METHOD AND SYSTEM FOR DEFINING A SAFE STORAGE AREA FOR USE IN RECOVERING A COMPUTER SYSTEM
    1.
    发明申请
    METHOD AND SYSTEM FOR DEFINING A SAFE STORAGE AREA FOR USE IN RECOVERING A COMPUTER SYSTEM 审中-公开
    用于定义用于恢复计算机系统的安全存储区域的方法和系统

    公开(公告)号:US20120030766A1

    公开(公告)日:2012-02-02

    申请号:US13253038

    申请日:2011-10-04

    CPC分类号: G06F21/575

    摘要: A method for defining an area to record changes made to a computer system is disclosed. The method includes defining a safe area on a primary storage device of the computer system and storing information on the location of the safe area on a secondary storage device. The method further includes booting the computer system utilizing a backup device and changing data on the primary storage device. The changes are recorded in the safe area of the primary storage device and are accessible when the computer system is booted from the backup device.

    摘要翻译: 公开了一种定义用于记录对计算机系统的改变的区域的方法。 该方法包括在计算机系统的主存储设备上定义安全区域,并将关于安全区域的位置的信息存储在辅助存储设备上。 该方法还包括利用备份设备引导计算机系统并在主存储设备上改变数据。 更改记录在主存储设备的安全区域中,并且在计算机系统从备份设备启动时可以访问。

    Downloading a computer file from a source computer to a target computer
    2.
    发明授权
    Downloading a computer file from a source computer to a target computer 有权
    将计算机文件从源计算机下载到目标计算机

    公开(公告)号:US07013330B1

    公开(公告)日:2006-03-14

    申请号:US09678692

    申请日:2000-10-03

    IPC分类号: G06F15/16

    CPC分类号: H04L67/06 H04L12/1863

    摘要: A source computer 2 having a copy of a computer file that it is desired to download to a plurality of target computers issues broadcast messages via a computer network linked to those target computers. The broadcast messages indicate the availability of the computer file for download and include a download qualifying parameter. The download qualifying parameter is used by receiving target computers to determine whether or not they qualify to attempt a download from the source computer in response to the received broadcast message. Only those target computers that do qualify attempt a download. The source computer monitors how many target computers make a download attempt in response to a particular broadcast message and adjusts the download qualifying parameters in subsequent broadcast messages so that the target computers progressively download the new computer file without overloading the source computer.

    摘要翻译: 具有希望下载到多个目标计算机的计算机文件的副本的源计算机2通过链接到这些目标计算机的计算机网络发布广播消息。 广播消息指示用于下载的计算机文件的可用性,并且包括下载限定参数。 接收目标计算机来使用下载限定参数来确定它们是否有资格根据接收的广播消息从源计算机尝试下载。 只有符合条件的目标计算机才能尝试下载。 源计算机监视多少目标计算机响应于特定广播消息进行下载尝试,并且在随后的广播消息中调整下载限定参数,使得目标计算机逐渐下载新的计算机文件而不会使源计算机过载。

    Method and system for defining a safe storage area for use in recovering a computer system
    3.
    发明授权
    Method and system for defining a safe storage area for use in recovering a computer system 失效
    用于定义用于恢复计算机系统的安全存储区域的方法和系统

    公开(公告)号:US08069480B1

    公开(公告)日:2011-11-29

    申请号:US10262307

    申请日:2002-09-30

    IPC分类号: G06F21/00

    CPC分类号: G06F21/575

    摘要: A method for defining an area to record changes made to a computer system is provided. A safe area is defined on a primary storage device of the computer system and information is stored on the location of the safe area on a secondary storage device. Further, the computer system is booted utilizing a backup device and data is changed on the primary storage device. The changes are recorded in the safe area of the primary storage device and are accessible when the computer system is booted from the backup device.

    摘要翻译: 提供了一种用于定义区域以记录对计算机系统进行的改变的方法。 在计算机系统的主存储设备上定义安全区域,并且将信息存储在辅助存储设备上的安全区域的位置。 此外,使用备份设备引导计算机系统,并且在主存储设备上改变数据。 更改记录在主存储设备的安全区域中,并且在计算机系统从备份设备启动时可以访问。

    Detecting unwanted properties in received email messages
    4.
    发明授权
    Detecting unwanted properties in received email messages 失效
    检测收到的电子邮件中的不需要的属性

    公开(公告)号:US06757830B1

    公开(公告)日:2004-06-29

    申请号:US09678688

    申请日:2000-10-03

    IPC分类号: G06F1130

    摘要: Received e-mail messages are subject to a minimum delay period determined in dependence upon characteristics of the e-mail message received. Prior to release of the e-mail message upon expiry of the minimum delay period a check is made that the most up-to-date anti-virus and anti-spamming tests have been applied to the e-mail message. Characteristics that may be used to determine the minimum delay period applied include sender characteristics, recipient characteristics, attachment type characteristics and message content type characteristics.

    摘要翻译: 收到的电子邮件消息的最小延迟时间取决于接收的电子邮件的特征。 在最短延迟时间到期之前发布电子邮件消息之前,请检查是否已将最新的反病毒和反垃圾邮件测试应用于电子邮件。 可用于确定应用的最小延迟时间的特征包括发送者特征,接收者特征,附件类型特征和消息内容类型特征。

    User alerts in an anti computer virus system
    5.
    发明授权
    User alerts in an anti computer virus system 有权
    防病毒系统中的用户警报

    公开(公告)号:US07272724B2

    公开(公告)日:2007-09-18

    申请号:US09785216

    申请日:2001-02-20

    CPC分类号: G06F21/564

    摘要: An anti computer virus program uses a library of virus drivers that includes an indication of whether a particular virus can cause irreparable damage and data indicating enhanced user warnings and actions that might be associated with such viruses. If a detected computer virus is one that can cause irreparable damage, then an enhanced user warning (16) is issued indicating this to the user and a notification (28) of the possibility of such corruption is added into the repaired computer file. The notification may take the form of an electronically signed (30) banner message or the like.

    摘要翻译: 反病毒程序使用病毒驱动程序库,其中包括特定病毒是否可能导致无法修复的损坏的指示,以及指示可能与此类病毒相关的增强的用户警告和操作的数据。 如果检测到的计算机病毒是可能导致不可修复的损坏的病毒,则发出增强的用户警告(16),向用户指示这一点,并且将这种损坏的可能性的通知(28)添加到修复的计算机文件中。 该通知可以采用电子签名(30)横幅消息等的形式。

    Event reporting between a reporting computer and a receiving computer
    6.
    发明授权
    Event reporting between a reporting computer and a receiving computer 有权
    报告计算机和接收计算机之间的事件报告

    公开(公告)号:US07228565B2

    公开(公告)日:2007-06-05

    申请号:US09854492

    申请日:2001-05-15

    IPC分类号: G06F11/30

    摘要: An event report, such as a virus detection event, is sent from a reporting computer 2 to a receiving computer 6 via an internet link 4. The report data may take the form of a URL requesting a web page 28 to be provided by the receiving computer 6, the URL bearing an encrypted form 24 of the report data that is used to identify the requested web page as well as pass further information to the receiving computer 6. Alternatively, the report data may be collated in the reporting computer 2 and passed to the receiving computer 6 when a computer virus definition data update is requested. The report data seeks to uniquely identify the event by incorporating the MAC address of the reporting computer 2, the date, time, computer product identifier, version identifier, update identifier and driver triggered. Additionally, a checksum derived from the infected file together with an indication of the corrective action, if any, taken by the reporting computer 2 may be included. The report data sent to the receiving computer 6 may be used to obtain real life information concerning the prevalence of particular viruses together with information characterising the anti-virus programs and their update status being employed by the user community.

    摘要翻译: 诸如病毒检测事件的事件报告经由因特网链接4从报告计算机2发送到接收计算机6。 报告数据可以采用请求网页28由接收计算机6提供的URL的形式,该URL具有用于识别所请求的网页的报告数据的加密形式24,并且传递进一步的信息 到接收计算机6。 或者,报告数据可以在报告计算机2中进行整理,并且当请求计算机病毒定义数据更新时被传递到接收计算机6。 报告数据寻求通过结合报告计算机2的MAC地址,日期,时间,计算机产品标识符,版本标识符,更新标识符和驱动程序来唯一地标识事件。 此外,可以包括从被感染文件导出的校验和以及由报告计算机2采取的校正动作(如果有的话)的指示。 发送到接收计算机6的报告数据可以用于获得关于特定病毒流行的真实生活信息,以及表征用户社区的反病毒程序及其更新状态的信息。

    Data scanning for updatable predefined properties
    7.
    发明授权
    Data scanning for updatable predefined properties 失效
    数据扫描可更新的预定义属性

    公开(公告)号:US06836860B2

    公开(公告)日:2004-12-28

    申请号:US09944387

    申请日:2001-09-04

    IPC分类号: G06F1100

    CPC分类号: H04L63/145 G06F21/562

    摘要: A scan of computer files for predefined properties indicative of such things as viruses is disclosed. The scan is performed in a circular manner, such that when all of the files to be scanned have been scanned it starts again from the first file. The ability to update the data defining the properties to be scanned for during a scan is provided.

    摘要翻译: 扫描计算机文件以预定义的属性,指示病毒被披露。 以循环方式执行扫描,使得当扫描的所有文件已经被扫描时,它再次从第一个文件开始。 提供了在扫描期间更新定义要扫描的属性的数据的能力。

    Handling of malware scanning of files stored within a file storage device of a computer network

    公开(公告)号:US07093002B2

    公开(公告)日:2006-08-15

    申请号:US10004120

    申请日:2001-12-06

    摘要: The present invention provides a load balancing device, computer program product, and method for balancing the load across a plurality of proxy devices arranged to perform malware scanning of files stored within a file storage device of a computer network. The computer network has a plurality of client devices arranged to issue access requests using a dedicated file access protocol to the file storage device in order to access files stored on the file storage device. The load balancing device is arranged so as to intercept access requests issued to the file storage device, and comprises a client interface for receiving an access request issued to the file storage device using the dedicated file access protocol. Further, the load balancing device comprises load balancing logic for applying a predetermined load balancing routine to determine to which proxy device to direct the received access request, and a proxy device interface for sending the access request to the proxy device determined by the load balancing logic, each proxy device being coupled to the file storage device. This enables a very efficient system to be developed for performing malware scanning of files stored within the file storage device, whilst enabling that system to be developed independently of the particular file storage device being used in the computer network, or the operating system being run on that file storage device.

    Providing break points in a malware scanning operation
    10.
    发明授权
    Providing break points in a malware scanning operation 有权
    在恶意软件扫描操作中提供断点

    公开(公告)号:US06968461B1

    公开(公告)日:2005-11-22

    申请号:US09678010

    申请日:2000-10-03

    CPC分类号: G06F21/564

    摘要: A computer virus scanning system is described in which during the scanning operation a measurement value indicative of the amount of data processing performed is calculated and this measurement value used to trigger breaks in the virus scanning operation. The triggered breaks can be used to perform a determination as to whether or not the virus scanning operations should be early terminated. One possibility is to measure the total size of the data processed during the virus scanning operation and calculate a ratio of this compared to the size of the computer file being virus scanned. If this calculated ratio exceeds a predetermined threshold, then virus scanning may be terminated. Another possibility is to associate a complexity value with each of a plurality of tests applied in the virus scanning operation. A total for these complexity values may be used to trigger the breaks and also to trigger early termination upon exceeding of respective threshold levels.

    摘要翻译: 描述了一种计算机病毒扫描系统,其中在扫描操作期间,计算指示执行的数据处理量的测量值,并且该测量值用于触发病毒扫描操作中断。 可以使用触发中断来确定病毒扫描操作是否应该提前终止。 一种可能性是测量在病毒扫描操作期间处理的数据的总大小,并计算与病毒扫描的计算机文件的大小相比的比率。 如果该计算的比率超过预定阈值,则可以终止病毒扫描。 另一种可能性是将复杂性值与在病毒扫描操作中应用的多个测试中的每一个相关联。 这些复杂度值的总和可以用于触发中断,并且还可以在超过相应的阈值水平时触发提前终止。