Digital protection that travels with data

US10417417B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10417417-B2
Application numberUS-201314911140-A
CountryUS
Kind codeB2
Filing dateDec 13, 2013
Priority dateSep 27, 2013
Publication dateSep 17, 2019
Grant dateSep 17, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure relates to a system and method for performing antimalware scanning of data files that is data-centric rather than device-centric, In the example, a plurality of computing devices are connected via a network. An originating device creates or first receives data, and scans the data for malware, After scanning the data, the originating device creates and attaches to the data a metadata record including the results of the malware scan, The originating device may also scan the data for malware contextually-relevant to a second device.

First claim

Opening claim text (preview).

What is claimed is: 1. At least one machine readable, non-transitory storage medium having instructions stored thereon for providing data-centric computer security between a first device and a second device remote from the first device, wherein the instructions, when executed by at least one processor, cause the at least one processor to perform operations comprising: scanning a data file using a security scanner at the first device to produce results; receiving, from the second device, an indication of an operating system platform version at the second device, a version of software at the second device for accessing the data file, or a date for accessing the data file at the second device; scanning the data file for malware contextually relevant to the second device based on the operating system platform version, the version of the software, or the date; creating a record based in part on the results from the security scanner, the record comprising a cryptographic hash of the data file, the record further comprising device information associated with the first device, scan information associated with the security scanner, or user information associated with a user of the first device, wherein the device information comprises at least one of a reputation of the first device, a version of the security scanner, and the operating system platform version, the user information comprises at least one of a reputation of the user of the first device and a manner in which the user of the first device is linked to a user of the second device, and the record is generated or augmented according to the indication; and transmitting the record along with the data file from the first device to the second device. 2. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the scan information comprises at least one of scan status or results, scan parameters, and a target platform for which the security scanner scanned. 3. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the record further comprises privacy information comprising at least one of a privacy reputation of the user of the first device, and the manner in which the user of the first device is linked to the user of the second device. 4. A first device for providing data-centric computer security between the first device and a second device remote from the first device, the first device comprising: at least one memory element; at least one processor coupled to the at least one memory element; and a file sharing client that, when executed by the at least one processor, is configured to receive, from the second device, an indication of an operating system platform version at the second device, a version of software at the second device for accessing the data file, or a date for accessing the data file at the second device, create a record associated with a data file based in part on scan results from a security scanner of the first device, the record comprising a cryptographic hash of the data file, the record further comprising device information associated with the first device, scan information associated with the security scanner, or user information associated with a user of the first device, wherein the security scanner of the first device is configured to scan the data file for malware contextually relevant to the second device based on the operating system platform version, the version of the software, or the date, the record is generated or augmented according to the indication, the device information comprises at least one of a reputation of the first device, a version of the security scanner, and the operating system platform version, and the user information comprises at least one of a reputation of the user of the first device and a manner in which the user of the first device is linked to a user of the second device, and transmit the record along with the data file from the first device to the second device. 5. The first device according to claim 4 , wherein the scan information comprises at least one of scan status or results, scan parameters, and a target platform for which the security scanner scanned. 6. The first device according to claim 4 , wherein the record further comprises privacy information comprising at least one of a privacy reputation of the user of the first device, and the manner in which the user of the first device is linked to the user of the second device. 7. A method for providing data-centric computer security between a first device and a second device remote from the first device, comprising: receiving, at a file sharing client of the first device, from the second device, an indication of an operating system platform version at the second device, a version of software at the second device for accessing a data file, or a date for accessing the data file at the second device; scanning, using a security scanner of the first device, the data file for malware contextually relevant to the second device based on the operating system platform version, the version of the software, or the date; retrieving scan results associated with the data file from the security scanner of the first device; creating, using the file sharing client, a record based in part on the scan results, the record comprising a cryptographic hash of the data file, the record further comprising device information associated with the first device, scan information associated with the security scanner, or user information associated with a user of the first device, wherein the record is generated or augmented according to the indication, the device information comprises at least one of a reputation of the first device, a version of the security scanner, and the operating system platform version, and the user information comprises at least one of a reputation of the user of the first device and a manner in which the user of the first device is linked to a user of the second device; and transmitting the record along with the data file from the first device to the second device. 8. The method according to 7 , wherein the scan information comprises at least one of scan status or results, scan parameters, and a target platform for which the security scanner scanned. 9. The method according to claim 7 , wherein the record further comprises privacy information comprising at least one of a privacy reputation of the user of the first device, and the manner in which the user of the first device is linked to the user of the second device. 10. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the record comprises a name of the data file. 11. The at least one machine readable, non-transitory storage medium according to claim 1 , wherein the record comprises a time stamp of the record.

Assignees

Inventors

Classifications

  • using dedicated hardware · CPC title

  • Assessing vulnerabilities and evaluating computer system security · CPC title

  • Test or assess software · CPC title

  • G06F21/56Primary

    Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

  • Test or assess a computer or a system · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10417417B2 cover?
The present disclosure relates to a system and method for performing antimalware scanning of data files that is data-centric rather than device-centric, In the example, a plurality of computing devices are connected via a network. An originating device creates or first receives data, and scans the data for malware, After scanning the data, the originating device creates and attaches to the data…
Who is the assignee on this patent?
Mcafee Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/56. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 17 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).