applicant]
US 11966472B2 · Summers et al. · 2024 [cited by applicant]
US 12397199B1 · Chung et al. · 2025 [cited by applicant]
US 20060206498A1 · Fujiwara · 2006 [cited by applicant]
US 20070282848A1 · Kiilerich · 2007 [cited by examiner]
US 20090280906A1 · Larsen et al. · 2009 [cited by applicant]
US 20120095973A1 · Kehoe et al. · 2012 [cited by applicant]
US 20150052044A1 · Castagna et al. · 2015 [cited by applicant]
US 20150133106A1 · Nakamura · 2015 [cited by examiner]
US 20150161397A1 · Cook et al. · 2015 [cited by applicant]
US 20150269132A1 · Weisberger et al. · 2015 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20180218753A1 · Hodge et al. · 2018 [cited by applicant]
US 20180285199A1 · Mitkar · 2018 [cited by examiner]
US 20180341631A1 · Verma · 2018 [cited by applicant]
US 20180341701A1 · Verma et al. · 2018 [cited by applicant]
US 20190114421A1 · Das · 2019 [cited by examiner]
US 20190207966A1 · Vashisht et al. · 2019 [cited by applicant]
US 20190207967A1 · Vashisht et al. · 2019 [cited by applicant]
US 20200112557A1 · McCullough, IV et al. · 2020 [cited by applicant]
US 20210209012A1 · Umberhocker et al. · 2021 [cited by applicant]
US 20210209079A1 · Lynch et al. · 2021 [cited by applicant]
US 20210218571A1 · Ansari · 2021 [cited by examiner]
US 20220366042A1 · Summers et al. · 2022 [cited by applicant]
US 20230401046A1 · Zhou et al. · 2023 [cited by applicant]
Hrishikesh Dewan ⋅ Ramesh Hansdah; Bristrita: Namespace and Metadata Distribution in Large-Scale Distributed Cloud Storage Systems; 2018 IEEE International Conference on Smart Cloud (SmartCloud) (2018, pp. 116-124); (Ye… [cited by examiner]
Hrishikesh Dewan ⋅ Ramesh C Hansdah; Julunga: A New Large-Scale Distributed Read-Write File Storage System for Cloud Computing Environments; 2018 IEEE 32nd International Conference on Advanced Information Networking and… [cited by examiner]
Arnab K. Paul ⋅ Ryan Chard ⋅ Kyle Chard ⋅ Steven Tuecke ⋅ Ali R. Butt ⋅ Ian Foster; FSMonitor: Scalable File System Monitoring for Arbitrary Storage Systems; 2019 IEEE International Conference on Cluster Computing (CLUS… [cited by examiner]
Tyler J. Skluzacek, et al., Skluma: An extensible metadata extraction pipeline for disorganized data, 2018 IEEE 14th International Conference on e-Science, DOI 10.1109/eScience.2019.00040, pp. 256-266. [cited by applicant]
Gonzalo P. Rodrigo, et al., ScienceSearch: Enabling Search through Automatic Metadata Generation, 2018 IEEE 14th International Conference on e-Science, DOI 10.1109/eScience.2018.00025, pp. 93-104. [cited by applicant]
Sriram Raghavan, et al., AssocGEN: Engtine for Analysing Metadata Based Associations in Digital Evidence, 978/1-4799-4061-5/13 © 2013 IEEE, downloaded on Nov. 30, 2023 from IEEE Xplore, pp. 8. [cited by applicant]
Ruitao Feng ⋅ Sen Chen ⋅ Xiaofei Xie ⋅ Guozhu Meng ⋅ Shang-Wei Lin ⋅ Yang Liu; A Performance-Sensitive Malware Detection u System Using Deep Learning on Mobile Devices; IEEE Transactions on Information Forensics and Sec… [cited by applicant]
Jiang Zhou⋅ Yong Chen ⋅ Wei ping Wang⋅ Shuibing He⋅ Dan Meng; A Highly Reliable Metadata Service for Large-Scale V Distributed File Systems; IEEE Transactions on Parallel and Distributed Systems (vol. 31, Issue: 2, 2020… [cited by applicant]
Yifeng Zhu⋅ Hong Jiang⋅ Jun Wang⋅ Feng Xian; HBA: Distributed Metadata Management for Large Cluster-Based Storage Systems; IEEE Transactions on Parallel and Distributed Systems (vol. 19, Issue: 6, 2008, pp. 750-763); (Y… [cited by applicant]