首页> 外国专利> ENCRYPTED DATA - COMPUTER VIRUS, MALWARE AND RANSOM WARE DETECTION SYSTEM

ENCRYPTED DATA - COMPUTER VIRUS, MALWARE AND RANSOM WARE DETECTION SYSTEM

机译:加密数据-计算机病毒,恶意软件和勒索软件检测系统

摘要

There is provided apparatus, systems and methods suitable for detectingmalware in encrypteddata. The term malware refers to any computer codes/instructions, whichperform actionsunauthorized or unwanted by the user, including computer viruses, worms,Trojans and exploits.Potential applications include, but are not limited to, secure and remotestorage systems such asemail servers and cloud servers, encrypted devices such as hard drives, USBflash drives and smartcards. Three approaches, with different properties, are provided for verifyingstandard hashsignatures and generic signatures such as code snippets patterns, usingencrypted indices andhomomorphic encryptions. The entire scanning process is executed in theencrypted domain. Oneor more method and system is provided for scanning the files for viruses andmalwares. Note that,in our system, the data to be scanned is encrypted under the data owner'sprivate key and not to beconfused with polymorphic viruses, which arc data encrypted by the malwarewriter/code. If asignature compatible to our system can be devised for a polymorphic virus, itcan also be detectedunder the present invention.This system allows storage of encrypted files on cloud computing/storageservers or theirpassage into secure system, by providing assurance that the encrypted filesare free of virusesand malwares that were available to the scanner. It may also provide assuranceto the file owner,that their files were not changed, such as when coupled with the invention in"Auditing usingEncrypted Indices", that the resident files were not tampered.One approach involves the data owner encrypting and sending the data files andtheir indices, inaccordance with an encryption scheme, to a storage repository, device, orcloud storage servers.Another consists of the storage of data encrypted using homomorphic encryptionand an anti-virusas a service provider sending encrypted virus/malware signatures, using dataowner's public key,for scanning on the storage device/server.This Invention covers three solutions for performing virus scanning overencrypted data,1) For a private encrypted data storage service/device, where the data ownerpossesses the anti-virus tools and database2) For a public encrypted data storage service/device, where the data ownerrequests thescanning service from an Anti-virus provider, which controls the anti-virustools anddatabase.3) For a public unencrypted data storage service/device, where the data ownerrequests thescanning service from the Anti-virus provider, which controls the anti-virustools anddatabase.
机译:提供了适合于检测的设备,系统和方法加密的恶意软件数据。恶意软件一词是指任何计算机代码/指令,执行动作用户未经授权或不想要的内容,包括计算机病毒,蠕虫,木马和漏洞利用。潜在的应用程序包括但不限于安全和远程存储系统,例如电子邮件服务器和云服务器,加密设备(例如硬盘驱动器,USB)闪存驱动器和智能牌。提供了三种具有不同属性的方法来进行验证标准哈希签名和通用签名,例如代码片段模式,使用加密索引和同态加密。整个扫描过程在加密域。一提供了一种或多种方法和系统来扫描文件中的病毒和恶意软件。注意,在我们的系统中,要扫描的数据在数据所有者的私钥而不是与多态病毒相混淆,这些多态病毒是由恶意软件加密的数据编写者/代码。如果一个与我们的系统兼容的签名可以被设计用于多态病毒,也可以被检测到在本发明下。该系统允许将加密文件存储在云计算/存储上服务器或其通过确保加密文件进入安全系统没有病毒以及扫描仪可用的恶意软件。它也可以提供保证给文件所有者他们的文件没有更改,例如与本发明结合使用时“审核使用加密索引”,表示常驻文件未遭到篡改。一种方法涉及数据所有者加密和发送数据文件,然后他们的索引,在根据加密方案存储到存储库,设备或云存储服务器。另一个包括使用同态加密加密的数据存储和防病毒软件作为服务提供商,使用数据发送加密的病毒/恶意软件签名所有者的公钥,用于在存储设备/服务器上进行扫描。本发明涵盖用于执行病毒扫描的三种解决方案。加密数据1)对于私有加密数据存储服务/设备,其中数据所有者拥有反病毒工具和数据库2)对于公共加密数据存储服务/设备,其中数据所有者要求来自防病毒提供商的扫描服务,该提供商控制防病毒工具和数据库。3)对于公共未加密的数据存储服务/设备,其中数据所有者要求来自防病毒提供程序的扫描服务,该服务可控制防病毒工具和数据库。

著录项

  • 公开/公告号CA2935130A1

    专利类型

  • 公开/公告日2018-01-26

    原文格式PDF

  • 申请/专利权人 KAMALUDEEN MIRZA;

    申请/专利号CA20162935130

  • 发明设计人 KAMALUDEEN MIRZA;

    申请日2016-07-26

  • 分类号G06F21/56;

  • 国家 CA

  • 入库时间 2022-08-21 12:47:59

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号