IP Library Granted Patent US 7,490,354
Granted Patent B2
US 7,490,354 · App. 10/865,252 · Granted Feb 10, 2009

Virus detection in a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,490,354
App. No.
10/865,252
Granted
Feb 10, 2009
Kind
B2
Abstract

A method that in an embodiment counts the number of times that a file or registry entry is added, changed, or deleted at clients in a network. If the count exceeds a threshold, then a warning is sent to the clients. The warning may prompt the clients to delete or rename the file or registry entry, run an anti-virus program, quarantine the file or registry entry, or issue a message. In this way, viruses may be detected at clients.

Claims (15)

1. A method comprising:

receiving a plurality of notifications from a plurality of clients in network, wherein each of the plurality of clients detected that an attribute of a file was changed, and wherein each of the plurality of notifications comprises a name of the file, a modifying entity, and the attribute of the file, wherein the modifying entity identifies a program that changed the attribute of the file;

determining a count of a number of times that the notifications that the attribute of the file was changed were received;

selecting a threshold, wherein the selecting the threshold further comprises selecting the threshold that is higher if the modifying entity is trusted by a system administrator and selecting the threshold that is lower if the modifying entity is not trusted by the system administrator; and

deciding whether the file includes a suspected virus if the count exceeds the threshold.

2. The method of claim 1 , further comprising:

if the deciding is true, sending a warning to the plurality of clients; and

if the deciding is false, refraining from sending the warning to the plurality of clients.

3. The method of claim 1 , wherein the attribute comprises a size of the file.

4. The method of claim 1 , wherein the attribute comprises a certificate of authenticity.

5. The method of claim 1 , wherein the attribute comprises an extension of the file.

6. The method of claim 2 , wherein the file comprises a registry entry.

7. The method of claim 6 , wherein the warning comprises an instruction to delete the registry entry.

8. The method of claim 2 , wherein the warning comprises an instruction to execute an anti-virus program.

9. The method of claim 2 , wherein the warning comprises an instruction to display a message.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2018
From: TREND MICRO INCORPORATED
To: FINJAN BLUE, INC.
Reel/Frame 046955/0289 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: TREND MICRO INCORPORATED
Reel/Frame 024286/0924 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2004
From: GARBOW, ZACHARY A.; GORDON, MICHAEL D.; HAMLIN, ROBERT H.; MARSHALL, WILLIAM R.; MCDANIEL, CLAYTON L.; SANOMI-FLEMING, EMUEJEVOKE J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014760/0856 →