IP Library Granted Patent US 7,856,661
Granted Patent B1
US 7,856,661 · App. 11/182,320 · Granted Dec 21, 2010

Classification of software on networked systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,856,661
App. No.
11/182,320
Granted
Dec 21, 2010
Kind
B1
Abstract

A method and system for the classification of software in networked systems, includes: determining a software received by a sensor is attempting to execute on a computer system of the sensor; classifying the software as authorized or unauthorized to execute, and gathering information on the software by the sensor if the software is classified as unauthorized to execute. The sensor sends the information on the software to one or more actuators, which determine whether or not to act on one or more targets based on the information. If so, then the actuator sends a directive to the target(s). The target(s) updates its responses according to the directive. The classification of the software is definitive and is not based on heuristics or rules or policies and without any need to rely on any a priori information about the software.

Claims (44)

1. A method to be executed by a processor operating in an electronic environment for classifying software in a network system, comprising:

(a) determining a software received by a sensor is attempting to execute on a computing system of the sensor;

(b) classifying the software as authorized or unauthorized to execute on the computing system;

(c) gathering information on the software by the sensor and sending the information to one or more actuators for analysis and generation of a directive for one or more targets, if the software is classified as unauthorized to execute, wherein the gathering step (c) comprises:

(c1) preparing data about the execution attempt of the unauthorized software:

(c2) collecting ancillary data relevant to the one or more actuators for the analyzing the execution attempt and for generating directives for the one or more targets; and

(c3) sending the ancillary data to the one or more actuators, and wherein the ancillary data comprises:

network packets which encoded the unauthorized software;

source and destination IP addresses and ports indicating a network connection of the network packets which encoded the unauthorized software;

a packet payload signature or a packet header signature; or

a checksum of the unauthorized software.

2. The method of claim 1 , wherein the software is received by the sensor over a network.

3. The method of claim 1 , wherein the determining step (a) comprises:

(a1) intercepting the software's attempt at execution.

4. The method of claim 1 , wherein the classifying step (b) comprises:

(b1) generating an identifier for the software; and

(b2) determining if the identifier is a member of a set of identifiers indicating a set of known authorized software, wherein the software is authorized to execute if the identifier is a member of the set of identifiers, wherein the software is otherwise unauthorized to execute.

5. The method of claim 4 , wherein the identifier comprises a hash, checksum, or message digest evaluated on all or part of a set of bits representing the software.

6. The method of claim 1 , wherein the classifying step (b) comprises:

(b1) determining the software is attempting to access an API which it is not authorized to access; and

(b2) classifying the software as unauthorized to execute.

7. A system comprising:

a sensor coupled to a network system, wherein the sensor receives a software through the network system, wherein the sensor:

determines that the received software is attempting to execute on a computing system of the sensor;

classifies the software as authorized or unauthorized to execute on the computing system;

gathers information on the unauthorized software and sends the information to one or more actuators for analysis and generation of a directive for one or more targets, if the software is classified as unauthorized to execute;

prepares data about the execution attempt of the unauthorized software;

collects ancillary data relevant to the one or more actuators for the analyzing the execution attempt and for generating directives for the one or more targets; and

sends the ancillary data to the one or more actuators, and wherein the ancillary data comprises:

network packets which encoded the unauthorized software;

source and destination IP addresses and ports indicating a network connection of the network packets which encoded the unauthorized software;

a packet payload signature or a packet header signature; or

a checksum of the unauthorized software.

8. A computer readable medium with program instructions for classification of software in a network system, comprising instructions for a processor to execute in an electronic environment, the instructions including:

determining a software received by a sensor is attempting to execute on a computing system of the sensor;

classifying the software as authorized or unauthorized to execute on the computing system;

gathering information on the software by the sensor and sending the information to one or more actuators for analysis and generation of a directive for one or more targets, if the software is classified as unauthorized to execute;

preparing data about the execution attempt of the unauthorized software;

collecting ancillary data relevant to the one or more actuators for the analyzing the execution attempt and for generating directives for the one or more targets; and

sending the ancillary data to the one or more actuators, and wherein the ancillary data comprises:

network packets which encoded the unauthorized software;

source and destination IP addresses and ports indicating a network connection of the network packets which encoded the unauthorized software;

a packet payload signature or a packet header signature; or

a checksum of the unauthorized software.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jul 20, 2009
From: SOLIDCORE SYSTEMS, INC.
To: MCAFEE, INC.
Reel/Frame 022973/0458 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2005
From: SEBES, E. JOHN; BHARGAVA, RISHI
To: SOLIDCORE SYSTEMS, INC.
Reel/Frame 016767/0988 →