Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
An apparatus, method, and a computer program are provided in order to allow for secure downloading of data to a host operating system. The host operating system transmits a request to a virtual machine in order download the data from the Internet. In response, the virtual machine downloads the data and scans the data for malicious programs. If the result of the scan is negative, then the host operating system is configured to download the data from the virtual machine.
Core Innovation
The invention relates to secure downloading in which a host operating system routes an Internet download request to an isolated virtual machine. The request is received at the virtual machine via secure shell (SSH) and includes an Internet Protocol (IP) address or uniform resource locator (URL) of the data and instructions for the virtual machine to execute the download of the data.
After downloading the requested Internet data, the virtual machine scans the downloaded data. The scanning determines whether the downloaded data attempted to alter a registry, changed system logs, opened one or more ports, or any combination thereof, to detect malicious programs and potential malicious system changes.
The virtual machine periodically receives a query from the host machine regarding a status of the scanning via secure shell (SSH). The connection between the virtual machine and host machine is only initiated by the host machine, and the virtual machine is unable to initiate communication with an operating system of the host machine; when results are verified, the virtual machine transmits a copy of verified downloaded Internet data to the host using SCP or SFTP initiated by the host.
Claims Coverage
The independent claims cover a method, an apparatus, and a computer program implementing an SSH-based download-to-scan workflow with periodic status reporting and host-initiated one-way verified data transfer. Across the independent claims, the inventive workflow includes four inventive features: SSH reception of a download request containing an IP/URL and instructions, downloading and scanning on the virtual machine, periodic SSH status queries, and host-initiated SCP/SFTP transmission of verified data with no VM-initiated communication to the host operating system.
Ssh-based download request reception with ip/url and download instructions
receiving, at a virtual machine, a request from a host operating system to download data from the Internet, wherein the request is received by way of secure shell (SSH) and comprises an Internet Protocol (IP) address or uniform resource locator (URL) of the data and instructions for the virtual machine to execute the download of the data
Virtual machine downloads and scans for registry, log, and port-alteration attempts
downloading, by the virtual machine, the data from the Internet to scan the downloaded data; scanning, by the virtual machine, the downloaded data, wherein the scanning of the downloaded data further comprises determining whether the downloaded data attempted to alter a registry, changed system logs, opened one or more ports, or any combination thereof
Periodic ssh status queries for scanning completion
periodically receiving a query from the host machine regarding a status of the scanning of the downloaded data via secure shell, wherein the query is periodically received until the virtual machine responds to the query
Host-initiated verified data transmission via scp/sftp with no vm-initiated host communication
transmitting, by the virtual machine, a copy of verified downloaded Internet data to the host machine, when the host machine initiates a secure copy (SCP) or secure file transfer protocol (SFTP) connection with the virtual machine, wherein the connection between the virtual machine and host machine is only initiated by the host machine and the virtual machine is unable to initiate communication with an operating system of the host machine
The independent claim set covers receiving an SSH-based Internet download request containing an IP address/URL and download instructions at a virtual machine, downloading and scanning the downloaded data for attempted registry/log/port changes, periodically handling host SSH status queries until response, and transmitting only verified downloaded data to the host via SCP/SFTP initiated solely by the host while preventing VM-initiated communication to the host operating system.
Stated Advantages
Not explicitly described in patent.
Documented Applications
Not explicitly described in patent.
Interested in licensing this patent?