IP Library › Granted Patent US 12,651,062
Granted Patent B2
US 12,651,062 · App. 18/377,999 · Granted Jun 9, 2026

System and method for archive AM scanning

Inventors: Mohamed Adly Amer Elgaafary (Vilnius, LT); Aleksandr Ševčenko (Vilnius, LT)
Assignee: UAB 360 IT
G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,062
App. No.
18/377,999
Granted
Jun 9, 2026
Kind
B2
Abstract

Systems and methods for archive scanning are provided herein. In some embodiments, a method includes: selecting an archive; reading a metadata representing a plurality of files within the archive; reading a plurality of hash strings from the archive; comparing the plurality of hash strings with a database of hash strings; and determining, based on the comparing, if the plurality of files within the archive represent a security threat based on the plurality of hash strings.

Claims (37)

1 . An archive scanning method comprising:

selecting an unextracted archive file that includes a plurality of files and metadata of the plurality of files in the unextracted archive file;

extracting the metadata without extracting the plurality of files;

sorting the plurality of files, based on the extracted metadata, into a first group having malicious traits and a second group not having malicious traits, wherein the sorting includes comparing the metadata to predefined metadata criteria, wherein the compared metadata does not include hash strings;

comparing a plurality of hash strings of files of the second group and not the first group with a database of hash strings; and

determining, based on the comparing, if the plurality of files within the archive represent a security threat.

2 . The method of claim 1 , further comprising calculating a file size associated with the plurality of files within the archive file.

3 . The method of claim 1 , further comprising determining if the archive file contains one or more additional unextracted archive files.

4 . The method of claim 1 , wherein the archive file is a ZIP or RAR file.

5 . The method of claim 1 , wherein the metadata includes at least one of file size, file name, file type, or date of file creation.

6 . The method of claim 1 , further comprising breaking an encryption of the archive file.

7 . A non-transient computer readable medium having stored thereon computer readable instructions, which when executed by a computer, perform an archive scanning method comprising;

selecting an unextracted archive file that includes a plurality of files and metadata of the plurality of files in the unextracted archive file;

extracting the metadata without extracting the plurality of files;

sorting the plurality of files, based on the extracted metadata, into a first group having malicious traits and a second group not having malicious traits, wherein the sorting includes comparing the metadata to predefined metadata criteria, wherein the compared metadata does not include hash strings;

comparing a plurality of hash strings of files of the second group and not the first group with a database of hash strings; and

determining, based on the comparing, if the plurality of files within the archive represent a security threat.

8 . The non-transient computer readable medium of claim 7 , further comprising calculating, based on the metadata, a file size associated with the plurality of files within the archive file.

9 . The non-transient computer readable medium of claim 7 , further comprising determining if the archive file contains one or more additional archives.

10 . The non-transient computer readable medium of claim 7 , wherein the metadata includes at least one of file type, file name, or date of creation.

11 . The non-transient computer readable medium of claim 7 , wherein the metadata includes file size.

12 . The non-transient computer readable medium of claim 7 , wherein the archive file is a ZIP or RAR file.

13 . The non-transient computer readable medium of claim 7 , wherein the method further comprises breaking an encryption of the archive.

14 . A security system comprising:

a user device; and

a processor programmed to:

select an unextracted archive file that includes a plurality of files and metadata of the plurality of files in the unextracted archive file;

extract the metadata without extracting the plurality of files;

sort the plurality of files, based on the extracted metadata, into a first group having malicious traits and a second group not having malicious traits, wherein the sorting includes comparing the metadata to predefined metadata criteria, wherein the compared metadata does not include hash strings;

compare a plurality of hash strings of files of the second group and not the first group with a database of hash strings; and

determine, based on the comparing, if the plurality of files within the archive represent a security threat.

15 . The system of claim 14 , wherein the metadata includes at least one of file type or file size.

16 . The system of claim 14 , wherein the metadata includes at least one of file name or date of file creation.

17 . The system of claim 14 , wherein the processor is configured to break an encryption of the archive file.

18 . The system of claim 14 , wherein the archive file is a ZIP or RAR file.

19 . The system of claim 14 , further comprising the processor calculating a file size associated with the plurality of files within the archive file.

20 . The system of claim 14 , further comprising the processor determining if the archive file contains one or more additional unextracted archive files.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: ELGAAFARY, MOHAMED ADLY AMER; SEVCENKO, ALEKSANDR
To: UAB 360 IT
Reel/Frame 066206/0175 →
Continuity (2)
Continuation 17673168 · Feb 16, 2022
Related Publication 20240037232A1 · Feb 1, 2024
References Cited (22)
US 6851058B1 · Gartside · 2005 [cited by examiner]
US 8863284B1 · Polyakov · 2014 [cited by applicant]
US 10621346B1 · Singh · 2020 [cited by applicant]
US 20050138081A1 · Alshab · 2005 [cited by examiner]
US 20080141373A1 · Fossen · 2008 [cited by applicant]
US 20090254575A1 · Kravets · 2009 [cited by applicant]
US 20110083181A1 · Nazarov · 2011 [cited by applicant]
US 20140143889A1 · Ginter · 2014 [cited by examiner]
US 20150142742A1 · Hong · 2015 [cited by applicant]
US 20150234848A1 · Weinstein · 2015 [cited by applicant]
US 20170359368A1 · Hodgman · 2017 [cited by applicant]
US 20180091306A1 · Antonopoulos · 2018 [cited by applicant]
US 20180101542A1 · Zhao · 2018 [cited by applicant]
US 20180203998A1 · Maisel · 2018 [cited by applicant]
US 20190065744A1 · Gaustad · 2019 [cited by examiner]
US 20190138446A1 · Iyer · 2019 [cited by applicant]
US 20200327227A1 · Chebyshev · 2020 [cited by examiner]
US 20210056204A1 · Singh · 2021 [cited by examiner]
US 20210357364A1 · Saliba · 2021 [cited by applicant]
Barrett, “NCBI GEO: archive for functional genomics data sets-update”, Nov. 27, 2012, Nucleic acids research, pp. 991-994 (Year: 2012). [cited by examiner]
You, “Evaluation of Efficient Archival Storage Technique”, 2004, MSST, pp. 1-5 (Year: 2004). [cited by examiner]
Miao, “Towards unified data and lifecycle management for deep learning”, 2017, IEEE, pp. 571-582 (Year: 2017). [cited by applicant]