Look ahead malware scanning
Abstract
The invention relates to a method of scanning for malware detection during execution of an application on a computer system. According to the invention, the method comprises the detection of access to files within a common directory, the use of the detected accesses to identify one or more groups of files within the common directory that the application may subsequently want to access and scanning the one or more groups of files for malware detection, prior to the application attempting to access files of the said group or groups.

Term
5.5 yearsto projected expiry
Projected expiry 29 March 2032, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
22 claims: 7 independent, 15 dependent
- 1Revendicări claims 1. Browsing method for malicious software during the execution of an application on a computer system, the method comprising:1. Metodă de explorare pentru software rău intenționat în timpul execuției unei aplicații pe un sistem de calculator, metoda cuprinzând: detectarea accesărilor de către aplicație a fișierelor din cadrul unui director comun;detecting accesses by the application of files within a common directory;using detected accesses to identify one or more groups of files within the shared directory that the application may subsequently want to access;and exploring one or more groups of files for malicious software before the application tries to access the files of the group or groups. utilizarea accesărilor detectate pentru a identifica unul sau mai multe grupuri de fișiere din cadrul directorului comun pe care aplicația poate ulterior dori să le acceseze;și explorarea acelui unul sau mai multe grupuri de fișiere, pentru software rău intenționat înainte ca aplicația să încerce să acceseze fișierele grupului sau grupurilor.
- 8The method according to claims 6 or 7, wherein the use of detected accesses to identify one or more file groups includes the step of adding the current file detected as being accessed by the application to a file group when the scan step is triggered. . 8. Metodă în conformitate cu revendicările 6 sau 7, în care utilizarea accesărilor detectate pentru a identifica unul sau mai multe grupuri de fișiere include pasul de adăugare a fișierului curent detectat ca fiind accesat de către aplicație la un grup de fișiere atunci când pasul de explorare este declanșat.
- 10A method according to claims 6 to 9, wherein the scanning step of one or more file groups includes the scanning completion step of the group or groups when a second period of time has elapsed after the scanning step has been triggered. . 10. Metodă în conformitate cu revendicările de la 6 la 9, în care pasul de explorare a unuia sau mai multor grupuri de fișiere include pasul de terminare a explorării grupului sau grupurilor atunci când o a doua perioadă de timp a trecut după ce pasul de explorare a fost declanșat.
- 13The method according to claims 11 or 12, wherein the files within the file group or groups are files within the common directory that require exploration. 13. Metodă în conformitate cu revendicările 11 sau 12, în care fișierele din cadrul grupului sau grupurilor de fișiere sunt fișiere din cadrul directorului comun care necesită explorare.
- 17Computer program for exploring malicious software while running an application on a computer system that includes computer program code means adapted to perform the following steps:17. Program de calculator pentru explorarea software-ului rău intenționat în timpul execuției unei aplicații pe un sistem de calculator care cuprinde mijloace de cod de program de calculator adaptate pentru a efectua pașii următori: detecting accesses by the application to files in the shared directory;detecția accesărilor de către aplicație la fișiere din cadrul directorului comun;using the detected accesses to identify one or more groups of files within the said shared directory that the application may subsequently wish to access;and training to explore that file group (s) for malicious software before the application tries to access group files or groups. utilizarea accesărilor detectate pentru a identifica unul sau mai multe grupuri de fișiere în cadrul directorului comun menționat pe care aplicația poate ulterior să dorească să le acceseze;și instruirea explorării acelui unul sau mai multor grupuri de fișiere menționate pentru software rău intenționat înainte ca aplicația să încerce să acceseze fișiere ale grupului sau grupurilor. 2 C 1 3 'J Ο 8 4 C - 2 9 Ό3- 2913 * 2 C 1 3 ' J Ο 8 4 C - 2 9 Ό3- 2913 *
- 20Computer system configured to scan files for malicious software while running an application on a processor, the computer system comprising:20. Sistem de calculator configurat pentru a explora fișiere pentru software rău intenționat în timpul execuției unei aplicații pe un procesor, sistemul de calculator cuprinzând: a detection unit for the application access detection of files within a shared directory, and the use of the detected accesses to identify one or more groups of files within the said shared directory that the application may subsequently wish to access, and training a scanning unit to scan one or more groups of files for malicious software before the application attempts to access the files of the group or groups. o unitate de detecție pentru detecția accesărilor de către aplicație a fișierelor din cadrul unui director comun, și utilizarea accesărilor detectate pentru a identifica unul sau mai multe grupuri de fișiere din cadrul directorului comun menționat pe care aplicația ar putea dori ulterior să le acceseze, și instruirea unei unități de explorare pentru explorarea unuia sau mai multor grupuri de fișiere menționate pentru software rău intenționat înainte ca aplicația să încerce să acceseze fișierele grupului sau grupurilor.
Independent claims7
150 paragraphs, as filed
Technical field
The present invention relates to a method and apparatus for performing malware scanning (malware). In particular, the present invention relates to a method and apparatus for optimizing the performance of a computer system that performs scanning for malicious software on a group of files.
Background of the Invention The term Malware is an abbreviation for malicious software and is used as a term to refer to any software designed to infiltrate or damage a computer system without the informed consent of cause of the owner. Malicious software may include computer viruses, worms, Trojan horses, root kits, rootkits, advertising software. adware), spyware and any other types of malicious or unwanted software.
Many end-users use anti-virus software to detect, and possibly remove, malicious software. In order to detect a malicious software file, anti-virus software must have a way to identify it from all other files present on a device. Typically, this requires the aniti-virus software to have a database containing "signatures" or "fingerprints" that are a feature of individual malicious software program files. When an anti-virus software vendor identifies a new malicious software threat, the threat is analyzed and its signature generated. Malicious software is then "known" and its signature may be distributed to end users as updates to their local anti-virus software databases.
σ-2 Ο 1 3 0 0 8 4 8--
9 -03- 2013
Anti-virus software typically provides on-demand file exploration in which the user of a computer system determines when files on the computer system should be scanned for the presence of malicious software. In on-demand scanning, the user can manually activate the scanning process, or configure the scanning process to begin under certain circumstances. For example, the user could configure anti-virus software to scan folders or folders (these terms will be used interchangeably) once a week, and to browse all files on a system. computer once a month. Additionally, anti-virus software can also provide real-time protection against malicious software by performing scanning for access.
In access exploration, a computer system is monitored for the presence of malicious software by automatically scanning files in the background when file access is detected by one or more applications running on the computer system. The most common method of accessing the file is read-only file access. This type of access is common for multiple file operations, such as searching for / in files, starting and running an application, copying files from file to folder (directory to directory), compressing files, etc. . The following examples further illustrate some of these common operations.
Example 1, copy command:
C: \> copy source \ *. * d: \ dest
This command (application) could be represented by the following pseudo code:
for each file in c: \ source \ *. * opens read only current file (c: \ source \ ...)
Ο ο 8 4 C -2 9 -03- ag read data from file close file save data to d: \ dest \
The copy command generates access for continuous and sequential read only for all source files.
Example 2, an application that runs on multiple module files:
It is assumed that the application consists of a single executable (-EXE) and a number of modules such as dynamically linked libraries (dynamic linked libraries .DLL). When a user launches the application, the application loads the required libraries and then starts running. This operation could be represented by the following pseudo-code:
for application.exe, module1.dll, module2.dll files ... moduleN.dll opens read-only file for current file uploads data from file
The application generates file-opening accesses only for continuous and sequential reads for the relevant source files in the application and / or relevant mode directories.
Similar file-opening access templates for continuous and sequential multi-file read-only from a given directory can be found in other commands or applications, such as searching for a template in a file collection (grep.exe or findstr.exe ), calculating a string of compression bytes (hash) over files (md5.exe), packing in a container (rar.exe or winzip.exe) and so on.
Figure 1 illustrates a common interaction between an application and anti-virus software when the application performs file-opening access for multiple file read-only. During the operation only when the anti-virus software detects the application's access to files it performs file access scanning.
(Ț- 2 Ο 1 3 OO 8 4 C - l S -13- 2013
<img file="RO130379A2_D0001.tif" />
In particular, when the application tries to open a file, the request for opening is intercepted by a filter that generates a scan request for use by the anti-virus software and prevents its application from opening and using the file. Upon receiving the scan request, the anti-virus software scans the file and generates a result in the usual way. Depending on the result, the file access is returned to the application for use, for example, reading, copying, or executing the file. However, if multiple files need to be accessed by the application, this operation will be repeated sequentially for each subsequent file access by the application as shown in Figure 1. This is a very slow and laborious process, which impacts the performance of the application and the computer system.
Most modern computer systems are now optimized for multiple task execution. A typical CPU often includes multiple kernel support (multiple threads), which effectively allows application tasks to run as if they were appearing simultaneously. An execution thread (a thread) is defined as the smallest processing unit (for example, a task or a portion of a task) that can be planned by an operating system. Multiple thread execution refers to an application that has multiple threads in which the threads are planned to be executed by one operating system at the same time. INTEL ™ article, "Predicting and Measuring Parallel Performance", March 9, 2010, available from http://software.intel.com/en-us/articles/predictinq-andmeasurinq-parallel -performance /, described the development of parallel software by applications with multiple threads to terminate them to process a given data set in less time, or to process multiple data sets in a fixed time.
A single processor can perform multiple threads by multiplying by time division of the threads (ie, multiple threads) so that the processor switches context between different threads. This context switching happens so frequently that the user perceives the threads or tasks as if they were executed in
F-2013 00048-2 9 -03- 2013 simultaneously or in parallel. On a multiple processor or multiple core system, some of the threads or tasks actually execute at the same time (depending on the number of processors), with each processor or core executing a particular thread or task. In order to achieve maximum performance, applications, when executed on the computer system, should try to parallel their complex equations or tasks.
Parallel scanning of files for malicious software with anti-virus software can be accomplished by simultaneously scheduling one or more threads to handle the process of scanning each of the files. As mentioned above, the operating system manages the execution of wires on a multi-tasking computer and / or multiple cores. Parallel scanning can be performed on multiple files in a crawl queue to increase the performance of the computer system. Queuing files accessed for malicious software exploration can use the power of parallel scanning. Such exploration could be performed by asynchronous shutdown methods. But, even with multiple kernel support, parallel scanning for access to multiple files for malicious software during file-only access to read by an application is problematic. Organizing files in queues for later parallel or batch browsing is not an option for applications that require the read-only file access operation. This type of file access requires immediate synchronous response from the anti-virus software to allow the application to proceed as quickly as possible. Scan requests from anti-virus filtering (specialized software for hardware access software) cannot be organized in queue for future group processing because anti-virus software does not know the next file that an application will request.
Applications can generate file-opening requests for arbitrary multiple sequential read-only and typical anti-virus scan logic requires that every read-only file open request trigger an scan event or request for that file. Due to the sequential nature of access to <Α- 2 Ο 1 3 Ο Ο 8 4 C - 2 9 -03- 2013
<img file="RO130379A2_D0002.tif" />
file, the crawl logic cannot determine which files will be accessed later by the application. This does not allow anti-virus software to take advantage of performing multiple or parallel file scanning on modern computer systems. This means that the application will need to either wait until the scan for malicious software finishes on all the files before it starts, or be interrupted during runtime while every file that needs to be accessed is crawled. Both scenarios significantly damage the performance of the application and the computer system.
The synchronous process of access scanning blocks an application from starting or stopping the execution of the application until a malicious software scan for all files or for each file has been performed. Thus, antivirus software prevents the execution of the application to progress, slowing down the rate at which it can perform its tasks. This impacts the performance of the computer system.
Summary
It is an object of the present invention to provide a method for performing malicious software scanning that minimizes the delays introduced by scanning during application execution on a computer system, thus optimizing the performance of the computer system.
According to a first aspect of the invention, a malicious software exploration method is provided while executing an application on a computer system, the method comprising detecting file access by the application within a common directory, using the accesses detected to identify one or more file groups within the said shared directory that the application can subsequently access, and exploring one or more of the groups of files mentioned for malicious software before the application tries to access the files of the group or groups.
C \ -2 Ο 1 3 0 0 8 4 0-l 9 -93- 3013
The embodiments of the invention provide that anti-virus software can perform the exploitation of a group from the multitude of files without the need to completely block the execution of the application before using one or more files in the group.
As an option, it additionally includes the selection of the file group or groups based on the file types of the files accessed by the application. The file selection preferably includes matching file types of files accessed by the application with file types of files within the shared directory. Preferably, files within the file group or groups are files that require exploration. The optional method further comprises identifying one or more groups of files by adding the current detected file to be accessed by the application to the file group for scanning when the current file requires scanning.
The method optionally includes the use of detected hits including the step of determining the number of hits accessed within the shared directory and using the results to trigger the group scan step, which are one or more. Preferably, the crawl step is triggered when the number of hits accessed reaches a predetermined threshold. Optionally, using detected accesses to identify one or more file groups includes the step of adding the current detected file to be accessed by the application to a file group when the scan step is triggered. Optionally, determining the number of hits accessed includes the reset step of the number of hits accessed when an initial period of time has passed and the scan step has not been triggered. Optionally, the method includes the step of completing the exploration of the group or groups when a second period of time has elapsed after the exploration step has been initiated.
The method optionally includes the fact that the step of using the detected accesses to identify one or more groups of files includes the step of maintaining a list of file types of the detected files accessed and the step of \ - 2 ο 1 3 0 O 8 4 β - 2 9 -03- 20î3
<img file="RO130379A2_D0003.tif" />
identifying one or more groups of files includes the file selection step based on the file type list. The file selection additionally includes matching the file type list of files accessed by the application with the file types of the files in the shared directory.
As an option, the application access detection step to files in the shared directory includes receiving an exploration request to explore a file accessed by the application in the shared directory. Optionally, the application access detection step to files in the shared directory includes the application's file access detection and generating an exploration request for file exploration when scanning is required.
According to a second aspect of the present invention, a computer program is provided for scanning for malicious software during the execution of an application on a computer system, the computer program comprising means of computer program code adapted to perform the following steps : detection of accesses by the application to files within a common directory;
using the detected accesses to identify one or more groups of files within the said shared directory that the application may subsequently wish to access; and training a malicious software explorer to scan one or more of the said malicious software file groups before the application attempts to access the files of the group or groups.
The computer program may further comprise means of program code adapted to scan one or more groups of files for malicious software.
In accordance with a third aspect of the present invention, a computer program is provided as outlined above embodied on a computer readable medium.
<img file="RO130379A2_D0004.tif" />
2- 2 Ο 1 3 0 0 8 4 C - 2 9 -03- 20J3 In accordance with a fourth aspect of the invention, a computer system is provided configured to explore files for malicious software during the execution of an application on a processor. , the computer system comprising a detection unit for the application access detection to files within a common directory, and using the detected accesses to identify one or more groups of files within the said shared directory that the application may subsequently want to access, and training an exploration unit to scan one or more of the mentioned groups of files for malicious software intentionally before the application tries to access the files of the group or groups. The computer system may additionally include an exploration unit for performing file group scanning, which is one or more.
Brief Description of the Drawings
Figure 1 is a diagram illustrating a process from the state of the art of performing malicious software access exploration;
Figure 2 schematically illustrates a computer system according to concrete applications of the present invention;
Figure 3 is a diagram illustrating a process of performing malicious software access exploration according to a particular application of the present invention;
Figure 4 is a flow chart illustrating a process according to a particular embodiment of the present invention;
Figure 5 illustrates a directory access table for use in updating and maintaining directories accessed by applications in accordance with concrete applications of the present invention;
Figure 6 is a Flowchart illustrating a process of performing malicious software access exploration for an application that accesses files in accordance with a particular application of the present invention.
tV 2 ο 1 3 0 O 8 4 C - 2 9 -03- 2013
Figure 7 is a flow chart illustrating a malicious software exploration process for accessing an application that accesses files in accordance with another embodiment of the present invention.
Detailed description
In order to overcome at least partially the problems described above, it is proposed here to improve the performance of a computer system by performing malicious software exploration to access in batch or in parallel multiple files before an application uses one of the multiple files. This means that the execution of the application is not completely blocked in subsequent file accesses. As described above, batch or parallel scanning is the simultaneous scheduling of a group of files for scanning by a computer system. For example, simultaneous scheduling of multiple scan threads, one thread per file in the group, for execution on the computer system.
This type of scanning is accomplished by detecting the application's access to files within a shared directory, using the detected accesses to identify one or more groups of files within the said shared directory that the application may subsequently want to access, browsing. to one or more of the groups of malicious software files mentioned before the application tries to access the group or groups files. After exploring a file group, a subsequent file group can be identified and / or explored.
By performing batch or parallel file group scanning that the application can use, the chances of the application being blocked or continually interrupted by malicious software exploration is minimized. This is because the application can access and use the crawled files in a group, which now does not require crawling. In fact, if the correct file group is identified for each scan, there will be only a delay of a file scan and then the execution of the application should not be blocked by any bad software scan ^ - 2 0 1 3 0 0 0 4 C "
9 -03- 2013 intentionally additional when the application accesses the scanned files. This type of scanning in batch or parallel minimizes the delay introduced by malicious software access access, thus optimizing the performance of the computer system.
Figure 2 schematically illustrates a computer system 1 and a remote computer system 12 according to embodiments of the present invention. Computer system 1 can be implemented as a combination of computer hardware and software. Computer system 1 comprises a memory 2, a cache 3, a processor 4 and a receiver-transmitter 5. The memory 2 stores all the files needed for the computer system 1. The files stored in memory 2 include the various executable programs / files that are implemented by the processor 4, as well as any data files 6. Applications / programs / executable files stored in memory 2, and implemented by processor 4, include a detection unit 7 and a malicious software scan unit 8, each of which may be sub-units of an anti-virus unit 9 which can run local anti-virus software as well as file system 10 and any other programs / applications 11. Data files 6 stored in memory 2 may include application data files, directory access tables as defined here, malicious software definition data files, files containing heuristic analysis rules, white lists, black lists , etc. Cache 3 provides a temporary storage unit for storing data that must be scanned by the malicious software explorer unit 8. Transmitter-receiver 5 can be used to communicate over an Internet / LAN or Network 13 with a remote computer system 12. The remote computer system 12 can provide data storage and application services to a computer system 1, from for example, the remote computer system 12 may be an application server that provides Software as a Service (SaaS) applications to the computer system user 1.
The remote computer system 12 is typically operated by a provider of various applications that are executed on the remote system 12 and used remotely by the user of the computer system 1. The remote computer system 12 c \ -2? - 3
9 -13- 'HJ can be implemented as a combination of computer hardware and software as it is for the computer system 1. The remote computer system 12 comprises a memory 14, a processor 15, and a transmitter-receiver 16. regarding the system from computer 1, memory 14 can store files that include various applications / programs / executable files that are implemented by the processor 15, as well as any data files 16. Applications / programs / executable files stored in memory 14, and implemented by the processor 15 also include a detection unit 18 and a malicious software explorer unit 19, each of which may be subunits of an anti-virus unit 20 which run local anti-virus software on remote system 12. Transmitter-receiver 16 is used to communicate with computer system 1 over network 13.
In operation, the computer system user 1 can run local applications, or can run applications on the remote computer system 12. The malicious software explorer unit 8 of the computer system 1 can be used to explore local files for malicious software from memory 2 accessed by local applications. The malicious software explorer unit 19 of the remote system 12 can be used to explore files for the malicious software in memory 14 accessed by the remote system applications 12. File exploration methods in any of these systems can be based on those according to the present invention. It should be appreciated that the embodiments of the invention, as described herein, can be implemented in standalone or network-connected computing systems through distributed computing systems where files and applications are stored and executed remotely.
In particular, computer systems 1 or 12 are configured to scan for malicious software files during the execution of an application or applications running on any of the processors 4 or 15, as appropriate. Computer systems 1 or 12 include detection units 7 or 18, as appropriate, for detecting accesses by applications to files within a common directory, and using detected accesses to identify one or more groups of files.
Ο 1 3 Ο Ο 8 4 C '2 9 -03- 2013
<img file="RO130379A2_D0005.tif" />
from said shared directory that the application may wish to access later, and training the 8 or 19 scanning units, appropriately, for scanning one or more of the mentioned file groups for malicious software before the application tries to access it group or group files. As illustrated, computer systems 1 or 12 already include scan units 8 or 19 for scanning one or more groups of files mentioned in response to training detection units 7 or 18, as appropriate. It should be appreciated that although the scanning of drives 8 or 19 is implemented within anti-virus drives 9 and 20, properly, scanning units 8 or 9 could also be deployed on other computer / server systems such that the drive Detection 7 or 18 sends instructions over network 13 to have the file groups, which are one or more, explored.
It should be appreciated that the embodiments of the invention can be used in a cloud computing or distributed computing system. For example, an application can run on the remote computer system 12 and access files from a remote data center (not shown) where file access detection is performed at the data center but malicious software is scanned at remote computer system 12. The remote computer system 12 can perform "Cloud" scanning, which is an example of providing the scanning capability for malicious software over a network or distributed computer system. To minimize the overhead involved in exploring files over a network, ie minimizing bandwidth, scanning can be limited to checking the file meta-data stored in the remote data center (remote server or backend). Meta-data could be created for each file from a string of bytes (hash) (for example sha1) calculated from the file data or from specific portions of the file data. Only meta data is uploaded and explored by the remote computer system 12 when it detects hits generated by a user application to files. The host computer system of user 1 could query the remote computer system 12 in relation to the data of the scanned file and <- 2 0 1 3 0 0 8 AC - 2 9 -03-2013
<img file="RO130379A2_D0006.tif" />
receives status based on a limited scan scan (cleanup, infected file name, and malicious software).
Concrete applications of the invention allow for parallel exploration (for example, multi-threaded exploration) on a computing system 1 or remote computing system 14 for exploration requests such as exploration requests for read-only file access. The methods described here are based on analyzing the behavior of one or more applications to find dependencies when an application generates sequential access to multiple files from a current working directory of the application or a shared directory. The term common directory refers to the same logical location in memory (for example, disk device) where one or more files are stored. Performance is optimized because applications commonly access multiple files in the same folder or directory. If the anti-virus software recognizes this type of application behavior model then it can perform an advance scan on a group of files that the application may subsequently want to access or use. The anti-virus software then performs scanning for access to multiple file groups for malicious software.
Figure 3 illustrates the process of performing malicious software exploration for batch or parallel access according to a particular application of the present invention. The anti-virus software groups multiple files together depending on the behavior of the applications that access the files and performs advanced scan on multiple file groups. The crawl results are cached and if the application accesses the crawled file in advance search it receives a cached response about the file being crawled and may continue to use the file.
In practice, normal file scanning is implemented in user mode and anti-virus software intercepts low-level file accesses by the application and sends a scan request to the user mode. This is an expensive operation and requires context switching (kernel to user mode and from q- 2 Ο 1 3 OO 8 4 C - 2 9 -03- 2013
<img file="RO130379A2_D0007.tif" />
new back). It should be appreciated that the scanning methods, as described here, reduce back-to-back calls from the application to anti-virus software, which greatly improve performance. For example, anti-virus software has a kernel filter driver that intercepts applications that try to access or open files. The kernel filter driver sends a request to the user mode to perform a scan task on the file that an application is trying to access. The scan service running in user mode performs a real malicious software scan on the file and notifies the scan results and status back to the kernel filter driver. Based on these results, the kernel filter driver allows or denies the application access to the file.
Referring to Figure 3, when the application opens the file named file, the anti-virus software intercepts the application's request to open the file 1. The anti-virus software, which has determined that a scan in parallel or in parallel is required from the behavior of the application, performs a batch or parallel scan on a file group, which may include the requested file (for example, tab, file2, and file3). Once the file, file2, and file3 have been explored the results are cached and the application can continue to open and use the file as normal. Because file2 and file3 have also been explored, when the application opens these files it receives a cache response that allows the application to open and immediately use file2 and file3 (depending on the response). In this example, batch or batch file group browsing allows the application to run without further interruption.
Although batch or parallel file group scanning can substantially improve the overall performance of an application or applications running on a computer system, performance is substantially improved if the scanned file group includes only those files that are required. for application / applications. Exploring files that are not used by one application can impact performance unless that file will be used by another application. For example, if the anti-virus software scans too many files in advance, which will not be accessible by any application, then it will only reduce overall performance. because computer resources are used to explore unnecessary files. The following embodiments of the present invention describe methods for minimizing unnecessary file scans, which maximize the performance of the application or applications and the computing system.
Figure 4 is a flow chart that further illustrates the process of scanning for malicious software while executing one or more applications on a computer system in accordance with a particular application of the present invention. The processes performed by a scanning unit or anti-virus software for each application that accesses files within a shared directory are outlined as follows:
A1. Detection of accesses by the application to files within a common directory.
A2. Using the detected accesses to identify one or more groups of files within the said shared directory that the application may later want to access.
A3. Scan one or more of the above groups of files for malicious software, before the application tries to access the files in the group or groups.
With respect to step A1, the application's access detection of files in the shared directory may include the receipt of an exploration request to explore a file accessed by the application (the current file accessed) within the shared directory. Detection of file access by the application may also include intercepting the file access made by the application and generating the scan request and sending the scan request, when scanning is requested, to the anti-virus software for scanning.
Π 1 3 C Ο θ 4 C - 2 9 -03 · 2013
<img file="RO130379A2_D0008.tif" />
Regarding step A2, using the detected accesses to identify one or more file groups may include the step of selecting the file group or groups based on the file types of the files accessed by the application. This may involve selecting files that match the file types of files accessed by the application with the file types or files in the shared directory. Additionally, files within the file group or groups can be selected from files in the common directory that require exploration. The current file detected as being accessed by the application can be added to the file group for scanning if the current file requires scanning.
In order to use the detected hits and to start exploring the group or groups of files, step A2 may include determining the number of hits accessed within the shared directory and using the results to trigger the group scan step, which are one or more. Scan triggering may occur when the number of hits accessed reaches a threshold, N. This threshold could be a predetermined threshold, or a dynamic threshold determined by the anti-virus software and its observed behavior in one or more applications that access the files in the shared directory. The current file detected for access by one or more applications can be added to the file group. This can occur before or when the scan step is triggered. The current file accessed may correspond to the file that corresponds to the received scan request. The current file is then added to the file group for scanning. The file group is scanned based on the scan request received by anti-virus for the current file. In order to avoid unnecessary crawling when applications access an uncommon directory, the number of hits detection step may include resetting the number of hits detected when an initial period has passed and the crawl step has not been triggered.
As explained below, using detected accesses to identify one or more groups of files may include maintaining a list of types of files, files, and files. accessed and the step of identifying one or more groups of files includes the file selection step based on the file type list. The file selection additionally includes matching the list of file types of files accessed by the application with the file types of files within a common directory. Anti-virus software can maintain a list for each shared directory that has files that are frequently accessed by one or more applications.
For step A3, the use of detected accesses to identify one or more file groups may include tracking the number of accesses detected and the result of triggering step A3. Triggering step A3 could occur when the number of hits accessed reaches a predetermined threshold or scan threshold. Identifying one or more groups of files for browsing may include selecting files from the shared directory based on the file types that were previously accessed or are accessed by the application. Alternatively, a selection of groups can be determined from a stored list of file types or names accessed by various applications within the common directory. Additionally, step A3 may include termination of operation after a predetermined period of time has elapsed, for example, if the directory has been frequently accessed but has not been accessed for a period of time that justifies completing the directory exploration, then exploring one or more file groups could be terminated to avoid unnecessary processing. This may occur when a second period of time has elapsed after the exploration step has been initiated.
Tracking the number of hits accessed (or the number of hits) to the shared directory helps determine whether applications are actively accessing the directory. If the directory has a sufficiently high "number of touches" due to the fact that it is accessed over a short period of time, then, for subsequent file accesses from the directory, the anti-virus software can simultaneously scan a selected file pool. from the prevalent scan file types or from the accessed file type and the current file accessed. As mentioned above, simultaneous browsing can be accomplished by simultaneously scheduling multiple scan threads for (\ -2 Ο 1 3 Ο ο 8 4 0 - 2 9 -03-2013 $ file exploration, that is, browsing in parallel or in batch. The scan is triggered once the number of hits accessed reaches a threshold.
Scan should be performed on a file group if it is detected that the current file that an application detects is an unexplored file. In this case, file access is detected or intercepted by a kernel filter driver, which generates an scan request that is received by the anti-virus software to scan the currently accessed file. Instead of scanning only the unexplored file, the anti-virus not only scans the unexplored file that was accessed, but also uploads a group or groups of files for scanning. The anti-virus software performs the scanning of the current scanning request (the scanning request for the currently accessed file) and simultaneously schedules (or executes) the scanning of multiple "back-scanned requests for files from a loaded list. The uploaded list is a list of anti-virus-generated files that can be accessed from the directory - this can include file types that are most commonly accessed. The anti-virus uploads a selection of files from the directory based on the uploaded list.
For example, if a directory (or folder) has files A, B, C, D, E, then at the time when files A and B were scanned, it may be considered that this directory was accessed frequently . If C, D, and E were placed on the uploaded list, when the scan is triggered by frequent accesses, the antivirus uploads the C, D, E files (A. B are omitted because they are already scanned). If it is detected that the C file is accessed by the application, then a scan request for the C file will be received by the anti-virus for scan, which scans the C file along with the scan of the D and E. This means that when D and E files are subsequently accessed by an application, then the scan requests for these files will not be generated by the filter driver because those files have already been scanned.
The file group or groups are files selected from the directory that the application may subsequently want to access. Exploring the group or groups "leads <Λ" 2 Ο 1 3 O 0 8 4 C - 2 9 -03- 2013 in the back "exploring the current accessed file, that is, the request for exploring the current file goes back. This prevents future exploration requests that are generated or made for the group files.
Even if some of the files selected for "back-to-back" scanning are not accessed by the application, the loss of performance in a single "back-to-back" batch is negligible due to batch or parallel scanning. When an application performs long processing (for example, copying an entire data file), this type of advanced search greatly increases overall performance. Anti-virus software estimates the multitude of files that must be accessed from the directory by selecting the most common files that applications have accessed from the directory over a particular time period. This can be done by maintaining a table at the time of executing directory visits, which depends on the behavior of the various applications that are executed.
Figure 5 is a directory access table illustrating the updating and maintenance of accesses detected by applications to files within one or more directories in accordance with concrete applications of the present invention. The directory access table can be implemented as a lookup table at run time stored in memory. The table is maintained by anti-virus software for use in determining the number of times the files in the directory are accessed.
Anti-virus software maintains the directory access table at runtime (or directory access table), which tracks file access within directories by applications. In this particular application, the directory access table has the following fields:
- The directory path, which maintains the name or logical location of the directory in which one or more files are accessed;
- The list of extensions accessed, which contains a list of file extensions of files that have been accessed and explored from the directory;
- The number of hits, which shows the number of hits to the file in the directory; and <2013 0 ^ 840-2 9 -03- 2013
<img file="RO130379A2_D0009.tif" />
- The state of the element, which defines the life cycle of the element of the director in this concrete application, the field of Element Status has 3 logical states Remarked, Collected, and Processed. The Remarked state (ie a pre-scan state) indicates that the file has been accessed in the directory but that the number of directory touches is not yet sufficient to guarantee parallel or batch exploration. Once the number of hits reaches a threshold, the Element Status of the directory is changed to the Collected state (that is, an exploration state). The Collected status means that the directory was or is actively accessed by an application, which guarantees parallel or batch exploration. Anti-virus software pre-uploads file groups with file extensions listed in the Accessed Extensions List, or file extensions of the current file that is accessed for parallel or batch scanning. The processed status means that the search in advance has already been done for the directory and the files should normally be scanned.
Each state has a validity period, after the expiry of the directory element is removed from the access table, for example if no file is accessed from a directory for a period of time, then the element is considered to be expired. The Remarked status has a short shelf life and simply serves to recognize directories that can be accessed frequently. The Collected and Processed states have longer validity periods due to the frequency of accesses and to avoid unnecessary re-exploration of the files accessed from the directory. It should be appreciated that these periods can be varied by anti-virus software based on any time scale.
It is appreciated that the Element Status field is used to exclude reloading and scanning of a directory if it was only recently processed (for example, 10 minutes ago). Other implementations of the directory access table may exclude this field and rely on timers or other means to prevent a directory from being scanned too regularly after it has been processed.
^ -2013 ϋ Ο 6 4 C - 2 9 -03- 2013
Figure 6 is a flow chart that further illustrates the process of using the table in Figure 5 when performing malicious software for parallel or batch access in accordance with a particular application of the present invention. The steps of the method are performed by the anti-virus software as follows:
B1. For each file intercepted for malicious software exploration, for example a scan request is generated for a file opening, continue to step B2 to check the access table.
B2. Verify that the file directory is in the access table, if the directory is not in the access table, then continue to step B3 to create a directory element, otherwise continue to step B4.
B3. Creates an access table element for the file directory, and initializes the Element Status of the directory to Note, Touch Number = 0, the file extension of the file is added to the File Extensions List (or list of file types explored) , continues to perform normal malicious software scan of the accessed file.
B4. Verify that the Director Element Status is in the Noted state, if the Element Status is Noticeable then continue to step B5, otherwise continue to step B8.
B5. Increases the Number of Touchs which represents the number of file accesses in the directory through various applications and adds the file extension of the file to the List of Accessed Extensions.
B6. Check that the Hit Number (HC) reaches a threshold value N (for example HC> = N, where N = 5). If the Number of Reaches reaches the threshold value, it will be -2013 «0 8 4 C-2 9 -03- 2013
Î9A then proceed to step B7, otherwise normal malicious software is scanned on the accessed file.
B7. The Element Status of the directory is changed to the Collected state and the process continues in step B8, where the anti-virus software uploads a file group that includes the file accessed for parallel or directory scanning.
B8. Check that the Element Status of the directory is in the Collected state, if the Element Status is Collected then continue to step B9, otherwise continue to step B10.
B9. Perform a malicious software scan in parallel (or batch) on a group or a selection of unexplored files that includes the current directory file.
The following rules can be used to select a group of files for scanning in batch or in parallel:
- Selects files with file extensions or file types that match the currently accessed file; or
- Select files with extensions or file types listed in the Accessed Extensions List.
B10. Verify that multiple file groups exist in the directory. Files can be selected from the uploaded list. If there are multiple file groups, the method continues in step B11, otherwise the method continues in step B12.
B11. Another group of unexplored files is selected from the uploaded list, and a malicious software scan in batch or in parallel is performed, the method continues in step B10. Although anti-virus software is intended to avoid blocking an application's execution, this can be achieved if the multiple-core support is capable of multiple tasks between the application and anti-virus software. This is (Λ- 2 Ο 1 3 θ 0 8 4 C - 2 S -03- 2013 exploration in batch or in parallel of additional unexplored files in the list that could be performed in the background so that the application can continue.
B12. Since there are no longer any uploaded files or unexplored files having file extensions listed in the Directory Access Extensions List, then the Element Status of the directory is changed to the Processed state. If a directory is found in the Process state, the process performs a normal malicious scan of the file if necessary.
The results of malicious software scans are added to the cache and are reported to the application when it accesses a crawled file from the directory, allowing the application to immediately use the accessed file.
Figure 7 is an alternative flow chart illustrating the malicious software exploration for access in batch or in parallel according to a particular application of the present invention. The method steps from B1 to B12 that are performed by the anti-virus software are similar to those in Figure 6, with the exception of steps B1O and B11 (B11 was deleted). Step B10 is described as follows:
B10. Checks if multiple groups of files exist in the directory. Files can be selected from the uploaded list. If more than one file group exists, the method continues to scan for malicious software normally until an additional file is accessed by the application that requests the scan, where the method starts again in step B1.
The reason for not continuing to perform additional parallel file scanning is that the application needs to access only a limited number of files in the directory, this process prevents anti-virus software from scanning in load or in parallel in the background on all files listed in the Access Extensions List until absolutely necessary when another file is
<img file="RO130379A2_D0010.tif" />
C \ - 2 Ο 1 3 OU 8 4 C - 2 9 -03- 2013 accessed by an application. This also minimizes the number of malicious software scan interruptions while running an application.
The following example illustrates how the above method can work when copying a large number of files from a common directory. The following assumptions are made:
a) The common directory has a collection of * .exe and * .dll files;
b) The access table is maintained by the anti-virus program;
c) The access table already has a director element in connection with the common director;
d) A number of hits representing the number of hits and a list of file extensions accessed from the shared directory are maintained.
The logic flow is as follows:
1. The first few exe files accessed are normally scanned until the directory collects a sufficient number of touches, ie the number of touches reaches a threshold;
2. As soon as the number of hits reaches a threshold, anti-virus software uploads files from the directory;
3. Any subsequent scanning request for "exe" files from the directory triggers a "back-to-back" scan of other "exe" files (a group of files) from the directory;
4. After copying is complete, the directory item expires after a period of time.
In more detail, when the copy operation, copy <from the shared directory> *. Exe <to another directory> is performed, the copy command (application) will access the "exe" files sequentially to read and copy data in the other directory. When the first "exe" file is accessed from the shared directory, a scan request will be generated for the anti-virus software. If the common directory does not have a directory element in the access table, the anti-virus software will create and initialize a c \ - 2 Ο 1 3 OO 8 4 C - 2 9 -D3- 2013
<img file="RO130379A2_D0011.tif" />
directory element for the shared directory, the number of directory element hits that represents the number of file accesses is initialized and the file type, in this case "exe", is added to an extension list in relation to the directory element. Otherwise, the number of directory element hits is increased and the "exe" file type is added to the extension list if it is not already in the extension list.
The first "exe" file accessed is then normally scanned for malicious software and used by the copy command. Subsequent "exe" files are accessed, scan requests are performed and are normally scanned by antivirus software, and the number of touches for the common directory element is increased on each access until the directory element in connection with the common directory collects a sufficient number of touches. As soon as the number of hits reaches a threshold, the anti-virus software starts uploading or determining one or more unexplored "exe" file groups from the shared directory. Each subsequent scan request of an unexplored "exe" file triggers the anti-virus to perform parallel (ie, substantially simultaneous scanning) scan of the unexplored "exe" file and of one of the unexplored file groups from the shared directory. Continuous browsing until the relevant "exe" files in the shared directory have been processed or the copy command is completed. After the copy command is complete, the directory element in the access table will expire within a predetermined time frame and is removed from the expiration table.
The computing systems as described here can each perform batch or parallel scan of a selected file group from a multitude of files accessed from a common directory for malicious software. The processors of such systems are configured to execute computer program instructions based on the methods described here, such instructions being contained in a computer readable environment, such as memory. The instructions of the computer program can be read in memory from another environment that can be read by the computer or from another device through a communication interface. The instructions contained in the memory cause the computer system processor to perform the procedures or
<img file="RO130379A2_D0012.tif" />
<img file="RO130379A2_D0013.tif" />
methods as described here. However, as an alternative, hardware wired circuits may be used instead or in combination with computer program instructions to implement processes consistent with the present invention. Thus, the present invention is not limited to any specific combination of hardware and / or software circuits.
In particular, a computer program that includes computer program code means adapted to perform app access detection steps to files within a common directory, using the detected accesses to identify one or more groups of files in the mentioned shared directory that the application may later want to access, and by training to explore the mentioned file groups, which are one or more, for malicious software before the application tries to access the files of the group or groups. The computer program may additionally include means of computer program code additionally adapted to scan one or more of said file groups. The computer program can be embedded on a computer-readable environment.
In addition, the methods described above can exploit the capabilities of multiprocessor, multiple tasks, multiple threads and hyperthreading of modern computer systems (as described here and also in Intel's Hyper-Threading document ®, Technical User's Guide (Inter® Hyper-Threadiqg Technology, Technical User's Guide), January 2003) to further improve the performance of a computer system when implementing malicious software access to read-only file access, by allowing the scanning of one or more groups of files to be parallelized.
It will be appreciated by the person skilled in the art that various modifications can be made to the concrete applications described above without departing from the scope of the present invention.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
8 priority claims, no other members on record
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 201113068610 | United States of America | A | |
| 201113068610 | United States of America | A | |
| 2012055733 | European Patent Office (EPO) | W | |
| 2012055733 | European Patent Office (EPO) | W | |
| 13068610 | – | – | – |
| TEP2012055733 | – | – | – |
| US201113068610 | – | – | – |
| WO2012EP55733 | – | – | – |
Numbers
- Publication
- 130379
- Publication, DOCDB
- 130379
- Publication, EPODOC
- RO130379
- Application
- 201300848
- Application, DOCDB
- 201300848
- Application, EPODOC
- RO20130000848
Titles2
- English
- LOOK AHEAD MALWARE SCANNING
- Romanian
- EXPLORARE PENTRU SOFTWARE RĂU INTENŢIONAT CU CĂUTARE ÎN AVANS
Classification
- CPC, 6
- G06F21/566
- G06F21/552
- G06F21/56
- G06F21/562
- G06F11/30
- G06F12/14
- IPC, 3
- G06F21 00
- G06F21 55
- G06F21 56