The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 14, 2022

Filed:

Mar. 19, 2020
Applicant:

Netskope, Inc., Santa Clara, CA (US);

Inventors:

Abhinav Singh, Sunnyvale, CA (US);

Himanshu Sharma, Milpitas, CA (US);

Assignee:

Netskope, Inc., Santa Clara, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); H04L 9/40 (2022.01); G06F 21/57 (2013.01); H04L 9/32 (2006.01);
U.S. Cl.
CPC ...
G06F 21/565 (2013.01); G06F 21/577 (2013.01); H04L 9/3239 (2013.01); H04L 63/145 (2013.01); G06F 2221/034 (2013.01);
Abstract

The disclosed technology teaches reducing threat detection processing, including recognizing that a file is an edited version of a previously processed file and retrieving, from an archive, metadata values, hashes for property groups and an entropy measure of the previously processed file. Also included is parsing the file into metadata values and property groups and calculating hashes of the property groups and entropy measure for the file. The method further includes applying similarity measures to compare the metadata values, the entropy measures, and the hashes on the property groups, for the edited version and the previously processed file. When any similarity measure or combination of similarity measures reaches a trigger, the technology teaches processing the file by using a threat detection module to detect malware. Property groups include core properties, application properties, document content and programming scripts for the edited version of the file and the previously processed file.


Find Patent Forward Citations

Loading…