IP Library Granted Patent US 7,873,999
Granted Patent B1
US 7,873,999 · App. 11/394,717 · Granted Jan 18, 2011

Customized alerting of users to probable data theft

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,873,999
App. No.
11/394,717
Granted
Jan 18, 2011
Kind
B1
Abstract

Computer-implemented methods, systems, and computer-readable media for determining ( 200 ) an action time when an action is taken regarding an executable content; storing ( 205 ) the action time with an indication of the executable content; storing ( 215 ) an entry time and an indication of the entered data source when the data processing system enters one of the plurality of data sources; receiving ( 220 ) an indication that the executable content is infected with a malicious code; receiving ( 225 ) an indication of a data source targeted by the malicious code; scanning the data processing system for the malicious code at a scan time; storing ( 230 ) the scan time; determining ( 245 ) whether one of the plurality of data sources corresponds to the targeted data source; and when it is determined that one of the plurality of data sources corresponds to the targeted data source, determining ( 255 ) whether the entry time occurs after the action time and before the scan time; and when it is determined that the entry time occurs after the action time and before the scan time, sending ( 260 ) a warning regarding the potential threat.

Claims (34)

1. A method for alerting a user regarding a potential threat on a data processing system, the method comprising the steps of:

using the data processing system to execute steps comprising:

determining an action time when an action is taken regarding executable content located at the data processing system, the action time being stored in a protected local storage medium, wherein the action comprises at least one of a first execution of the executable content, creation of the executable content, and modification of the executable content;

tracking data sources visited by the user and entry times of data sources entered by the user using the data processing system, wherein at least one of the entered data sources comprises a website visited by the user;

receiving an indication that the executable content is infected with a malicious code and an indication of a data source targeted by the malicious code, wherein the targeted data source comprises a website;

determining whether an entered data source corresponds to the targeted data source; and

when it is determined that an entered data source corresponds to the targeted data source, determining whether an entry time for the entered data source occurs after the action time, and when it is determined that the entry time for the entered data source occurs after the action time, sending a warning regarding the targeted data source to the user.

2. The method of claim 1 , wherein the executable content comprises one of an executable file and a memory-based content.

3. The method of claim 1 , wherein the malicious code comprises at least one of spyware, a rootkit, a Trojan Horse, a virus, and a worm.

4. The method of claim 1 , wherein the indication of the data source comprises at least one of a uniform resource locator (URL) identifying the website targeted by the malicious code, a hash of the URL, and a domain name identifying a domain of the website targeted by the malicious code.

5. The method of claim 1 , wherein the indication of the data source comprises one of a name of the data source and a location of the data source.

6. The method of claim 1 , wherein the warning comprises at least one of a name of the targeted data source, contact information for the targeted data source, and a type of information targeted by the malicious code.

7. A non-transitory computer-readable medium storing a computer executable program for alerting a user regarding a potential threat on a data processing system, the computer executable program comprising program instructions for:

determining an action time when an action is taken regarding executable content located at the data processing system, the action time being stored in a protected local storage medium, wherein the action comprises at least one of a first execution of the executable content, creation of the executable content, and modification of the executable content;

tracking data sources visited by the user and entry times of data sources entered by the user using the data processing system, wherein at least one of the entered data sources comprises a website visited by the user;

receiving an indication that the executable content is infected with a malicious code and an indication of a data source targeted by the malicious code, wherein the targeted data source comprises a website;

determining whether an entered data source corresponds to the targeted data source; and when it is determined that an entered data source corresponds to the targeted data source, determining whether an entry time for the entered data source occurs after the action time, and when it is determined that the entry time for the entered data source occurs after the action time, sending a warning regarding the targeted data source to the user.

8. The computer-readable medium of claim 7 , wherein the executable content comprises one of an executable file and a memory-based content.

9. The computer-readable medium of claim 7 , wherein the malicious code comprises at least one of spyware, a rootkit, a Trojan Horse, a virus, and a worm.

10. The computer-readable medium of claim 7 , wherein the indication of the data source comprises at least one of a uniform resource locator (URL) identifying the website targeted by the malicious code, a hash of the URL, and a domain name identifying a domain of the website targeted by the malicious code.

11. The computer-readable medium of claim 7 , wherein the indication of the data source comprises one of a name of the data source and a location of the data source.

12. The computer-readable medium of claim 7 , wherein the warning comprises at least one of a name of the targeted data source, contact information for the targeted data source, and a type of information targeted by the malicious code.

13. A data processing system for alerting a user regarding a potential threat, comprising:

a memory device storing a computer executable program for:

determining an action time when an action is taken regarding executable content located at the data processing system, the action time being stored in a protected local storage medium, wherein the action comprises at least one of a first execution of the executable content, creation of the executable content, and modification of the executable content;

tracking data sources visited by the user and entry times of data sources entered by the user using the data processing system, wherein at least one of the entered data sources comprises a website visited by the user;

receiving an indication that the executable content is infected with a malicious code and receiving an indication of a data source targeted by the malicious code, wherein the targeted data source comprises a website;

determining whether an entered data source corresponds to the targeted data source; and

when it is determined that an entered data source corresponds to the targeted data source, determining whether an entry time for the entered data source occurs after the action time, and when it is determined that the entry time for the entered data source occurs after the action time, sending a warning regarding the targeted data source to the user; and a processor, coupled to the memory device, configured to execute the computer program.

14. The data processing system of claim 13 , wherein the executable content comprises one of an executable file and a memory-based content.

15. The data processing system of claim 13 , wherein the malicious code comprises at least one of spyware, a rootkit, a Trojan Horse, a virus, and a worm.

16. The data processing system of claim 13 , wherein the indication of the data source comprises at least one of a uniform resource locator (URL) identifying the website targeted by the malicious code, a hash of the URL, and a domain name identifying a domain of the website targeted by the malicious code.

17. The data processing system of claim 13 , wherein the indication of the data source comprises one of a name of the data source and a location of the data source.

18. The data processing system of claim 13 , wherein the warning comprises at least one of a name of the targeted data source, contact information for the targeted data source, and a type of information targeted by the malicious code.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2006
From: NACHENBERG, CAREY; COLE, DAVID
To: SYMANTEC CORPORATION
Reel/Frame 017715/0822 →