IP Library Granted Patent US 8,346,805
Granted Patent B2
US 8,346,805 · App. 11/148,690 · Granted Jan 1, 2013

Filter driver for identifying disk files by analysis of content

Assignee: Symantec Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,346,805
App. No.
11/148,690
Filed
Jun 9, 2005
Granted
Jan 1, 2013
Kind
B2
Art Unit
2158
USPC
707/781
Abstract

A system and method for excluding certain types of files from being saved to a system by examining file data. The file data is examined by: mapping the circular queue to memory; reading the file identifiers from the circular queue (a named mutex is locked until all file identifiers have been read from the queue); using the file identifier to open the file; scanning the opened file to create a file signature; comparing the file signature to each entry on a list of signature criteria; and performing a storage policy if there is a match.

Claims (34)

1. A method, comprising:

intercepting operations to save files to a system, wherein said intercepting is performed by a kernel mode input/output filter driver;

scanning contents of said files to generate file signatures respectively corresponding to said files, wherein said file signatures are dependent upon data stored within respective files, and wherein said scanning is performed by a signature processing user mode service;

for two or more of said files, determining whether individual ones of said file signatures respectively corresponding to said files match one or more signatures stored in a signature database;

for at least one file, in response to determining that said file signature respectively corresponding to said at least one file matches one or more signatures stored in said signature database, executing a storage policy with respect to said at least one file; and

for at least another file, in response to determining that said file signature respectively corresponding to said at least another file matches no signatures stored in said signature database, saving said at least another file to said system.

2. The method as recited in claim 1 , wherein for a given one of said files, said file signature is indicative of a type of data stored within said given file.

3. The method as recited in claim 2 , wherein said file signature includes a pattern of information located within the first 1,024 bytes of said given file, and wherein said pattern of information is common to all files of the same type as said given file.

4. The method as recited in claim 1 , wherein executing said storage policy includes at least one of: deleting said at least one file, quarantining said at least one file, notifying a system administrator of said operation to save said at least one file, or notifying a user who initiated said operation that said at least one file is not allowed to be saved.

5. A method, comprising:

intercepting operations to save files to a system, wherein said intercepting is performed by a kernel mode input/output filter driver;

determining whether file identifiers respectively corresponding to said files satisfy specified file identifier criteria, wherein said file identifier criteria indicate disallowed types of files, and wherein said determining is performed by a signature processing user mode service;

for at least a first file, in response to determining that said respectively corresponding file identifier satisfies said file identifier criteria, executing a storage policy with respect to said at least a first file;

for at least a second and a third file, in response to determining that said respectively corresponding file identifier does not satisfy said file identifier criteria, determining whether a file signature generated dependent upon data stored within said at least a second file matches one or more signatures stored in a signature database, wherein determining whether said file signature matches is performed by a signature processing user mode service;

for said at least a second file, in response to determining that said file signature matches one or more signatures stored in said signature database, executing said storage policy with respect to said at least a second file; and

for said at least a third file, in response to determining that said respectively corresponding file signature matches no signatures stored in said signature database, saving said at least a third file to said system.

6. The method as recited in claim 5 , wherein a given one of said file identifiers includes a file name.

7. The method as recited in claim 5 , wherein a given one of said file identifiers includes a file extension.

8. The method as recited in claim 5 , wherein for a given one of said files, said file signature is indicative of a type of data stored within said given file.

9. The method as recited in claim 8 , wherein said file signature includes a pattern of information located within the first 1,024 bytes of said given file, and wherein said pattern of information is common to all files of the same type as said given file.

10. The method as recited in claim 5 , wherein executing said storage policy includes at least one of: deleting said at least a first file, quarantining said at least a first file, notifying a system administrator of said operation to save said at least a first file, or notifying a user who initiated said operation that said at least a first file is not allowed to be saved.

11. The method as recited in claim 5 , wherein said determining whether said file identifiers respectively corresponding to said files satisfy said specified file identifier criteria is performed by the kernel-mode input/output filter driver.

12. A system, comprising:

an input/output filter driver configured to operate in kernel mode;

a signature processing user mode service;

a signature database; and

a policy database;

wherein said input/output filter driver is configured to intercept attempts to save files to the system;

wherein said signature processing user mode service is configured to scan contents of said file to generate file signatures respectively corresponding to said files, wherein said file signatures are dependent upon data stored within respective files, and to determine whether individual ones of said file signatures respectively corresponding to said files match one or more signatures stored in said signature database;

wherein for at least one file, in response to determining that said file signature respectively corresponding to said at least one file matches one or more signatures stored in said signature database, said signature processing user mode service is further configured to execute a storage policy stored within said policy database with respect to said at least one file; and

wherein for at least another file, in response to said signature processing user mode service determining that said file signature respectively corresponding to said at least another file matches no signatures stored in said signature database, said input/output filter driver is further configured to save said at least another file to said system.

13. The system as recited in claim 12 , wherein for a given one of said files, said file signature is indicative of a type of data stored within said file.

14. The system as recited in claim 13 , wherein said file signature includes a pattern of information located within the first 1,024 bytes of said given file, and wherein said pattern of information is common to all files of the same type as said given file.

15. The system as recited in claim 12 , wherein executing said storage policy includes at least one of: deleting said at least one file, quarantining said at least one file, notifying a system administrator of said operation to save said at least one file, or notifying a user who initiated said operation that said at least one file is not allowed to be saved.

Assignments (19)
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA AND CORRECT THE PATENT NUMBERS PREVIOUSLY RECORDED AT REEL: 69548 FRAME: 468. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 4, 2026
From: VERITAS TECHNOLOGIES LLC
To: ARCTERA US LLC
Reel/Frame 074876/0584 →
SECURITY INTEREST Recorded Dec 12, 2025
From: ARCTERA US LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 073951/0470 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 069585/0150 Recorded Dec 1, 2025
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: ARCTERA US LLC
Reel/Frame 073833/0848 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 070530/0497 Recorded Dec 1, 2025
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: ARCTERA US LLC
Reel/Frame 073833/0730 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
PATENT SECURITY AGREEMENT Recorded Dec 10, 2024
From: ARCTERA US LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069585/0150 →
SECURITY INTEREST Recorded Dec 10, 2024
From: ARCTERA US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 069563/0243 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC
To: ARCTERA US LLC
Reel/Frame 069548/0468 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER AND CHANGE OF NAME Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC; VERITAS TECHNOLOGIES LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038455/0752 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037697/0412 →
CHANGE OF NAME Recorded May 29, 2015
From: PRECISE SOFTWARE SOLUTIONS
To: SYM COMPANY P, INC.
Reel/Frame 035805/0408 →
MERGER AND CHANGE OF NAME Recorded May 29, 2015
From: SYM COMPANY P, INC.; SYMANTEC CORPORATION
To: SYMANTEC CORPORATION
Reel/Frame 035747/0436 →
MERGER AND CHANGE OF NAME Recorded May 29, 2015
From: W. QUINN; PRECISE SOFTWARE SOLUTIONS
To: PRECISE SOFTWARE SOLUTIONS
Reel/Frame 035747/0340 →
Continuity (3)
Continuation 10133370 · Apr 29, 2002
Provisional Application 60287350 · Apr 27, 2001
Related Publication 20050234866A1 · Oct 20, 2005