Adaptive content inspection
Abstract
Methods and apparatus are provided involving adaptive content inspection. In one embodiment, a content inspection processor may identify information with respect to input data and provide the information to a host controller. The host controller may adapt search criteria or other parameters and provide the adapted parameter to the content inspection processor. Other embodiments may include a content inspection processor having integrated feedback, such that results data is fed back to the content inspection processor. The results data may be processed before being provided to the content inspection processor.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An electronic apparatus, comprising:
a content inspection processor configured to inspect input data using a first search criteria to determine first result data indicative of a higher level identifying characteristic of the input data; and a host controller communicatively coupled to the content inspection processor, wherein the host controller is configured to:
determine a second search criteria based at least in part on the higher level identifying characteristic of the input data indicated in the first result data; and
program the content inspection processor to inspect the input data using the second search criteria to enable the content inspection to determine a lower level identifying characteristic of the input data.
2 . The electronic apparatus of claim 1 , wherein:
the content inspection processor configured to:
inspect the input data using the first search criteria to detect whether a first code fragment associated with a first one or more attack signatures is present in the input data; and
output the first result data to indicate whether the first code fragment is detected in the input data; and
the host controller is configured to, when the first result data indicates that the first code fragment is detected in the input data:
determine the second search criteria based on the first one or more attack signatures associated with the first code fragment; and
program the content inspection processor to inspect the input data using the second search criteria to enable the electronic apparatus to detect whether malware is present in the input data.
3 . The electronic apparatus of claim 2 , wherein:
the content inspection processor configured to:
inspect the input data using the first search criteria to detect whether a second code fragment associated with a second one or more attack signatures is present in the input data; and
output the first result data to indicate whether the second code fragment is detected in the input data; and
the host controller is configured to, when the first result data indicates that the second code fragment is detected in the input data:
determine the second search criteria based on the second one or more attack signatures associated with the second code fragment; and
program the content inspection processor to inspect the input data using the second search criteria to enable the electronic apparatus to detect whether malware is present in the input data.
4 . The electronic apparatus of claim 1 , wherein
the content inspection processor configured to:
inspect the input data using the first search criteria to determine a natural language of the input data; and
output the first result data to indicate the natural language of the input data; and
the host controller is configured to:
determine the second search criteria based at least in part on a language pattern used in the natural language of the input data; and
program the content inspection processor to inspect the input data using the second search criteria to enable the electronic apparatus to translate the natural language of the input data into a different language.
5 . The electronic apparatus of claim 4 , wherein the content inspection processor is configured to:
inspect the input data using the second search criteria to detect presence of the language pattern in the input data; and output second result data indicative of whether the language pattern is detected in the input data and, when the language pattern is detected in the input data, location of the language pattern in the input data to enable the electronic apparatus to translate the language pattern from the natural language of the input data into the different language.
6 . The electronic apparatus of claim 5 , wherein:
the language pattern is used in a regional dialect of the natural language of the input data; and the electronic apparatus is configured to detect that the input data uses the regional dialect when the second result data indicates that the language pattern is detected in the input data.
7 . The electronic apparatus of claim 1 , comprising a communication port configured to communicatively couple the electronic apparatus to a communication network, wherein:
the electronic apparatus is configured to receive the input data from the communication network via the communication port; and the content inspection processor is configured to:
inspect the input data using the first search criteria to determine a network protocol used by the communication network; and
output the first result data to indicate the network protocol used by the communication network.
8 . The electronic apparatus of claim 1 , wherein the input data inspected by the content inspection processor comprises encoded image data output from a video encoder.
9 . The electronic apparatus of claim 1 , wherein the electronic apparatus comprises a computer, a pager, a cellular phone, a personal organizer, a portable audio player, a network router, a network firewall, or a network switch.
10 . A method of operating an electronic apparatus comprising:
inspecting, using the electronic apparatus, received data using a first search criteria to determine first result data indicative of a higher level identifying characteristic of the received data; determining, using the electronic apparatus, a second search criteria based at least in part on the higher level identifying characteristic of the received data indicated in the first result data; and re-inspecting, using the electronic apparatus, the received data using the second search criteria to enable the electronic apparatus to determine a lower level identifying characteristic of the input data encompassed by the higher level identifying characteristics of the received data.
11 . The method of claim 10 , wherein:
inspecting the received data comprises:
inspecting the received data using the first search criteria to determine a natural language of the received data; and
determining the first result data to indicate the natural language of the received data;
determining the second search criteria comprises determining the second search criteria based at least in part on a language pattern used in the natural language of the received data; and re-inspecting the received data comprises re-inspecting the received data using the second search criteria to enable the electronic apparatus to translate the natural language of the received data into a different language.
12 . The method of claim 11 , wherein re-inspecting the received data comprises:
re-inspecting the received data using the second search criteria to detect presence of the language pattern in the received data; and determining second result data indicative of whether the language pattern is detected in the received data and, when the language pattern is detected in the received data, location of the language pattern in the received data to enable the electronic apparatus to translate the language pattern from the natural language of the received data into the different language.
13 . The method of claim 10 , comprising receiving the received data from a communicating network communicatively coupled to the electronic apparatus via a communication port, wherein inspecting the received data comprises:
inspecting the received data using the first search criteria to determine a network protocol used by the communication network; and determining the first result data to indicate the network protocol used by the communication network.
14 . The method of claim 10 , wherein:
inspecting the received data comprises:
inspecting the received data using the first search criteria to determine whether a code fragment associated with one or more attack signatures is present in the received data; and
determining the first result data to indicate whether the code fragment is detected in the received data; and
when the first result data indicates that the code fragment is detected in the received data:
determining the second search criteria comprises determining the second search criteria based on the one or more attack signatures associated with the code fragment; and
re-inspecting the received data comprises re-inspecting the received data using the second search criteria to enable the electronic apparatus to detect whether malware is present in the received data.
15 . The method of claim 14 , comprising:
executing, using the electronic apparatus, the received data when re-inspection of the received data using the second search criteria determines that malware is not present in the received data; and disregarding, using the electronic apparatus, the received data when the re-inspection of the received data using the second search criteria determines that malware is present in the received data.
16 . A network device comprising:
a communication port configured to communicatively couple the network device to a communication network to enable the network device to receive input data from the communication network; and one or more processors communicatively coupled to the communication port, wherein the one or more processors are programmed to:
inspect the input data using a first search criteria to determine first result data indicative of whether a first code fragment associated with a first one or more attack signatures is present in the input data; and
when the first result data indicates that the first code fragment is detected in the input data:
determine a second search criteria based at least in part on the first one or more attack signatures associated with the first code fragment; and
re-inspect the input data using the second search criteria to enable the network device to detect whether malware is present in the input data before execution.
17 . The network device of claim 16 , wherein the one or more processors are programmed to:
inspect the input data using a third search criteria before the first search criteria to determine second result data indicative of a network protocol used by the communication network; and determine the first search criteria based at least in part on the network protocol indicated in the first result data.
18 . The network device of claim 16 , wherein the one or more processors are programmed to:
inspect the input data using the first search criteria to determine the first result data such that the first result data indicates of whether a second code fragment associated with a second one or more attack signatures is present in the input data; and determine the second search criteria based at least in part on the second one or more attack signatures associated with the second code fragment when the first result data indicates that the second code fragment is detected in the input data.
19 . The network device of claim 16 , wherein the one or more processors are programmed to re-inspect the input data using the second search criteria to determine second result data indicative of whether malware is present in the input data.
20 . The network device of claim 16 , wherein the network device comprises a network router, a network firewall, a network switch, or any combination thereof.Join the waitlist — get patent alerts
Track US2019180191A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.