发明名称 DETECTION OF UNDESIRED COMPUTER FILES IN ARCHIVES
摘要 Systems and methods for content filtering are provided. According to one embodiment, a self-extracting archive is received with an electronic mail (email) message. Prior to delivery of the email message, a determination is made regarding whether a file contained in the archive may be malicious or undesired. A type of archive and associated structure of the archive are determined by examining identification bytes stored within a header portion of the archive that identify the type of archive. Based on the type and associated structure, for each contained file, descriptive information, including a checksum of the file in uncompressed form, a size of the file in uncompressed form and/or a size of the file in the compressed form, is extracted from the header portion. A file is identified as potentially malicious or undesired when the descriptive information matches a detection signature of a known malicious or undesired file.
申请公布号 US2012090031(A1) 申请公布日期 2012.04.12
申请号 US201113312966 申请日期 2011.12.06
申请人 FOSSEN STEVEN MICHAEL;MACDONALD ALEXANDER DOUGLAS;FORTINET, INC. A DELAWARE CORPORATION 发明人 FOSSEN STEVEN MICHAEL;MACDONALD ALEXANDER DOUGLAS
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址