IP Library Granted Patent US 10,909,245
Granted Patent B1
US 10,909,245 · App. 16/143,031 · Granted Feb 2, 2021

Secure quarantine of potentially malicious content

Inventors: Jordan Saxonberg (Los Angeles, CA); Joe H. Chen (Manhattan Beach, CA)
Assignee: CA, Inc.
G06F21/568G06F21/602H04L9/0631H04L9/0825G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,909,245
App. No.
16/143,031
Granted
Feb 2, 2021
Kind
B1
Abstract

Secure Quarantine of Potentially Malicious Content. In one embodiment, a method for secure quarantine of potentially malicious content may include receiving a computer file from a third party, preventing the computer file from initially being accessed by a user associated with the computing device, collecting metadata from the computer file, encrypting the file and the collected metadata using a first encryption key, creating an encrypted computer file, encrypting the first encryption key using an asymmetric key, embedding the encrypted computer file into a new computer file, wherein at least one file object that is in the encrypted computer file is removed from the new computer file, enabling user access to the new computer file and the embedded encrypted computer file.

Claims (39)

1. A computer-implemented method for quarantining a malicious computer file, at least a portion of the method being performed by a computing device comprising one or more processors, the method comprising:

receiving a computer file;

preventing the computer file from initially being accessed by a user associated with the computing device;

collecting metadata from the computer file;

encrypting the computer file and the collected metadata using a first encryption key to create an encrypted quarantined computer file;

encrypting the first encryption key using an asymmetric key;

wherein the first encryption key is a symmetric encryption key;

embedding the quarantined encrypted computer file into a sanitized new computer file,

wherein at least one file object that is in the encrypted quarantined computer file is removed from the sanitized new computer file; and

enabling user access to the sanitized new computer file and the embedded quarantined encrypted computer file.

2. The method of claim 1 , encrypting the quarantined computer file and the collected metadata further comprises:

using an Advanced Encryption Standard (AES) algorithm.

3. The method of claim 1 , wherein using the symmetric encryption key further comprises: generating the symmetric encryption key in real-time.

4. The method of claim 1 , further comprising

removing an unencrypted copy of the encrypted symmetric key from memory after the first encryption key is encrypted with the preconfigured asymmetric key.

5. The method of claim 1 , wherein encrypting the first encryption key using the asymmetric key further comprises:

preconfiguring the asymmetric key by an administrator.

6. The method of claim 1 , wherein the preconfigured asymmetric key is stored in memory on the computing device.

7. The method of claim 1 , wherein encrypting the first encryption key using the asymmetric key further comprises:

encrypting the first encrypting the first encryption key using a Rivest-Sharmir-Adleman (RSA) algorithm.

8. The method of claim 1 , further comprising:

determining the computer file contains a malicious object.

9. The method of claim 1 , wherein collecting metadata further comprises:

collecting a name of the computer file, a size of the computer file, a hash of the computer file, a detection name, a detection time, a computer file creation time, or a combination thereof.

10. One or more non-transitory computer-readable media comprising one or more computer readable instructions that, when executed by one or more processors of a computing device, cause the computing device to perform a method for quarantining a malicious computer file, the method comprising: receiving a computer file;

preventing the computer file from initially being accessed by a user associated with the computing device;

collecting metadata from the computer file;

encrypting the computer file and the collected metadata using a first encryption key to create an encrypted quarantined computer file;

encrypting the first encryption key using an asymmetric key;

wherein the first encryption key is a symmetric key;

embedding the quarantined encrypted computer file into a sanitized new computer file,

wherein at least one file object that is in the quarantined encrypted computer file is removed from the sanitized new computer file; and

enabling user access to the sanitized new computer file and the embedded quarantined encrypted computer file.

11. The computer-readable media of claim 10 , the method further comprising: determining the computer file contains a malicious object.

12. The computer-readable media of claim 10 , wherein collecting metadata further comprises:

collecting a name of the computer file, a size of the computer file, a hash of the computer file, a detection name, a detection time, a computer file creation time, or a combination thereof.

13. The computer-readable media of claim 10 , wherein the symmetric encryption key is generated in real-time; and

wherein an unencrypted version of the encrypted symmetric key is erased after the symmetric key is encrypted with the asymmetric key.

14. The computer-readable media of claim 10 , wherein the asymmetric key is preconfigured by an administrator and is stored in memory on the computing device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2018
From: SAXONBERG, JORDAN; CHEN, JOE H.
To: SYMANTEC CORPORATION
Reel/Frame 046983/0957 →