IP Library Granted Patent US 8,863,286
Granted Patent B1
US 8,863,286 · App. 11/837,779 · Granted Oct 14, 2014

Notification for reassembly-free file scanning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,863,286
App. No.
11/837,779
Granted
Oct 14, 2014
Kind
B1
Abstract

Techniques for notification of reassembly-free file scanning are described herein. According to one embodiment, a first request for accessing a document provided by a remote node is received from a client. In response to the first request, it is determined whether a second request previously for accessing the document of the remote node indicates that the requested document from the remote node contains offensive data. If the requested document contains offensive data, a message is returned to the client, without accessing the requested document of the remote node, indicating that the requested document is not delivered to the client.

Claims (48)

1. A computer implemented method, comprising:

maintaining, by a processor a data structure in a storage device to store a list of previous requests for accessing a plurality of documents that have been determined to contain offensive data;

in response to receiving a first request for accessing a document provided by a remote node from a client, the first request is in response to a previous failed request for accessing the document, the processor determining whether one of the previous requests for accessing the document of the remote node indicates that the requested document from the remote node contains offensive data, wherein the determining is based, in part, on whether an Internet Protocol of address of the remote node and a URL (universal resource locator) of the first request match an Internet Protocol address and URL corresponding to the one of the previous requests, and the document is one of the plurality of documents, wherein the determining that the first request matches the Internet Protocol address and URL corresponding to one of the previous requests contains offensive data is performed using a hash function, and wherein storage space of the data structure is reduced by deleting least recently used entries in the data structure; and

returning, by the processor, a message to the client, without accessing the requested document of the remote node, indicating that the requested document is not delivered to the client if it is determined that the requested document from the remote node contains offensive data, wherein the message contains reasons regarding why connections made in response to the first request and the one of the previous requests are terminated without accessing the document.

2. The method of claim 1 , wherein maintaining the data structure comprises:

storing in a storage device Internet Protocol address of the remote node and a URL of the requested document in the data structure; and

storing in the data structure in a storage device information representing one or more reasons why the access to the requested document has been denied in view of the offensive data.

3. The method of claim 2 , further comprising:

prior to receiving the first request, receiving, by the processor, a second request for accessing the document of the remote node;

in response to the second request, downloading, by the processor, at least a portion of the document from the remote node;

scanning, by the processor, the downloaded portion of the document to determine whether the document contains offensive data;

storing, by the processor, the Internet Protocol address of the remote node and the URL of the document in the data structure, including information regarding the offensive data; and

terminating, by the processor, a connection with the remote node without forwarding the complete document to a client that initiates the second request.

4. The method of claim 2 , further comprising

in response to the first request, extracting, by the processor, the Internet Protocol address of the remote node and the URL of the requested document from the first request.

5. The method of claim 4 , further comprising retrieving, by the processor, the information representing one or more reasons from the data structure and associated with the Internet Protocol address and URL.

6. The method of claim 2 , further comprising performing, by the processor, the hash function on the at least one of the Internet Protocol address and URL prior to storing in the data structure.

7. The method of claim 1 , wherein the offensive data comprises at least one of virus data and spyware data.

8. A non-transitory machine-readable storage medium having embodied thereon a program executable by a processor to perform a method, the method comprising:

maintaining a data structure in a storage device to store a list of previous requests for accessing a plurality of documents that have been determined to contain offensive data;

in response to receiving a first request for accessing a document provided by a remote node from a client, the first request is in response to a previous failed request for accessing the document, determining whether one of the previous requests for accessing the document of the remote node indicates that the requested document from the remote node contains offensive data, wherein the determining is based, in part, on whether an Internet Protocol address of the remote node and a URL (universal resource locator) of the first request match an Internet Protocol address and URL corresponding to the one of the previous requests, and the document is one of the plurality of documents, wherein the determining that the first request matches the Internet Protocol address and URL corresponding to one of the previous requests contains offensive data is performed using a hash function, and wherein storage space of the data structure is reduced by deleting least recently used entries in the data structure; and

returning a message to the client, without accessing the requested document of the remote node, indicating that the requested document is not delivered to the client if it is determined that the requested document from the remote node contains offensive data, wherein the message contains reasons regarding why connections made in response to the first request and the one of the previous requests are terminated without accessing the document.

9. The non-transitory machine-readable storage medium of claim 8 , wherein maintaining the data structure comprises:

storing an Internet Protocol address of the remote node and a URL of the requested document in the data structure; and

storing in the data structure information representing one or more reasons why the access to the requested document has been denied in view of the offensive data.

10. The non-transitory machine-readable storage medium of claim 9 , wherein the method further comprises:

prior to receiving the first request, receiving a second request for accessing the document of the remote node;

in response to the second request, downloading at least a portion of the document from the remote node;

scanning the downloaded portion of the document to determine whether the document contains offensive data;

storing the Internet Protocol address of the remote node and the URL of the document in the data structure, including information regarding the offensive data; and

terminating a connection with the remote node without forwarding the complete document to a client that initiates the second request.

11. The non-transitory machine-readable storage medium of claim 9 , wherein the method further comprises

in response to the first request extracting at least one of the Internet Protocol address of the remote node and the URL of the requested document from the first request.

12. The non-transitory machine-readable storage medium of claim 11 , wherein the method further comprises retrieving the information representing one or more reasons from the data structure and associated with the at least one of the Internet Protocol address and URL.

13. The non-transitory machine-readable storage medium of claim 9 , wherein the method further comprises performing a hash function on the at least one of the-address and URL prior to storing in the data structure.

14. The non-transitory machine-readable storage medium of claim 8 , wherein the offensive data comprises at least one of virus data and spyware data.

15. A computer implemented method, comprising:

in response to at least a portion of a document downloaded from a remote node based on a first request from a client, scanning, by a processor, the downloaded portion of the document to determine whether the document contains offensive data;

storing in a storage device an Internet Protocol address of the remote node and a URL (universal resource locator) of the document, as well as information regarding the offensive data, in a data structure, wherein the Internet Protocol address of the remote node and the URL of the document are used to prevent subsequent requests from accessing the document of the remote node;

in response to a second request subsequent to the first request for accessing the document of the remote node, the second request is in response to the first request being failed, extracting, by the processor, an Internet Protocol address of the remote node and URL associated with the document from the second request;

accessing, by the processor, the data structure to determine whether the data structure contains the extracted the Internet Protocol address and URL that are associated with offensive data, wherein the determining whether the Internet Protocol address and URL are associated with offensive data is performed using a hash function on the data structure, and wherein the processor reduces storage space of the data structure by deleting least recently used entries in the data structure; and

when the data structure contains the Internet Protocol address and URL, returning, by the processor, to the client, without accessing the document requested by the second request, the information regarding the offensive data associated with the Internet Protocol address and URL, wherein the information contains reasons regarding why connections made in response to the first and second requests are terminated without accessing the document.

16. The method of claim 15 , further comprising hashing, by the processor, the at least one of the Internet Protocol address and URL using a predetermined hash function prior to storing in the data structure.

17. A network access device, comprising:

a non-transitory storage medium including a data structure having a plurality of entries, each entry storing at least one of an Internet Protocol address of an information provider and a universal resource locator (URL) of a document provided by the information provider that the document contains offensive data, and information concerning the offensive data; and

a processor configured for running a scan of the data structure to determine whether the data structure contains at least one of an Internet Protocol address of the remote node and a URL associated with the requested document in response to receiving a second request for accessing a document provided by a remote node received from a client, the second request is in response to a failed first request for accessing the document, and extracting an Internet Protocol address of the remote node and URL associated with the document from the second request;

accessing the data structure to determine whether the data structure contains the extracted Internet Protocol address and URL are associated with offensive data, wherein the determining whether the Internet Protocol address and URL that are associated with offensive data is performed using a hash function on the data structure, and wherein the processor reduces storage space of the data structure by deleting least recently used entries in the data structure; and

when the data structure contains the Internet Protocol address and URL, returning to the client, without accessing the document requested by the second request, the information regarding the offensive data associated with the Internet Protocol address and URL and reasons regarding why connections made in response to the first and second requests are terminated without accessing the document.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Nov 15, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044770/0871 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
CONVERSION AND NAME CHANGE Recorded Jun 16, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 035922/0019 →
MERGER Recorded Jun 16, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 035847/0547 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2007
From: DUBROVSKY, ALEKSANDR; KORSUNSKY, IGOR; YANOVSKY, ROMAN; YANOVSKY, BORIS
To: SONICWALL, INC.
Reel/Frame 019686/0346 →