IP Library Patent Application 11386595
Patent Application
App. No. 11/386,595

Method and system for denying pestware direct drive access

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/386,595
Abstract

A method and system for denying pestware direct drive access on a computer is described. In one illustrative embodiment, a driver intercepts a direct drive access by a process running on the computer, and a user interface reports the direct drive access to a user and permits or denies the direct drive access in response to input from the user. In other illustrative embodiments, the user is given the option of permitting or denying a particular running process direct drive access on a one-time or a permanent basis.

Claims (47)

1 . A method, comprising:

intercepting a direct drive access by a process running on a computer;

reporting the direct drive access to a user; and

performing one of permitting and denying the direct drive access in accordance with input from the user.

2 . The method of claim 1 , wherein the direct drive access is permitted automatically without the reporting and without input from the user, when the process is associated with an operating system of the computer.

3 . The method of claim 1 , wherein the direct drive access is permitted automatically without the reporting and without input from the user, when the process is associated with an application in a set of authorized applications.

4 . The method of claim 1 , wherein the direct drive access is denied automatically without the reporting and without input from the user, when the process is associated with an application in a set of unauthorized applications.

5 . The method of claim 1 , further comprising:

adding, to a set of authorized applications, an application associated with the process in response to input from the user, processes associated with applications in the set of authorized applications being permitted unconditionally to perform direct drive accesses on the computer, without the reporting and without input from the user.

6 . The method of claim 1 , further comprising:

adding, to a set of unauthorized applications, an application associated with the process in response to input from the user, processes associated with applications in the set of unauthorized applications being prevented unconditionally from performing direct drive accesses on the computer, without the reporting and without input from the user.

7 . The method of claim 1 , wherein intercepting includes hooking at least one direct-drive-access application program interface (API) associated with the operating system.

8 . The method of claim 7 , wherein an original, unmodified version of the at least one direct-drive-access API is hooked before any other process running on the computer has hooked the original, unmodified version of the at least one direct-drive-access API.

9 . A method, comprising:

intercepting a direct drive access by a process running on a computer;

permitting the direct drive access, when the process is associated with an operating system of the computer;

permitting the direct drive access, when the process is associated with an application in a set of authorized applications;

denying the direct drive access, when the process is associated with an application in a set of unauthorized applications; and

performing the following, when the process is associated with neither the operating system, an application in the set of authorized applications, nor an application in the set of unauthorized applications:

reporting the direct drive access to a user;

permitting the direct drive access without adding an application associated with the process to the set of authorized applications in response to a first input from the user;

permitting the direct drive access and adding an application associated with the process to the set of authorized applications in response to a second input from the user;

denying the direct drive access without adding an application associated with the process to the set of unauthorized applications in response to a third input from the user; and

denying the direct drive access and adding an application associated with the process to the set of unauthorized applications in response to a fourth input from the user, the first, second, third, and fourth inputs being mutually exclusive.

10 . The method of claim 9 , wherein intercepting includes hooking at least one direct-drive-access application program interface (API) associated with the operating system.

11 . The method of claim 10 , wherein an original, unmodified version of the at least one direct-drive-access API is hooked before any other process running on the computer has hooked the original, unmodified version of the at least one direct-drive-access API.

12 . A system, comprising:

a driver configured to intercept a direct drive access by a process running on a computer; and

a user interface configured to:

report the direct drive access to a user; and

perform one of permitting and denying the direct drive access in accordance with input from the user.

13 . The system of claim 12 , wherein the user interface is configured to permit the direct drive access automatically without reporting the direct drive access to the user and without input from the user, when the process is associated with an operating system of the computer.

14 . The system of claim 12 , wherein the user interface is configured to permit the direct drive access automatically without reporting the direct drive access to the user and without input from the user, when the process is associated with an application in a set of authorized applications.

15 . The system of claim 12 , wherein the user interface is configured to deny the direct drive access automatically without reporting the direct drive access to the user and without input from the user, when the process is associated with an application in a set of unauthorized applications.

16 . The system of claim 12 , wherein the user interface is further configured to:

add, to a set of authorized applications, an application associated with the process in response to input from the user; and

permit unconditionally processes associated with applications in the set of authorized applications to perform direct drive accesses on the computer, without reporting the direct drive accesses to the user and without input from the user.

17 . The system of claim 12 , wherein the user interface is further configured to:

add, to a set of unauthorized applications, an application associated with the process in response to input from the user; and

prevent unconditionally processes associated with applications in the set of unauthorized applications from performing direct drive accesses on the computer, without reporting the direct drive accesses to the user and without input from the user.

18 . The system of claim 12 , wherein the driver is configured to intercept the direct drive access by hooking at least one direct-drive-access application program interface (API) associated with the operating system.

19 . The system of claim 18 , wherein the driver is configured to hook an original, unmodified version of the at least one direct-drive-access API before any other process running on the computer has hooked the original, unmodified version of the at least one direct-drive-access API.

20 . A computer-readable storage medium containing program instructions, comprising:

a first instruction segment configured to intercept a direct drive access by a process running on a computer; and

a second instruction segment configured to:

report the direct drive access to a user; and

perform one of permitting and denying the direct drive access in accordance with input from the user.

Assignments (2)
CHANGE OF NAME Recorded Sep 13, 2012
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 028953/0917 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2006
From: NICHOLS, TONY
To: WEBROOT SOFTWARE, INC.
Reel/Frame 017685/0601 →