EP0965094B1

System and method for protecting a computer and a network from hostile downloadables

Abstract

A computer-based method for generating a Downloadable ID to identify a Downloadable, including obtaining a Downloadable that includes one or more references to software components required by the Downloadable, fetching at least one software component identified by the one or more references, and performing a function on the Downloadable and the fetched software components to generate a Downloadable ID. A system and a computer-readable storage medium are also described and claimed.

EP0965094B1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Expired 6 November 2017, 8.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

58 claims: 2 independent, 56 dependent

  1. 1
    A method of operating a computer system comprising an internal network security system (110) coupling at least one client computer with an external network (105), the method comprising receiving, by said internal network security system, from said external network, executable application programs, herein referred to as Downloadables (602) addressed to said client computer, checking said Downloadables and passing or discarding said Downloadables characterised in that the method includes examining said Downloadables according to a security policy defined by at least one test, the method including conducting said test, by said internal network security system, on a received Downloadable addressed to said client computer, with reference to a Downloadable security profile, herein also referred to as a DSP, comprising a list of suspicious computer operations that the received Downloadable may attempt if executed, determining, by said internal network security system, that said security policy has been violated if the Downloadable fails said test, and discarding the Downloadable and thereby preventing the Downloadable from passing to said client computer if the internal network security system determines that said security policy has been violated.
  2. 22
    The method of Claim 1, further comprising the step of comparing the Downloadable against at least one known Downloadable, by the internal network security system.
  3. 23
    The method of Claim 22, further comprising the step of including a previously received Downloadable as a known Downloadable.
  4. 28
    A computer system comprising an internal network security system (110) coupling at least one client computer with an external network (105), said internal network security system including an interface (225) for connection with a said client computer or computers and an interface (210) for connection with said external network, characterised in that said internal network system is adapted to check incoming executable application programs, herein referred to as Downloadables (602), for compliance with a security policy defined by at least one test, with reference to Downloadable security profiles, herein also referred to as DSPs, for said Downloadables, each DSP comprising a list of suspicious computer operations that the respective Downloadable may attempt if executed, the system including a comparator (320) adapted for conducting said test by comparing said list with the security policy, the system including a logical engine which is adapted to determine, if a Downloadable has failed said test, that the security policy has been violated and is adapted to discard the Downloadable and thus prevent it from passing to a said client computer to which it is addressed.