发明名称 DETECTION OF UNDESIRED COMPUTER FILES IN ARCHIVES
摘要 Systems and methods that can detect known undesired computer files in protected archives are provided. According to one embodiment, an archive file in transit across a network as an attachment to an email message destined for a client workstation is scanned, without decrypting or decompressing contents of the archive, by an anti-virus detection module running on a network gateway. A type and associated structure of the archive are identified by examining primary or secondary identification bytes of the archive. Based on the type and structure, descriptive information regarding a contained file is obtained. The descriptive information includes a hash value of the contained file in uncompressed format. If the descriptive information matches a signature of a known undesired computer file, then a clean version of the archive is produced by removing the contained file and regenerating the archive. Finally, the clean version of the archive is delivered.
申请公布号 US2011016530(A1) 申请公布日期 2011.01.20
申请号 US20100893094 申请日期 2010.09.29
申请人 FORTINET, INC. 发明人 FOSSEN STEVEN MICHAEL;MACDONALD ALEXANDER DOUGLAS
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址