System and method for archive AM scanning
Systems and methods for archive scanning are provided herein. In some embodiments, a method includes: selecting an archive; reading a metadata representing a plurality of files within the archive; reading a plurality of hash strings from the archive; comparing the plurality of hash strings with a database of hash strings; and determining, based on the comparing, if the plurality of files within the archive represent a security threat based on the plurality of hash strings.
1 . An archive scanning method comprising:
selecting an unextracted archive file that includes a plurality of files and metadata of the plurality of files in the unextracted archive file;
extracting the metadata without extracting the plurality of files;
sorting the plurality of files, based on the extracted metadata, into a first group having malicious traits and a second group not having malicious traits, wherein the sorting includes comparing the metadata to predefined metadata criteria, wherein the compared metadata does not include hash strings;
comparing a plurality of hash strings of files of the second group and not the first group with a database of hash strings; and
determining, based on the comparing, if the plurality of files within the archive represent a security threat.
2 . The method of claim 1 , further comprising calculating a file size associated with the plurality of files within the archive file.
3 . The method of claim 1 , further comprising determining if the archive file contains one or more additional unextracted archive files.
4 . The method of claim 1 , wherein the archive file is a ZIP or RAR file.
5 . The method of claim 1 , wherein the metadata includes at least one of file size, file name, file type, or date of file creation.
6 . The method of claim 1 , further comprising breaking an encryption of the archive file.
7 . A non-transient computer readable medium having stored thereon computer readable instructions, which when executed by a computer, perform an archive scanning method comprising;
selecting an unextracted archive file that includes a plurality of files and metadata of the plurality of files in the unextracted archive file;
extracting the metadata without extracting the plurality of files;
sorting the plurality of files, based on the extracted metadata, into a first group having malicious traits and a second group not having malicious traits, wherein the sorting includes comparing the metadata to predefined metadata criteria, wherein the compared metadata does not include hash strings;
comparing a plurality of hash strings of files of the second group and not the first group with a database of hash strings; and
determining, based on the comparing, if the plurality of files within the archive represent a security threat.
8 . The non-transient computer readable medium of claim 7 , further comprising calculating, based on the metadata, a file size associated with the plurality of files within the archive file.
9 . The non-transient computer readable medium of claim 7 , further comprising determining if the archive file contains one or more additional archives.
10 . The non-transient computer readable medium of claim 7 , wherein the metadata includes at least one of file type, file name, or date of creation.
11 . The non-transient computer readable medium of claim 7 , wherein the metadata includes file size.
12 . The non-transient computer readable medium of claim 7 , wherein the archive file is a ZIP or RAR file.
13 . The non-transient computer readable medium of claim 7 , wherein the method further comprises breaking an encryption of the archive.
14 . A security system comprising:
a user device; and
a processor programmed to:
select an unextracted archive file that includes a plurality of files and metadata of the plurality of files in the unextracted archive file;
extract the metadata without extracting the plurality of files;
sort the plurality of files, based on the extracted metadata, into a first group having malicious traits and a second group not having malicious traits, wherein the sorting includes comparing the metadata to predefined metadata criteria, wherein the compared metadata does not include hash strings;
compare a plurality of hash strings of files of the second group and not the first group with a database of hash strings; and
determine, based on the comparing, if the plurality of files within the archive represent a security threat.
15 . The system of claim 14 , wherein the metadata includes at least one of file type or file size.
16 . The system of claim 14 , wherein the metadata includes at least one of file name or date of file creation.
17 . The system of claim 14 , wherein the processor is configured to break an encryption of the archive file.
18 . The system of claim 14 , wherein the archive file is a ZIP or RAR file.
19 . The system of claim 14 , further comprising the processor calculating a file size associated with the plurality of files within the archive file.
20 . The system of claim 14 , further comprising the processor determining if the archive file contains one or more additional unextracted archive files.