Secure and reliable content disarm and reconstruction
Abstract
The present teachings disclose a file Content Disarm and Reconstruction (CDR) system and method. The system includes: a disarm environment comprising disarm sandboxes to transform a file; a separate reconstruct environment; and a controller to classify a file content of a file as a filetype, to provide the file and the filetype to a selected disarm sandbox of the disarm sandboxes for transformation, to receive one or more disarmed files from the selected disarm sandbox, to provide the one or more disarmed files to the reconstruct environment, and to receive a reconstructed file from the reconstruct environment, wherein the disarm environment, the reconstruct environment, and the controller are isolated and separated from one another by hardware. Isolated and separate Virtual Machines (VMs) may host the controller, the disarm environment and the reconstruct environment. The VMs may be disposable VMs that include an application sandbox environment. The VMs may be provided by a cloud service.
Claims
exact text as granted — not AI-modifiedI claim as my invention:
1 . A file Content Disarm and Reconstruction (CDR) system comprising:
a physical computer; a disarm environment hosted by the physical computer comprising disarm sandboxes to transform a file; and a reconstruct environment, wherein the disarm sandbox transforms the file by deconstructing the file into primitive chunks, and by skipping a potentially invalid, malicious or unauthorized primitive chunk of the primitive chunks.
2 . The system of claim 1 , wherein the disarm sandbox further transforms by saving a text file comprising an object type and associated properties for each known primitive chunk, and by saving graphics content in the file in a graphics file per a basic image file format.
3 . The system of claim 1 , further comprising: a gateway to validate, authenticate and authorize a file transformation request, and to route the file transformation request to the disarm environment and the reconstruct environment.
4 . The system of claim 1 , further comprising a controller to apply a security policy, based on a filetype of the file, to forbid transformation of the file, to return the file without transformation, to return the one or more disarmed files, or to return the reconstructed file.
5 . The system of claim 4 , wherein the controller validates, authenticates and authorizes a file transformation request, and routes the file transformation request to the disarm environment and the reconstruct environment.
6 . The system of claim 4 , wherein the controller selects the disarm sandbox and the reconstruct environment based on the filetype.
7 . The system of claim 4 , wherein the controller receives the one or more disarmed files by downloading the one or more disarmed files from the disarm sandbox, and the controller receives the reconstructed file by downloading the reconstructed file from the reconstruct environment.
8 . The system of claim 4 , wherein the controller ensures that each of the one or more disarmed files is in a safe format.
9 . The system of claim 4 , further comprising:
a first Virtual Machine (VM) to host the controller; a second VM to host the disarm environment; and a third VM to host the reconstruct environment.
10 . The system of claim 4 , wherein the file comprises one or more package files,
the filetype is a file package, the disarm sandbox returns the one or more package files as the one or more disarmed files, for each disarmed file of the one or more disarmed files, the controller classifies a file content of the respective disarmed file as a sub-filetype, receives one or more sub-disarmed files by providing the respective disarmed file and the respective sub-filetype to a disarm sandbox of the disarm sandboxes, and receives a sub-reconstructed file by providing the one or more sub-disarmed files to the reconstruct environment; the controller provides the one or more sub-disarmed files to the reconstruct environment to receive a reconstructed package as the reconstructed file from the reconstruct environment.
11 . The system of claim 4 , wherein the controller stores the file in a temporary storage, the controller selects a preview configuration based on the filetype, the disarm sandbox disarms the file by converting the file to graphics content in a basic image file format, and the reconstruct sandbox reconstructs by converting the one or more disarmed files into the reconstructed file in a preview image format.
12 . The system of claim 1 , further comprising:
a supervisor, wherein the supervisor creates, manages and disposes of VMs, and wherein the supervisor creates a VM to host the disarm environment using a preconfigured hardened template, and wherein the VMs are hosted by the physical computer.
13 . The system of claim 1 , wherein the physical computer is selected from a single computer, a mobile device, a dedicated server, a serverless service or a cloud service.
14 . The system of claim 1 , further comprising a firewall configured to block network connections originating from the disarm environment and to block network connections originating from the reconstruct environment.
15 . The system of claim 1 , wherein the disarm environment comprises one or multiple disposable VMs.
16 . The system of claim 1 , wherein one or more of the disarm environment and the reconstruct environment comprise a VM, a dedicated server, a serverless service or a cloud service.
17 . The system of claim 1 , wherein the file comprises network traffic of a network protocol.
18 . The system of claim 1 , wherein the reconstruct environment transforms the primitive chunks that are known into a reconstructed file.
19 . The system of claim 17 , wherein a file type of the reconstructed file is different than a file type of the file.
20 . The system of claim 1 , further comprising a first VM to host the disarm environment; and a second VM to host the reconstruct environment, wherein the first VM is different than the second VM.
21 . The system of claim 1 , wherein the reconstruct environment receives the one or more disarmed files by downloading the one or more disarmed files from the disarm sandbox, and ensures that each of the one or more disarmed files is in a safe format.Join the waitlist — get patent alerts
Track US2021182382A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.