EP2447876A2

System and method for server-based antivirus scan of data downloaded from a network

Abstract

Aspect of the invention are directed to antivirus scanning, by a proxy server, of data downloaded from the network onto a PC workstation. The antivirus scanning is optimized for each scan by selecting an algorithm for that scan based on a determined overall likelihood that the downloaded data contains malicious code. Determination of the overall likelihood is augmented by the strength, or confidence, of statistical data relating to malware screening of results of previous downloads having similar parameters to the instant download.

EP2447876A2, drawing sheet 1
Sheet 1 of 8

Term

4.8 yearsto projected expiry

Projected expiry 20 July 2031, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 2 independent, 13 dependent

  1. 1
    A method for antivirus scanning on a proxy server (102) of data downloaded to a destination computer (101), the method comprising the steps of:- determining parameters of the downloaded data, comparing the parameters with rules for these parameters, and evaluating the level of overall risk probability whether the downloaded data contain a malicious program code;- determining the depth of the antivirus scanning depending on the overall risk probability whether the downloaded data contain a malicious program code, wherein the depth of the antivirus scanning depends on which types of data analysis are used for detecting the presence of a malicious program code and in which combination;- performing the antivirus scanning in accordance with the determined depth of the antivirus scanning and the level of the overall risk probability whether the downloaded data contain a malicious program code;- curing the data containing the malicious program code in case of detection of a malicious program code;- transmitting the data to the destination computer (101) in case a malicious program code is not detected in the downloaded data, or in case the curing of the malicious program code was successful.
  2. 3
    The method of claims 1 or 2, wherein the rules for the parameters of the downloaded data is the information stored in a database (203), which determines for any value of each parameter of the downloaded data the probability that the downloaded data contain malicious program code.
  3. 8
    The method of claims 5 to 7, wherein the depth of the antivirus scanning is maximum in case of a high level of the overall risk probability whether the downloaded data contain a malicious program code.
  4. 9
    The method of claims 7 or 8, wherein the low level of the overall risk probability whether the downloaded data contain a malicious program code is divided into sublevels, wherein the depth of the antivirus scanning varies from each sublevel to an other in case of a low level of the overall risk probability whether the downloaded data contain a malicious program code.
  5. 10
    The method of any of claims 5 to 9, wherein, if a malicious program code is detected in case of a low level of the overall risk probability whether the downloaded data contain a malicious program code, the rules forming the value of the overall risk probability are corrected.
  6. 12
    A system for antivirus scanning on a proxy server (102) of data downloaded from a data server (104) upon request from a destination computer (101), the system comprising a data analysis module (204) being connected to a database (203) of a proxy server (102), an antivirus module (202) and a cache (206), and designed to determine parameters of data downloaded on the destination computer (101) from the data server (104), to compare the parameters with rules for these parameters from the database (203) of the proxy server (102), and to evaluate the overall risk probability whether the downloaded data contain a malicious program code, wherein said level is determined as high or low depending on whether a predetermined value of the overall risk level is exceeded or not; wherein the data analysis module (204), in case of a high level of the overall risk probability whether the downloaded data contain a malicious program code, is designed to forward the downloaded data to the cache (206) and to transmit the information about the high level of the overall risk probability whether the downloaded data contain a malicious program code, as well as the information that data are downloaded from the data server (104) to the cache (206) to the antivirus module (202); wherein the data analysis module (204), in case of a low level of the overall risk probability whether the downloaded data contain a malicious program code, is designed to forward the downloaded data to the antivirus module (202); wherein the database (203) of the proxy server (102) is connected to the antivirus module (202) and to the data analysis module (204), and comprises rules for determining the probability whether the downloaded data contain a malicious program code depending on the parameters of data downloaded on the destination computer (101) from a data server (104), as well as rules for determining the depth of the antivirus scanning depending on the level of the overall risk probability whether the downloaded data contain a malicious program code, wherein the system further comprises - a data reception module (201a) being designed to obtain a data to be received from the data server (104) in response to a request by the destination computer (101) and - a data transmission module (201b) being designed to transmit to the destination computer (101) the downloaded data after the antivirus scanning in case of a high level of the overall risk probability that the downloaded data contain a malicious program code, and transmit to the destination computer (101) the downloaded data during the antivirus scanning in case of a low level of the overall risk probability that the downloaded data contain a malicious program code. wherein the cache (206) is designed to receive data downloaded from the data server (104) in case of a high level of the overall risk probability whether the downloaded data contain a malicious program code, wherein the cache (206) is also connected to the antivirus module (202) and to the data transmission module (201b) and is designed to transmit data for the antivirus scanning to the antivirus module (202) and to transmit the data after the antivirus scanning to the data transmission module (201b); wherein the antivirus module (202) is connected to the cache (206), the data transmission module (201b) and the database (203) of the proxy server (102), characterized in that the antivirus module (202) is designed for:● antivirus scanning of the data contained in the cache (206) in case of a high level of the overall risk probability that the downloaded data contain a malicious program code, ● as well as for antivirus scanning of the data transmitted by the data analysis module (204), and for transmitting the data by portions in the coarse of the scanning to the data transmission module (201b) in case of a low level of the overall risk probability that the downloaded data contain a malicious program code;
  7. 15
    The system according to one of the claims 12 to 14, designed to determine the overall risk probability that the downloaded data contain a malicious program code by using the probability that the downloaded data contain a malicious program code for each parameter of the downloaded data.