SYSTEM AND METHOD FOR DETECTING A FILE EMBEDDED IN AN ARBITRARY LOCATION AND DETERMINING THE REPUTATION OF THE FILE
First Claim
Patent Images
1. A method, comprising:
- identifying a file format identifier associated with a beginning of a file;
parsing the file based on the file format identifier to identify an end of the file; and
calculating a hash value from the beginning of the file to the end of the file.
10 Assignments
0 Petitions
Accused Products
Abstract
A method is provided in one example embodiment that includes identifying a file format identifier associated with a beginning of a file, parsing the file based on the file format identifier until an end of the file is identified, and calculating a hash from the beginning of the file to the end of the file. The method may also include sending the hash to a reputation system and taking a policy action based on the hash'"'"'s reputation received from the reputation system.
-
Citations
20 Claims
-
1. A method, comprising:
-
identifying a file format identifier associated with a beginning of a file; parsing the file based on the file format identifier to identify an end of the file; and calculating a hash value from the beginning of the file to the end of the file. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. Logic encoded in one or more non-transitory media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:
-
identifying a file format identifier associated with a beginning of a file; parsing the file based on the file format identifier to identify an end of the file; and calculating a hash value from the beginning of the file to the end of the file. - View Dependent Claims (13, 14, 15, 16)
-
-
17. An apparatus, comprising:
-
one or more processors operable to execute instructions associated with file detection module such that the apparatus is configured for; identifying a file format identifier associated with a beginning of a file; parsing the file based on the file format identifier to identify an end of the file; and calculating a hash value from the beginning of the file to the end of the file. - View Dependent Claims (18, 19, 20)
-
Specification