IP Library Granted Patent US 7,669,059
Granted Patent B2
US 7,669,059 · App. 10/808,260 · Granted Feb 23, 2010

Method and apparatus for detection of hostile software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,669,059
App. No.
10/808,260
Granted
Feb 23, 2010
Kind
B2
Abstract

Methods and apparatuses are presented for detecting hostile software in a computer system involving storing a representation of configuration data associated with an operating system for the computer system obtained at a first time, comparing the stored representation of the configuration data obtained at the first time with a representation of the configuration data associated with the operating system for the computer system obtained at a second time, and if deviation is detected between the stored representation of the configuration data obtained at the first time and the representation of the configuration data obtained at the second time, automatically performing at least one remedial measure in response to the deviation detected. In one embodiment of the invention, the configuration data relates to identification of executable code installed in the computer system. The configuration data may be obtained from a registry key in a registry maintained by the operating system.

Claims (31)

1. A method for detecting hostile software in a computer system comprising:

storing a representation of configuration data associated with an operating system for the computer system obtained at a first time, wherein the stored representation of configuration data is encrypted prior to being stored;

comparing the stored representation of the configuration data obtained at the first time with a representation of the configuration data associated with the operating system for the computer system obtained at a second time, wherein the operating system is actively operating at the second time; and

if deviation is detected between the stored representation of the configuration data obtained at the first time and the representation of the configuration data obtained at the second time, automatically performing at least one remedial measure in response to the deviation detected, wherein the operating system continues to operate after the at least one remedial measure is performed, wherein the at least one remedial measure comprises determining a storage location associated with suspected executable code in the computer system and moving suspected executable code to a specified storage location for later evaluation, and wherein the at least one remedial measure further comprises determining whether the suspected executable is being executed, and if the suspected executable code is being executed, terminating the execution of the suspected executable code without first providing warning to the suspected executable code prior to terminating the execution to prevent the suspected executable code from performing one or more countermeasures.

2. The method of claim 1 wherein the configuration data relates to identification of executable code installed in the computer system.

3. The method of claim 1 wherein the configuration data relates to identification of a command line for invoking executable code associated with a particular file extension.

4. The method of claim 1 wherein the configuration data is obtained from a registry maintained by the operating system.

5. The method of claim 4 wherein the configuration data obtained from at least one key associated with the registry.

6. The method of claim 1 wherein the configuration data is obtained from a file stored in the computer system.

7. The method of claim 1 wherein the configuration data is compared to a predefined value.

8. The method of claim 1 wherein the configuration data is checked for addition of data.

9. The method of claim 1 wherein the configuration data is checked for removal of data.

10. The method of claim 1 wherein the at least one remedial measure comprises determining whether suspected executable code is currently executing.

11. The method of claim 10 wherein the at least one remedial measure further comprises terminating execution of the suspected executable code.

12. The method of claim 11 , wherein the suspected executable code does not receive notification prior to being terminated.

13. The method of claim 1 wherein the at least one remedial measure comprises altering configuration data associated with the operating system to reflect the stored representation of the configuration data.

14. The method of claim 1 wherein the operating system is a Windows-based operating system.

15. The method of claim 1 wherein the operating system is a Linux-based operating system.

16. A computer system capable of detecting hostile software comprising:

a processing unit capable of being controlled by an operating system;

a storage unit coupled to the processing unit, the storage unit capable of storing a representation of configuration data associated with the operating system obtained at a first time, wherein the stored representation of configuration data is encrypted prior to being stored;

wherein the processing unit is capable of comparing the stored representation of the configuration data obtained at the first time with a representation of the configuration data associated with the operating system obtained at a second time, wherein the operating system is actively operating at the second time, and, if deviation is detected between the stored representation of the configuration data obtained at the first time and the representation of the configuration data obtained at the second time, automatically performing at least one remedial measure in response to the deviation detected, wherein the operating system continues to operate after the at least one remedial measure is performed, wherein the at least one remedial measure comprises determining a storage location associated with suspected executable code in the computer system and moving suspected executable code to a specified storage location for later evaluation, and wherein the at least one remedial measure further comprises determining whether the suspected executable is being executed, and if the suspected executable code is being executed, terminating the execution of the suspected executable code without first providing warning to the suspected executable code prior to terminating the execution to prevent the suspected executable code from performing one or more countermeasures.

17. A system for detecting hostile software in a computer system comprising:

means for storing a representation of configuration data associated with an operating system for the computer system obtained at a first time, wherein the stored representation of configuration data is encrypted prior to being stored;

means for comparing the stored representation of the configuration data obtained at the first time with a representation of the configuration data associated with the operating system for the computer system obtained at a second time, wherein the operating system is actively operating at the second time; and

means for automatically performing at least one remedial measure in response to the deviation detected, if deviation is detected between the stored representation of the configuration data obtained at the first time and the representation of the configuration data obtained at the second time, wherein the operating system continues to operate after the at least one remedial measure is performed, wherein the at least one remedial measure comprises determining a storage location associated with suspected executable code in the computer system and moving suspected executable code to a specified storage location for later evaluation, and wherein the at least one remedial measure further comprises determining whether the suspected executable is being executed, and if the suspected executable code is being executed, terminating the execution of the suspected executable code without first providing warning to the suspected executable code prior to terminating the execution to prevent the suspected executable code from performing one or more countermeasures.

18. An article of manufacture comprising:

a computer usable medium having computer readable program code means embodied therein for causing hostile software to be detected in a computer system, the computer readable program code means in said article of manufacture comprising:

computer readable program code means for causing a computer to store a representation of configuration data associated with an operating system for the computer system obtained at a first time, wherein the stored representation of configuration data is encrypted prior to being stored;

computer readable program code means for causing the computer to compare the stored representation of the configuration data obtained at the first time with a representation of the configuration data associated with the operating system for the computer system obtained at a second time, wherein the operating system is actively operating at the second time; and

computer readable program code means for causing the computer to automatically perform at least one remedial measure in response to the deviation detected, if deviation is detected between the stored representation of the configuration data obtained at the first time and the representation of the configuration data obtained at the second time, wherein the operating system continues to operate after the at least one remedial measure is performed, wherein the at least one remedial measure comprises determining a storage location associated with suspected executable code in the computer system and moving suspected executable code to a specified storage location for later evaluation, and wherein the at least one remedial measure further comprises determining whether the suspected executable is being executed, and if the suspected executable code is being executed, terminating the execution of the suspected executable code without first providing warning to the suspected executable code prior to terminating the execution to prevent the suspected executable code from performing one or more countermeasures.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2024
From: CITIZENS BANK, N.A.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 067822/0433 →
TERMINATION AND RELEASE OF FIRST SUPPLEMENT OT PATENT SECURITY AGREEMENT AT R/F 049035/0939 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058740/0265 →
SECURITY INTEREST Recorded Mar 3, 2020
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052076/0905 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SCHEDULE PREVIOUSLY RECORDED ON REEL 049035 FRAME 0939. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST SUPPLEMENT TO PATENT SECURITY AGREEMENT. Recorded Aug 22, 2019
From: GENBAND US LLC; RIBBON COMMUNICATIONS OPERATING COMPANY, INC., FORMERLY KNOWN AS SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 050705/0001 →
FIRST SUPPLEMENT TO SECURITY AGREEMENT Recorded Apr 30, 2019
From: GENBAND US LLC; RIBBON COMMUNICATIONS OPERATING COMPANY, INC., FORMERLY KNOWN AS SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 049035/0939 →
CHANGE OF NAME Recorded Jan 16, 2019
From: SONUS NETWORKS, INC.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
Reel/Frame 048078/0036 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2017
From: NETWORK EQUIPMENT TECHNOLOGIES, INC.
To: SONUS NETWORKS, INC.
Reel/Frame 044904/0829 →
RELEASE OF SECURITY INTEREST Recorded Oct 24, 2017
From: BANK OF AMERICA, N.A.
To: SONUS NETWORKS, INC.; SONUS FEDERAL, INC.; NETWORK EQUIPMENT TECHNOLOGIES, INC.; PERFORMANCE TECHNOLOGIES, INCORPORATED; SONUS INTERNATIONAL, INC.; TAQUA, INC.
Reel/Frame 044283/0361 →
SECURITY INTEREST Recorded Sep 12, 2014
From: SONUS NETWORKS, INC.; SONUS FEDERAL, INC.; NETWORK EQUIPMENT TECHNOLOGIES, INC.; PERFORMANCE TECHNOLOGIES, INCORPORATED; SONUS INTERNATIONAL, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033728/0409 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2004
From: BRENT, MICHAEL D.
To: NETWORK EQUIPMENT TECHNOLOGIES, INC.
Reel/Frame 015881/0107 →