System and method for protecting a computer and a network from hostile downloadables
Abstract
A computer-based method for generating a Downloadable ID to identify a Downloadable, including obtaining a Downloadable that includes one or more references to software components required by the Downloadable, fetching at least one software component identified by the one or more references, and performing a function on the Downloadable and the fetched software components to generate a Downloadable ID. A system and a computer-readable storage medium are also described and claimed.
Term
Term ended
Projected expiry passed 6 November 2017, 8.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 1 independent, 19 dependent
- 1Claims of equivalent WO 9821683 A2 WHAT IS CLAIMED IS:1. A computer-based method, comprising the steps of: receiving a Downloadable;comparing the Downloadable against a security policy to determine if the security policy has been violated;and discarding the Downloadable if the security policy has been violated.
225 paragraphs in 5 sections, as filed
Description of equivalent WO 9821683 A2
0001SYSTEM AND METHOD FOR PROTECTING A COMPUTER AND A NETWORK FROM HOSTILE DOWNLOADABLES
0002BACKGROUND OF THE INVENTION 1. Field of the Invention
0003This invention relates generally to computer networks, and more particularly provides
0004a system and method for protecting a computer and a network from hostile Downloadables.
00052. Description of the Background Art
0006The Internet is currently a collection of over 100,000 individual computer networks owned by governments, universities, nonprofit groups and companies, and is expanding at an accelerating rate. Because the Internet is public, the Internet has become a major source of many system damaging and system fatal application programs, commonly referred to as "viruses." Accordingly, programmers continue to design computer and computer network security systems for blocking these viruses from attacking both individual and network
0007computers. On the most part, these security systems have been relatively successful.
0008However, these security systems are not configured to recognize computer viruses which
0009have been attached to or configured as Downloadable application programs, commonly
0010referred to as "Downloadables." A Downloadable is an executable application program, which is downloaded from a source computer and run on the destination computer. Downloadable is typically requested by an ongoing process such as by an Internet browser or web engine. Examples of Downloadables include Java'<sup>M</sup> applets designed for use in the Java<sup>I</sup> distributing environment developed by Sun Microsystems, Inc., JavaScript scripts also developed by Sun Microsystems, Inc., ActiveX™ controls designed for use in the ActiveX <sup>I M</sup>
0011distributing environment developed by the Microsoft Corporation, and Visual Basic also
0012developed by the Microsoft Corporation. Therefore, a system and method are needed to
0013protect a network from hostile Downloadables.
SUMMARY OF THE INVENTION
0015The present invention provides a system for protecting a network from suspicious Downloadables. The system comprises a security policy, an interface for receiving a Downloadable, and a comparator, coupled to the interface, for applying the secuπn polιc to the Downloadable to determine if the security policy has been violated. The Downloadable
0016may include a Java™ applet, an ActiveX™ control, a JavaScript™ script, or a Visual Basic
0017script. The security policy may include a default security policy to be applied regardless of
0018the client to whom the Downloadable is addressed, a specific security policy to be applied
0019based on the client or the group to which the client belongs, or a specific policy to be applied based on the client/group and on the particular Downloadable received. The system uses an ID generator to compute a Downloadable ID identifying the Downloadable, preferably, by fetching all components of the Downloadable and performing a hashing function on the Downloadable including the fetched components.
0020Further, the security policy may indicate several tests to perform, including ( h a
0021comparison with known hostile and non-hostile Downloadables; (2) a comparison with
0022Downloadables to be blocked or allowed per administrative override; (3) a comparison of the
0023Downloadable security profile data against access control lists; (4) a comparison of a
0024certificate embodied in the Downloadable against trusted certificates; and (5) a comparison of
0025the URL from which the Downloadable originated against trusted and untrusted URLs. Based on these tests, a logical engine can determine whether to allow or block the
0026Downloadable.
0027The present invention further provides a method for protecting a computer from
0028suspicious Downloadables. The method comprises the steps of receiving a Downloadable.
0029comparing the Downloadable against a security policy to determine if the security policy has
0030been violated, and discarding the Downloadable if the security policy has been violated.
0031It will be appreciated that the system and method of the present invention may provide
0032computer protection from known hostile Downloadables. The system and method of the
0033present invention may identify Downloadables that perform operations deemed suspicious.
0034The system and method of the present invention may examine the Downloadable code to
0035determine whether the code contains any suspicious operations, and thus may allow or block
0036the Downloadable accordingly.
BRIEF DESCRIPTION OF THE DRAWINGS
0038FIG. 1 is a block diagram illustrating a network system, in accordance with the
0039present invention;
0040FIG. 2 is a block diagram illustrating details of the internal network security system of
FIG. 1 ;
0042FIG. 3 is a block diagram illustrating details of the security program and the security
0043database of FIG. 2;
0044FIG. 4 is a block diagram illustrating details of the security policies of FIG. 3;
0045FIG. 5 is a block diagram illustrating details of the security management console of
0046FIG. 1 ; FIG. 6A is a flowchart illustrating a method of examining for suspicious
0047Downloadables, in accordance with the present invention;
0048FIG. 6B is a flowchart illustrating details of the step for finding the appropriate security policy of FIG. 6A; FIG. 6C is a flowchart illustrating a method for determining whether an incoming
0049Downloadable is to be deemed suspicious;
0050FIG. 7 is a flowchart illustrating details of the FIG. 6 step of decomposing a Downloadable; and
0051FIG. 8 is a flowchart illustrating a method 800 for generating a Downloadable ID for
0052identifying a Downloadable.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT
0054FIG. 1 is a block diagram illustrating a network system 100, in accordance with the present invention. The network system 100 includes an external computer network 105, such as the Wide Area Network (WAN) commonly referred to as the Internet, coupled via a communications channel 125 to an internal network security system 1 10. The network
0055system 100 further includes an internal computer network 1 15, such as a corporate Local
0056Area Network (LAN), coupled via a communications channel 130 to the internal network
0057computer system 110 and coupled via a communications channel 135 to a security
0058management console 120.
0059The internal network security system 1 10 examines Downloadables received from external computer network 105, and prevents Downloadables deemed suspicious from reaching the internal computer network 1 15. It will be further appreciated that a Downloadable is deemed suspicious if it performs or may perform any undesirable operation. or if it threatens or may threaten the integrity of an internal computer network 1 15
0060component. It is to be understood that the term "suspicious" includes hostile, potentially
0061hostile, undesirable, potentially undesirable, etc. Security management console 120 enables
0062viewing, modification and configuration of the internal network security system 110.
0063FIG. 2 is a block diagram illustrating details of the internal network security system 1 10, which includes a Central Processing Unit (CPU) 205, such as an Intel Pentium" " microprocessor or a Motorola Power PC<sup>®</sup> microprocessor, coupled to a signal bus 220. The internal network security system 1 10 further includes an external communications interface 210 coupled between the communications channel 125 and the signal bus 220 for receiving
0064Downloadables from external computer network 105, and an internal communications
0065interface 225 coupled between the signal bus 220 and the communications channel 130 for
0066forwarding Downloadables not deemed suspicious to the internal computer network 115.
0067The external communications interface 210 and the internal communications interface 225 may be functional components of an integral communications interface (not shown) for both receiving Downloadables from the external computer network 105 and forwarding Downloadables to the internal computer network 1 15.
0068Internal network security system 1 10 further includes Input/Output (I/O) interfaces 215 (such as a keyboard, mouse and Cathode Ray Tube (CRT) display), a data storage
0069device 230 such as a magnetic disk, and a Random-Access Memory (RAM) 235. each
0070coupled to the signal bus 220. The data storage device 230 stores a security database 240,
0071which includes security information for determining whether a received Downloadable is to
0072be deemed suspicious. The data storage device 230 further stores a users list 260 identifying
0073the users within the internal computer network 115 who may receive Downloadables, and an event log 245 which includes determination results for each Downloadable examined and
0074runtime indications of the internal network security system 1 10. An operating system 250
0075controls processing by CPU 205, and is typically stored in data storage device 230 and
0076loaded into RAM 235 (as illustrated) for execution. A security program 255 controls
0077examination of incoming Downloadables, and also may be stored in data storage device 230
0078and loaded into RAM 235 (as illustrated) for execution by CPU 205.
0079FIG. 3 is a block diagram illustrating details of the security program 255 and the
0080security database 240. The security program 255 includes an ID generator 3 15, a policy
0081finder 317 coupled to the ID generator 315, and a first comparator 320 coupled to the policy
0082finder 317. The first comparator 320 is coupled to a logical engine 333 via four separate
0083paths, namely, via Path 1 , via Path 2, via Path 3 and via Path 4. Path 1 includes a direct
0084connection from the first comparator 320 to the logical engine 333. Path 2 includes a code
0085scanner coupled to the first comparator 320, and an Access Control List (ACL) comparator
0086330 coupling the code scanner 325 to the logical engine 333. Path 3 includes a certificate
0087scanner 340 coupled to the first comparator 320, and a certificate comparator 345 coupling
0088the certificate scanner 340 to the logical engine 333. Path 4 includes a Uniform Resource
0089Locator (URL) comparator 350 coupling the first comparator 320 to the logical engine 3330.
0090A record-keeping engine 335 is coupled between the logical engine 333 and the event log
0091245.
0092The security program 255 operates in conjunction with the security database 240,
0093which includes security policies 305, known Downloadables 307, known Certificates 309
0094and Downloadable Security Profile (DSP) data 310 corresponding to the known
0095Downloadables 307. Security policies 305 includes policies specific to particular users 260 and default (or generic) policies for determining whether to allow or block an incoming
0096Downloadable. These security policies 305 may identify specific Downloadables to block,
0097specific Downloadables to allow, or necessary criteria for allowing an unknown Downloadable. Referring to FIG. 4, security policies 305 include policy selectors 405. access control lists 410, trusted certificate lists 415, URL rule bases 420. and lists 425 of Downloadables to allow or to block per administrative override.
0098Known Downloadables 307 include lists of Downloadables which Original Equipment Manufacturers (OEMs) know to be hostile, of Downloadables which OFMs
0099know to be non-hostile, and of Downloadables previously received by this security program
0100255. DSP data 310 includes the list of all potentially hostile or suspicious computer
0101operations that may be attempted by each known Downloadable 307, and may also include
0102the respective arguments of these operations. An identified argument of an operation is referred to as "resolved." An unidentified argument is referred to as "unresolved." DSP data 310 is described below with reference to the code scanner 325. The ID generator 315 receives a Downloadable (including the URL from which it
0103came and the userlD of the intended recipient) from the external computer network 105 via the external communications interface 210, and generates a Downloadable ID for identifying
0104each Downloadable. The Downloadable ID preferably includes a digital hash of the
0105complete Downloadable code. The ID generator 315 preferably prefetches all components
0106embodied in or identified by the code for Downloadable ID generation. For example, the ID
0107generator 315 may prefetch all classes embodied in or identified by the Java™ applet bytecode to generate the Downloadable ID. Similarly, the ID generator 315 may retrieve all components listed in the .INF file for an ActiveX™ control to compute a Downloadable ID. Accordingly, the Downloadable ID for the Downloadable will be the same each time the ID generator 315 receives the same Downloadable. The ID generator 15 adds the generated Downloadable ID to the list of known Downloadables 307 (if it is not already listed). The ID generator 315 then forwards the Downloadable and Downloadable ID to the policy finder
0108317.
0109The policy finder 317 uses the userlD of the intended user and the Downloadable ID
0110to select the specific security policy 305 that shall be applied on the received Downloadable.
0111If there is a specific policy 305 that was defined for the user (or for one of its super groups) and the Downloadable, then the policy is selected. Otherwise the generic policy 305 that was defined for the user (or for one of its super groups) is selected. The policy finder 317 then sends the policy to the first comparator 320.
0112The first comparator 320 receives the Downloadable, the Downloadable ID and the security policy 305 from the policy finder 317. The first comparator 320 examines the
0113security policy 305 to determine which steps are needed for allowing the Downloadable. For
0114example, the security policy 305 may indicate that, in order to allow this Downloadable, it
0115must pass all four paths. Path 1, Path 2, Path 3 and Path 4. Alternatively, the security policy
0116305 may indicate that to allow the Downloadable, the it must pass only one of the paths. The first comparator 320 responds by forwarding the proper information to the paths identified by the security policy 305.
0117Path 1
0118In path 1, the first comparator 320 checks the policy selector 405 of the securitv
0119policy 305 that was received from the policy finder 317. If the policy selector 405 is either
0120"Allowed" or "Blocked," then the first comparator 320 forwards this result directly to the
0121logical engine 333. Otherwise, the first comparator 320 invokes the comparisons in path2 and/or path 3 and/or path 4 based on the contents of policy selector 405. It will be appreciated that the first comparator 320 itself compares the Downloadable ID against the
0122lists of Downloadables to allow or block per administrative override 425. That is, the system security administrator can define specific Downloadables as "Allowed" or "Blocked." Alternatively, the logical engine 333 may receive the results of each of the paths and
0123based on the policy selector 405 may institute the final determination whether to allow or
0124block the Downloadable. The first comparator 320 informs the logical engine 333 of the
0125results of its comparison.
0126Path 2
0127In path 2, the first comparator 320 delivers the Downloadable, the Downloadable ID and the security policy 305 to the code scanner 325. If the DSP data 310 of the received Downloadable is known, the code scanner 325 retrieves and forwards the information to the ACL comparator 330. Otherwise, the code scanner 325 resolves the DSP data 310. That is.
0128the code scanner 325 uses conventional parsing techniques to decompose the code (including
0129all prefetched components) of the Downloadable into the DSP data 310. DSP data 310
0130includes the list of all potentially hostile or suspicious computer operations that may be
0131attempted by a specific Downloadable 307, and may also include the respective arguments of these operations. For example, DSP data 310 may include a READ from a specific file, a SEND to an unresolved host, etc. The code scanner 325 may generate the DSP data 310 as a list of all operations in the Downloadable code which could ever be deemed potentially hostile and a list of all files to be accessed by the Downloadable code. It will be appreciated that the code scanner 325 may search the code for any pattern, which is undesirable or suggests that the code was written by a hacker. An Example List of Operations Deemed Potentially Hostile
0132• File operations: READ a file, WRITE a file;
0133• Network operations: LISTEN on a socket, CONNECT to a socket. SEND data, RECEIVE data, VIEW INTRANET;
0134• Registry operations: READ a registry item, WRITE a registry item:
0135• Operating system operations: EXIT WINDOWS, EXIT BROWSER. START
PROCESS/THREAD, KILL PROCESS/THREAD, CHANGE PROCESS/THREAD
0137PRIORITY, DYNAMICALLY LOAD A CLASS/LIBRARY, etc.; and
0138• Resource usage thresholds: memory, CPU, graphics, etc.
0139In the preferred embodiment, the code scanner 325 performs a full-content inspection. However, for improved speed but reduced security, the code scanner 325 may examine only a portion of the Downloadable such as the Downloadable header. The code scanner 325 then stores the DSP data into DSP data 310 (corresponding to its Downloadable I D), and sends the Downloadable, the DSP data to the ACL comparator 330 for comparison w ith th
0140security policy 305.
0141The ACL comparator 330 receives the Downloadable, the corresponding DSP data
0142and the security policy 305 from the code scanner 325, and compares the DSP data against
0143the security policy 305. That is, the ACL comparator 330 compares the DSP data of the
0144received Downloadable against the access control lists 410 in the received security policy 305. The access control list 410 contains criteria indicating whether to pass or fail the Downloadable. For example, an access control list may indicate that the Downloadable fails if the DSP data includes a WRITE command to a system file. The ACL comparator 330
0145sends its results to the logical engine 333.
0146Path 3: In path 3, the certificate scanner 340 determines whether the received Downloadable was signed by a certificate authority, such as VeriSign, Inc., and scans for a certificate embodied in the Downloadable. The certificate scanner 340 forwards the found certificate to the certificate comparator 345. The certificate comparator 345 retrieves known certificates 309 that were deemed trustworthy by the security administrator and compares the found certificate with the known certificates 309 to determine whether the Downloadable was signed by a trusted certificate. The certificate comparator 345 sends the results to the logical
0147engine 333.
0148Path 4: In path 4, the URL comparator 350 examines the URL identifying the source of the
0149Downloadable against URLs stored in the URL rule base 420 to determine whether the Downloadable comes from a trusted source. Based on the security policy 305, the URL comparator 350 may deem the Downloadable suspicious if the Downloadable comes from an
0150untrustworthy source or if the Downloadable did not come from a trusted source. For example, if the Downloadable comes from a known hacker, then the Downloadable may be
0151deemed suspicious and presumed hostile. The URL comparator 350 sends its results to the
0152logical engine 333. The logical engine 333 examines the results of each of the paths and the policy selector 405 in the security policy 305 to determine whether to allow or block the Downloadable. The policy selector 405 includes a logical expression of the results received from each of the paths. For example, the logical engine 333 may block a Downloadable if it
0153fails any one of the paths, i.e., if the Downloadable is known hostile (Path 1), if the
0154Downloadable may request suspicious operations (Path 2), if the Downloadable was not
0155signed by a trusted certificate authority (Path 3), or if the Downloadable did came from an
0156untrustworthy source (Path 4). The logical engine 333 may apply other logical expressions according to the policy selector 405 embodied in the security policy 305. If the policy selector 405 indicates that the Downloadable may pass, then the logical engine 333 passes the Downloadable to its intended recipient. Otherwise, if the policy selector 405 indicates
0157that the Downloadable should be blocked, then the logical engine 333 forwards a non-hostile Downloadable to the intended recipient to inform the user that internal network security
0158system 1 10 discarded the original Downloadable. Further, the logical engine 333 forwards a
0159status report to the record-keeping engine 335, which stores the reports in event log 245 in
0160the data storage device 230 for subsequent review, for example, by the MIS director.
0161FIG. 5 is a block diagram illustrating details of the security management console 120, which includes a security policy editor 505 coupled to the communications channel 135, an event log analysis engine 510 coupled between communications channel 135 and a user notification engine 515, and a Downloadable database review engine 520 coupled to the communications channel 135. The security management console 120 further includes computer components similar to the computer components illustrated in FIG. 2. The security policy editor 505 uses an I/O interface similar to I/O interface 215 for
0162enabling authorized user modification of the security policies 305. That is, the security policy editor 505 enables the authorized user to modify specific security policies 305 corresponding to the users 260, the default or generic security policy 305, the Downloadables to block per administrative override, the Downloadables to allow per administrative override, the trusted certificate lists 415, the policy selectors 405, the access
0163control lists 410, the URLs in the URL rule bases 420, etc. For example, if the authorized
0164user learns of a new hostile Downloadable, then the user can add the Downloadable to the
0165Downloadables to block per system override.
0166The event log analysis engine 510 examines the status reports contained in the event
0167log 245 stored in the data storage device 230. The event log analysis engine 510 determines whether notification of the user (e.g., the security system manager or MIS director) is warranted. For example, the event log analysis engine 510 may warrant user notification whenever ten (10) suspicious Downloadables have been discarded by internal network
0168security system 1 10 within a thirty (30) minute period, thereby flagging a potential imminent security threat. Accordingly, the event log analysis engine 510 instructs the user notification
0169engine 515 to inform the user. The user notification engine 515 may send an e-mail via
0170internal communications interface 220 or via external communications interface 210 to the
0171user, or may display a message on the user's display device (not shown).
0172FIG. 6A is a flowchart illustrating a method 600 for protecting an internal computer network 115 from suspicious Downloadables. Method 600 begins with the ID generator 315 in step 602 receiving a Downloadable. The ID generator 315 in step 604 generates a Downloadable ID identifying the received Downloadable, preferably, by generating a digital hash of the Downloadable code (including prefetched components). The policy finder 317 in
0173step 606 finds the appropriate security policy 305 corresponding to the userlD specifying
0174intended recipient (or the group to which the intended recipient belongs) and the
0175Downloadable. The selected security policy 305 may be the default security policy 305. Step 606 is described in greater detail below with reference to FIG. 6B.
0176The first comparator 320 in step 608 examines the lists of Downloadables to allow or to block per administrative override 425 against the Downloadable ID of the incoming Downloadable to determine whether to allow the Downloadable automatically. If so. then in step 612 the first comparator 320 sends the results to the logical engine 333. If not. then the
0177method 600 proceeds to step 610. In step 610, the first comparator 620 examines the lists of
0178Downloadables to block per administrative override 425 against the Downloadable ID of the
0179incoming Downloadable for determining whether to block the Downloadable automatically.
0180If so, then the first comparator 420 in step 612 sends the results to the logical engine 333. Otherwise, method 600 proceeds to step 614. In step 614, the first comparator 320 determines whether the security policy 305 indicates that the Downloadable should be tested according to Path 4. If not, then method 600 jumps to step 618. If so, then the URL comparator 350 in step 616 compares the URL embodied in the incoming Downloadable against the URLs of the URL rules bases 420. and
0181then method 600 proceeds to step 618.
0182In step 618, the first comparator 320 determines whether the security policy 305
0183indicates that the Downloadable should be tested according to Path 2. If not, then method
0184600 jumps to step 620. Otherwise, the code scanner 235 in step 626 examines the DSP data
0185310 based on the Downloadable ID of the incoming Downloadable to determine whether the Downloadable has been previously decomposed. If so, then method 600 jumps to step 630. Otherwise, the code scanner 325 in step 628 decomposes the Downloadable into DSP data Downloadable decomposition is described in greater detail with reference to FIG 7 In step 630, the ACL comparator 330 compares the DSP data of the incoming Downloadable against
0186the access control lists 410 (which include the criteria necessary for the Downloadable to fail
0187or pass the test).
0188In step 620, the first comparator 320 determines whether the security policy 305
0189indicates that the Downloadable should be tested according to Path 3. If not, then method 600 returns to step 612 to send the results of each of the test performed to the logical engine 333. Otherwise, the certificate scanner 622 in step 622 scans the Downloadable for an embodied certificate. The certificate comparator 345 in step 624 retrieves trusted certificates
0190from the trusted certificate lists (TCL) 415 and compares the embodied certificate with the trusted certificates to determine whether the Downloadable has been signed by a trusted
0191source. Method 600 then proceeds to step 612 by the certificate scanner 345 sending the
0192results of each of the paths taken to the logical engine 333. The operations of the logical
0193engine 333 are described in greater detail below with reference to FIG. 6C. Method 600 then
0194ends.
0195One skilled in the art will recognize that the tests may be performed in a different order, and that each of the tests need not be performed. Further, one skilled in the art will recognize that, although path 1 is described in FIG. 6A as an automatic allowance or blocking, the results of Path 1 may be another predicate to be applied by the logical engine 333. Further, although the tests are shown serially in FIG. 6A, the tests may be performed in
0196parallel as illustrated in FIG. 3. FIG. 6B is a flowchart illustrating details of step 606 of FIG. 6A (referred to herein as method 606). Method 606 begins with the policy finder 317 in step 650 determining whether security policies 305 include a specific security policy corresponding to the userlD and the Downloadable. If so, then the policy finder 317 in step 654 fetches the
0197corresponding specific policy 305. If not, then the policy finder 317 in step 652 fetches the default or generic security policy 305 corresponding to the userlD. Method 606 then ends.
0198FIG. 6C is a flowchart illustrating details of a method 655 for determining whether to
0199allow or to block the incoming Downloadable. Method 655 begins with the logical engine
0200333 in step 660 receiving the results from the first comparator 320, from the ACL comparator 330, from the certificate comparator 345 and from the URL comparator 350. The logical engine 333 in step 662 compares the results with the policy selector 405 embodied in the security policy 305, and in step 664 determines whether the policy selector 405 confirms the pass. For example, the policy selector 405 may indicate that the logical engine 333 pass the Downloadable if it passes one of the tests of Path 1 , Path 2, Path 3 and Path 4. If the policy selector 405 indicates that the Downloadable should pass, then the
0201logical engine 333 in step 666 passes the Downloadable to the intended recipient. In step
0202668, the logical engine 333 sends the results to the record-keeping engine 335, which in turn
0203stores the results in the event log 245 for future review. Method 655 then ends. Otherwise,
0204if the policy selector 405 in step 664 indicates that the Downloadable should not pass, then the logical engine 333 in step 670 stops the Downloadable and in step 672 sends a non- hostile substitute Downloadable to inform the user that the incoming Downloadable has been blocked. Method 655 then jumps to step 668. FIG. 7 is a flowchart illustrating details of step 628 of FIG. 6A (referred to herein as
0205method 628) for decomposing a Downloadable into DSP data 310. Method 628 begins in
0206step 705 with the code scanner 325 disassembling the machine code of the Downloadable. The code scanner 325 in step 710 resolves a respective command in the machine code, and in step 715 determines whether the resolved command is suspicious (e.g., whether the command is one of the operations identified in the list described above with reference to FIG. 3). If not, then the code scanner 325 in step 725 determines whether it has completed decomposition of the Downloadable, i.e., whether all operations in the Downloadable code have been resolved. If so, then method 628 ends. Otherwise, method 628 returns to step
0207710.
0208Otherwise, if the code scanner 325 in step 715determines that the resolved command
0209is suspect, then the code scanner 325 in step 720 decodes and registers the suspicious
0210command and its command parameters as DSP data 310. The code scanner 325 in step 720 registers the commands and command parameters into a format based on command class (e.g., file operations, network operations, registry operations, operating system operations, resource usage thresholds). Method 628 then jumps to step 725.
0211FIG. 8 is a flowchart illustrating a method 800 for generating a Downloadable ID for
0212identifying a Downloadable. Method 800 begins with the ID generator 315 in step 810
0213receiving a Downloadable from the external computer network 105. The ID generator 315 in
0214step 820 may fetch some or all components referenced in the Downloadable code, and in
0215step 830 includes the fetched components in the Downloadable code. The ID generator 315
0216in step 840 performs a hashing function on at least a portion of the Downloadable code to generate a Downloadable ID. The ID generator 315 in step 850 stores the generated Downloadable ID in the security database 240 as a reference to the DSP data 3 10.
0217Accordingly, the Downloadable ID will be the same for the identical Downloadable each
0218time it is encountered.
0219The foregoing description of the preferred embodiments of the invention is by way of
0220example only, and other variations of the above-described embodiments and methods are
0221provided by the present invention. For example, although the invention has been described
0222in a system for protecting an internal computer network, the invention can be embodied in a
0223system for protecting an individual computer. Components of this invention may be
0224implemented using a programmed general purpose digital computer, using application
0225specific integrated circuits, or using a network of interconnected conventional components
0226and circuits. The embodiments described herein have been presented for purposes of
0227illustration and are not intended to be exhaustive or limiting. Many variations and
0228modifications are possible in light of the foregoing teaching. The system is limited only by
0229the following claims.
Contents5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP3289510A4 | Cited by | European Patent Office (EPO) | Search report |
| US10256979B2 | Cited by | United States of America | Applicant |
| US12081540B2 | Cited by | United States of America | Applicant |
| US12120519B2 | Cited by | United States of America | Applicant |
| US9489515B2 | Cited by | United States of America | Applicant |
| US11038876B2 | Cited by | United States of America | Applicant |
| US11259183B2 | Cited by | United States of America | Applicant |
| US10419222B2 | Cited by | United States of America | Applicant |
| US8914879B2 | Cited by | United States of America | Applicant |
| US11336458B2 | Cited by | United States of America | Applicant |
| US10540494B2 | Cited by | United States of America | Applicant |
| US5412717A | Cites | United States of America | Search report |
58 members in 9 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| P30639 | United States of America | – | |
| 3063996 | United States of America | P | |
| 9701626 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 96438897 | United States of America | A |
Members58
| Document | Office | Kind | |
|---|---|---|---|
| CA2275771A1 | Canada | A1 | |
| WO9821683A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9821683A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO9935583A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9935583A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0965094A2This record | European Patent Office (EPO) | A2 | |
| US6092194A | United States of America | A | |
| US6154844A | United States of America | A | |
| US6167520A | United States of America | A | |
| WO0188673A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU7440601A | Australia | A | |
| US2002013910A1 | United States of America | A1 | |
| JP2002514326A | Japan | A | |
| US6480962B1 | United States of America | B1 | |
| WO0188673A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US6804780B1 | United States of America | B1 | |
| EP0965094A4 | European Patent Office (EPO) | A4 | |
| US2005005107A1 | United States of America | A1 | |
| US2005108554A1 | United States of America | A1 | |
| US2005240999A1 | United States of America | A1 | |
| US2006026677A1 | United States of America | A1 | |
| CA2578792A1 | Canada | A1 | |
| CA2842218A1 | Canada | A1 | |
| WO2006025050A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006025050A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US7058822B2 | United States of America | B2 | |
| US2006149968A1 | United States of America | A1 | |
| EP1810152A2 | European Patent Office (EPO) | A2 | |
| JP3952315B2 | Japan | B2 | |
| US7418731B2 | United States of America | B2 | |
| EP0965094B1 | European Patent Office (EPO) | B1 | |
| CA2275771C | Canada | C | |
| ATE409920T1 | Austria | T1 | |
| DE69739021D1 | Germany | D1 | |
| IL147712A | Israel | A | |
| US7613926B2 | United States of America | B2 | |
| US7647633B2 | United States of America | B2 | |
| IL190518A | Israel | A | |
| US7975305B2 | United States of America | B2 | |
| US8079086B1 | United States of America | B1 | |
| US2012117651A1 | United States of America | A1 | |
| US8225408B2 | United States of America | B2 | |
| IL181611A | Israel | A | |
| EP1810152A4 | European Patent Office (EPO) | A4 | |
| US8677494B2 | United States of America | B2 | |
| US2014143827A1 | United States of America | A1 | |
| US2015169870A1 | United States of America | A1 | |
| US2015180885A1 | United States of America | A1 | |
| US9141786B2 | United States of America | B2 | |
| US2015288720A1 | United States of America | A1 | |
| US9189621B2 | United States of America | B2 | |
| US9219755B2 | United States of America | B2 | |
| US2016070907A1 | United States of America | A1 | |
| US9444844B2 | United States of America | B2 | |
| EP1810152B1 | European Patent Office (EPO) | B1 | |
| CA2578792C | Canada | C | |
| CA2842218C | Canada | C | |
| US10552603B2 | United States of America | B2 |
60 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Withdrawal/refusal of revocation action now finalR040 | R040 | DE | |
| Case pending at federal patent courtR008 | R008 | DE | |
| Revocation action filedR039 | R039 | DE | |
| Withdrawal/refusal of revocation action now finalR040 | R040 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Withdrawal/refusal of revocation action now finalR040 | R040 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Patent expired because of reaching the maximum lifetime of a patentExpiredMK | MK | NL | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Case pending at federal patent courtR008 | R008 | DE | |
| Revocation action filedR039 | R039 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20100114 AND 20100120732E | 732E | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Supplementary search report drawn up and despatchedA4 | A4 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0965094
- Application
- 979503510
Titles3
- English
- SYSTEM AND METHOD FOR PROTECTING A COMPUTER AND A NETWORK FROM HOSTILE DOWNLOADABLES
- French
- SYSTEME ET PROCEDE POUR PROTEGER UN ORDINATEUR ET UN RESEAU CONTRE DES PROGRAMMES D'APPLICATION TELECHARGEABLES HOSTILES
- German
- SYSTEM UND VERFAHREN ZUM SCHUTZ EINES COMPUTERS UND EINES NETZES GEGEN FEINDLICHE HERUNTERLADBARE PROGRAMME
Classification
- CPC, 6
- H04L63/145
- G06F21/51
- G06F21/53
- G06F2211/009
- G06F2221/2119
- G06F2221/2141
- IPC, 10
- G06F21 22
- G06F1 00
- G06F13 00
- G06F21 00
- H04L29 06
- G06F19 00
- G06F9 44
- G06F15 18
- G06F21 51
- G06F21 53
Designated states1
- Contracting states, 1
- Sweden