US2015235027A1PendingUtilityA1
Malicious code detection
Assignee: HEWLETT PACKARD DEVELOPMENT COPriority: Oct 31, 2009Filed: Apr 24, 2015Published: Aug 20, 2015
Est. expiryOct 31, 2029(~3.2 yrs left)· nominal 20-yr term from priority
Inventors:David A. Warren
G06F 21/567G06F 21/566H04L 63/1416G06F 21/564G06F 2221/033
44
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A device includes a pipeline and a detector that are both implemented at least in hardware. Data is moved through the pipeline to perform processing of the data unrelated to detection of malicious code. The detector detects the malicious code within the data as the data is moved through the pipeline, in parallel with the processing of the data as the data is moved through the pipeline. The detector detects the malicious code within the data as the data is moved through the pipeline without delaying movement of the data into, through, and out of the pipeline.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A non-transitory computer readable medium storing instructions that when executed by a processor cause the processor to:
store a malicious code signature in a storage, wherein the malicious code signature includes a number of bytes greater than a total number of bytes in each row of a pipeline; simultaneously compare the malicious code signature to each of a plurality of portions of data in the pipeline, wherein each of the plurality of portions of data begins at a different byte within a given row of the pipeline and spans more than one row of data in the pipeline; and indicate that the malicious code has been detected within the data in the pipeline when a predetermined number of bytes in one of the plurality of portions of data matches the malicious code signature.
3 . The non-transitory computer readable medium of claim 2 , wherein a total number of the plurality of portions of data to be compared to the malicious code signature equals to the total number of bytes in each row of the pipeline.
4 . The non-transitory computer readable medium of claim 2 , wherein the signature of malicious code includes portions corresponding to different types of malicious code.
5 . The non-transitory computer readable medium of claim 2 , wherein the instructions further cause the processor to:
process the data within the pipeline independently from the simultaneous comparing of the malicious code signature to each of the plurality of portions of data in the pipeline.
6 . The non-transitory computer readable medium of claim 2 , wherein, to compare the malicious code signature to each of the plurality of portions of data, the processor is to determine whether each byte of the respective portion of data matches each byte of the malicious code signature.
7 . A method comprising:
storing a malicious code signature in a storage, wherein the malicious code signature includes a number of bytes greater than a total number of bytes in each row of a pipeline; simultaneously comparing, by a processing device, the malicious code signature to each of a plurality of portions of data in the pipeline, wherein each of the plurality of portions of data begins at a different byte within a given row of the pipeline and spans more than one row of data in the pipeline; and indicating, by the processing device, that the malicious code has been detected within the data in the pipeline when a predetermined number of bytes in one of the plurality of portions of data matches the malicious code signature.
8 . The method of claim 7 , wherein a total number of the plurality of portions of data to be compared to the malicious code signature equals to the total number of bytes in each row of the pipeline.
9 . The method of claim 7 , wherein the signature of malicious code includes portions corresponding to different types of malicious code.
10 . The method of claim 7 , further comprising:
processing the data in the pipeline independently from the simultaneous comparing of the malicious code signature to each of the plurality of portions of data in the pipeline.
11 . The method of claim 7 , wherein comparing the malicious code signature to each of the plurality of portions of data includes determining whether each byte of the respective portion of data matches each byte of the malicious code signature.
12 . A malicious code detecting device comprising:
a processor; and a non-transitory computer readable medium storing instructions that when executed by the processor cause the processor to:
store a malicious code signature, wherein the malicious code signature includes a number of bytes greater than a total number of bytes in each row of a pipeline,
simultaneously compare the malicious code signature to each of a plurality of portions of data in the pipeline, wherein each of the plurality of portions of data begins at a different byte within a given row of the pipeline and spans more than one row of data in the pipeline, and
indicate that the malicious code has been detected within the data in the pipeline when a predetermined number of bytes in one of the plurality of portions of data matches the malicious code signature.
13 . The malicious code detecting device of claim 12 , wherein a total number of the plurality of portions of data to be compared to the malicious code signature equals to the total number of bytes in each row of the pipeline.
14 . The malicious code detecting device of claim 12 , wherein the signature of malicious code includes portions corresponding to different types of malicious code.
15 . The malicious code detecting device of claim 12 , wherein the instructions are to cause the processor to process the data in the pipeline as the data is moved through the pipeline,
wherein the processing of the data is independent from the simultaneous comparing of the malicious code signature to each of the plurality of portions of data.
16 . The malicious code detecting device of claim 12 , wherein, to compare the malicious code signature to each of the plurality of portions of data, the processor is to determine whether each byte of the respective portion of data matches each byte of the malicious code signature.Join the waitlist — get patent alerts
Track US2015235027A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.