发明名称 Systems and methods for detecting undesirable network traffic content
摘要 A method of detecting a content desired to be detected includes receiving electronic data at a first host, determining a checksum value using the received electronic data, sending the checksum value to a processing station, the processing station being a second host that is different from the first host, and receiving a result from the processing station, the result indicating whether the electronic data is associated with a content desired to be detected. A method of detecting a content desired to be detected includes receiving electronic data at a receiving station, and determining whether the received electronic data is associated with a content desired to be detected, wherein the receiving station does not include content detection data for identifying the content desired to be detected.
申请公布号 US9634989(B2) 申请公布日期 2017.04.25
申请号 US201615205520 申请日期 2016.07.08
申请人 Fortinet, Inc. 发明人 Fang Michael Yu
分类号 H04L29/06;G06F21/56 主分类号 H04L29/06
代理机构 Law Office of Dorian Cartwright 代理人 Law Office of Dorian Cartwright ;Cartwright Dorian
主权项 1. A method for detecting a content desired to be detected within a first host device on a network, comprising: receiving electronic data intended for a user station at the first host device, the first host device comprising a processor and memory and responsible for receiving electronic data and passing the electronic data to the user station to which the electronic data is intended; prior to receiving a whole of the electronic data at the first host device, determining, via the processor, a primary checksum value upon and at the time of receipt of each incremental portion of received electronic data on the first host device using all and actual incremental portions of the received electronic data, each primary checksum value determined from all data of previously received incremental portions of electronic data and data of a respective newly received incremental portion of electronic data; sending each primary checksum value from the first host device to a processing station as the incremental portions of electronic data are received and the primary checksum value is determined, the processing station comprising a processor and memory and being a second host device that is different from the first host device; receiving, by the first host device, a result from the processing station for each primary checksum value sent to the processing station, each respective result indicating whether the electronic data is associated with the content desired to be detected; and in response to a determination that upon receipt of a first summative result indicating the electronic data is associated with the content desired to be detected, preventing the electronic data from being sent to the user station to which the electronic data is intended; in response to a determination that receipt of a first summative result indicating the electronic data is not associated with the content desired to be detected: determining one or more additional checksum values for the whole of the electronic data, wherein each of the one or more additional checksum values is distinct from the primary checksum value;sending the one or more additional checksum values from the first host device to the processing station;receiving, by the first host device, one or more respective additional summative results from the processing station for the one or more additional checksum values, the one or more respective additional summative results indicating whether the electronic data is associated with the content desired to be detected; in response to a determination that receipt of the one or more respective additional summative results indicates the electronic data is associated with the content desired to be detected, preventing the electronic data from being sent to the user station to which the electronic data is intended.
地址 Sunnyvale CA US