IP Library Granted Patent US 7,376,977
Granted Patent B2
US 7,376,977 · App. 10/856,454 · Granted May 20, 2008

Defense against virus attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,376,977
App. No.
10/856,454
Granted
May 20, 2008
Kind
B2
Abstract

A method, software, and computer system for defending against virus attacks is described. Assume that a computer system receives an instruction to run an executable file. Before the computer system runs the executable file, the computer system determines if the executable file is certified to run on the computer system. If the executable file is not certified, then the computer system prevents the executable file from running. If the executable file is certified, then the computer system determines if the executable file has been modified since being certified. If the executable file has been modified, then the computer system prevents the executable file from running. If the executable file has been certified and has not been modified, then the computer system runs the executable file. Because many viruses are included in executable files, virus attacks may be prevented by requiring executable files to be certified before they can run.

Claims (56)

1. A method of operating a computer system, the method comprising the steps of:

receiving an instruction to run an executable file;

determining if the executable file is certified to run on the computer system by:

identifying a certification indicator in the executable file;

identifying a computer ID for the computer system;

determining if the certification indicator corresponds with the computer ID; and

determining that the executable file is certified to run on the computer system if the certification indicator corresponds with the computer ID;

determining if the executable file has been modified since being certified for the computer system; and

running the executable file responsive to a determination that the executable file is certified to run on the computer system and that the executable file has not been modified since being certified.

2. The method of claim 1 further comprising the step of:

preventing the executable file from running responsive to a determination that the executable file is not certified or that the executable file has been modified since being certified.

3. The method of claim 1 further comprising the steps of:

notifying a user of the computer system if the executable file is not certified; and

determining if the executable file is certified to run on another computer system.

4. The method of claim 1 further comprising the steps of:

receiving a user ID and a password from a user of the computer system;

validating the user based on the user ID and password; and

certifying the executable file by writing a certification indicator into the executable file.

5. The method of claim 4 further comprising the steps of:

determining a modification indicator for the executable file; and

writing the modification indicator into the executable file.

6. The method of claim 1 wherein the step of determining if the executable file has been modified since being certified for the computer system comprises the steps of:

determining a current modification value for the executable file;

identifying a modification indicator from the executable file;

determining if the current modification value corresponds with the modification indicator; and

determining that the executable file has been modified if the current modification value does not correspond with the modification indicator.

7. A software product for a computer system, the software product comprising:

operating system software when executed by a processing system that:

receives an instruction to run an executable file,

determines if the executable file is certified to run on the computer system when the operating system software:

identifies a certification indicator in the executable file,

identifies a computer ID for the computer system,

determines if the certification indicator corresponds with the computer ID, and

determines that the executable file is certified to run on the computer system if the certification indicator corresponds with the computer ID,

determines if the executable file has been modified since being certified for the computer system, and

runs the executable file responsive to a determination that the executable file is certified and that the executable file has not been modified since being certified; and

a storage system that stores the operating system software.

8. The software product of claim 7 wherein the operating system software prevents the executable file from running responsive to a determination that the executable file is not certified or that the executable file has been modified since being certified.

9. The software product of claim 7 wherein the operating system software notifies a user of the computer system if the executable file is not certified and determines if the executable file is certified to run on another computer system.

10. The software product of claim 7 wherein the operating system software receives a user ID and a password from a user of the computer system, validates the user based on the user ID and password, and certifies the executable file by writing a certification indicator into the executable file.

11. The software product of claim 10 wherein the operating system software determines a modification indicator for the executable file and writes the modification indicator into the executable file.

12. The software product of claim 7 wherein the operating system software determines a current modification value for the executable file, identifies a modification indicator from the executable file, determines if the current modification value corresponds with the modification indicator, and determines that the executable file has been modified if the current modification value does not correspond with the modification indicator.

13. A computer system, comprising:

a user interface configured to receive an instruction to run an executable file; and

a processing system, responsive to receiving the instruction from the user interface, that:

determines if the executable file is certified to run on the computer system when the operating system software:

identifies a certification indicator in the executable file,

identifies a computer ID for the computer system,

determines if the certification indicator corresponds with the computer ID, and

determines that the executable file is certified to run on the computer system if the certification indicator corresponds with the computer ID,

determines if the executable file has been modified since being certified for the computer system, and

runs the executable file responsive to a determination that the executable file is certified and that the executable file has not been modified since being certified.

14. The computer system of claim 13 wherein the processing system prevents the executable file from running responsive to a determination that the executable file is not certified or that the executable file has been modified since being certified.

15. The computer system of claim 13 wherein the processing system notifies a user of the computer system if the executable file is not certified and determines if the executable file is certified to run on another computer system.

16. The computer system of claim 13 wherein the processing system receives a user ID and a password from a user of the computer system, validates the user based on the user ID and password, and certifies the executable file by writing a certification indicator into the executable file.

17. The computer system of claim 13 wherein the processing system determines a current modification value for the executable file, identifies a modification indicator from the executable file, determines if the current modification value corresponds with the modification indicator, and determines that the executable file has been modified if the current modification value does not correspond with the modification indicator.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded May 22, 2015
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 035696/0040 →
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033950/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 032716/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2014
From: ALCATEL LUCENT
To: INVENTIVE ACQUISITION COMPANY I, INC.
Reel/Frame 032557/0841 →
CHANGE OF NAME Recorded Mar 31, 2014
From: INVENTIVE ACQUISITION COMPANY I, INC.
To: IDPA HOLDINGS, INC.
Reel/Frame 032568/0542 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2013
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 031859/0973 →
MERGER Recorded Dec 18, 2013
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 031805/0874 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2004
From: JINDAL, DINESH K.; NANDAM, VENKATESHWAR
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 015407/0648 →