IP Library Granted Patent US 7,434,297
Granted Patent B1
US 7,434,297 · App. 10/715,346 · Granted Oct 14, 2008

Tracking computer infections

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,434,297
App. No.
10/715,346
Granted
Oct 14, 2008
Kind
B1
Abstract

A technique is disclosed for tracking a virus. The technique comprises copying information from a first packet; passing through a second packet; saving the copied information; determining whether an infection has been received, wherein the infection is associated with a network transmission, and wherein the network transmission is also associated with the first packet; and retrieving the saved information.

Claims (35)

1. A method for tracking a virus comprising:

copying from a first packet received at a destination host to which the first packet is addressed an information including a sender information usable to determine a sending source that addressed and sent the first packet to the destination host, wherein the information is copied from the first packet based at least in part on a determination that the first packet comprises an open packet;

passing through a second packet associated with the first packet, without copying from the second packet said information including a sender information, based at least in part on a determination that the second packet does not comprise an open packet;

saving the information copied from the first packet;

determining whether an infection has been received, wherein the infection is associated with a network transmission with which the first and second packets are associated;

retrieving the saved information; and

using the saved information to identify and take a responsive action with respect to the sending source.

2. The method of claim 1 , wherein the information includes a file system location.

3. The method of claim 1 , wherein the information includes a file name.

4. The method of claim 1 , wherein the information includes a network address of a source computer.

5. The method of claim 1 , wherein the information is saved on the destination host.

6. The method of claim 1 , wherein the determination of when a virus has been received is performed when an attempt to write a file occurs.

7. The method of claim 1 , wherein the determination of when a virus has been received is performed when an attempt to open a file occurs.

8. The method of claim 1 , wherein the determination of when a virus has been received is performed when an attempt to read a file occurs.

9. The method of claim 1 , wherein the determination of when a virus has been received is performed when an attempt to create a file occurs.

10. The method of claim 1 , wherein the determination of when a virus has been received is performed when an attempt to delete a file occurs.

11. The method of claim 1 , wherein the determination of when a virus has been received is performed when an attempt to access a file occurs.

12. The method of claim 1 , wherein the network transmission includes a plurality of network packets.

13. The method of claim 1 , further comprising copying information from a third packet and saving the copied information.

14. The method of claim 1 , further comprising copying and saving information from a plurality of packets, wherein the plurality of packets are a subset of a network transmission.

15. The method of claim 14 , further comprising passing through a second plurality of packets, wherein the second plurality of packets are a second subset of the network transmission.

16. The method of claim 1 , wherein information includes a username.

17. The method of claim 1 , wherein information includes a user credential.

18. The method of claim 1 , wherein information includes a name of a source computer.

19. The method of claim 1 , wherein information includes a netbios name.

20. The method of claim 1 , wherein information includes a domain name service name.

21. A system for tracking a virus comprising:

a processor configured to copy from a first packet received at a destination host to which the first packet is addressed an information including a sender information usable to determine a sending source that addressed and sent the first packet to the destination host, wherein the information is copied from the first packet based at least in part on a determination that the first packet comprises an open packet; pass through a second packet associated with the first packet, without copying from the second packet said information including a sender information, based at least in part on a determination that the second packet does not comprise an open packet; save the information copied from the first packet; determine whether an infection has been received, wherein the infection is associated with a network transmission with which the first and second packets are associated retrieve the saved information; and use the saved information to identify and take a responsive action with respect to the sending source; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions.

22. A computer program product for tracking a virus, the computer program product being embodied in a computer readable medium and comprising computer instructions for:

copying from a first packet received at a destination host to which the first packet is addressed an information including a sender information usable to determine a sending source that addressed and sent the first packet to the destination host, wherein the information is copied from the first packet based at least in part on a determination that the first packet comprises an open packet;

passing through a second packet associated with the first packet, without copying from the second packet said information including a sender information, based at least in part on a determination that the second packet does not comprise an open packet;

saving the information copied from the first packet;

determining whether an infection has been received, wherein the infection is associated with a network transmission with which the first and second packets are associated retrieving the saved information; and

using the saved information to identify and take a responsive action with respect to the sending source.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2004
From: SUTTON, RICHARD; MILLARD, JOHN
To: SYMANTEC CORPORATION
Reel/Frame 014458/0618 →