IP Library Granted Patent US 8,528,089
Granted Patent B2
US 8,528,089 · App. 11/641,043 · Granted Sep 3, 2013

Known files database for malware elimination

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,528,089
App. No.
11/641,043
Granted
Sep 3, 2013
Kind
B2
Abstract

A method, system, and computer program product for identifying files that are found during a malware scan, thus enabling them to be excluded from further analysis. A method for handling a potential malware file comprises the steps of scanning a plurality of files to identify at least one file as potential malware, querying a database to determine whether the at least one file is known, and handling the at least one file based on whether the at least one file is known.

Claims (46)

1. A method, comprising:

scanning a plurality of files to identify at least one file as potential malware;

generating information identifying the at least one file, wherein the generated information comprises a secure hash of the at least one file that is generated using a cryptographic hash function;

querying a database to determine whether the at least one scanned file identified as potential malware is already known to be free from potential malware or known to be representative of malware, wherein the secure hash is evaluated in order to determine its status as being legitimate or representative of malware, wherein the database includes at least one entry representing a file known to legitimate and at least one entry representing a file known to be representative of malware, wherein each entry of the database represents either a file known to be legitimate or a file known to be representative of malware, and wherein each entry further includes information indicating whether the representation of the file is legitimate or representative of malware;

excluding the at least one file from further analysis if the at least one file is known; and

performing further analysis on the at least one file if the at least one file is not known.

2. The method of claim 1 , wherein the querying step comprises the steps of:

querying the database to obtain information indicating whether the at least one file is known.

3. The method of claim 2 , wherein the step of querying the database to obtain information indicating whether the at least one file is known comprises the steps of:

transmitting a query including the generated information identifying the at least one file to a remote database; and

receiving from the remote database the information indicating whether the at least one file is known.

4. The method of claim 1 , wherein the at least one cryptographic hash function comprises at least one of MD5, MD4, SHA1, SHA256, and CRC32.

5. The method of claim 2 , wherein the step of querying the database to obtain information indicating whether at least one file is known comprises the step of:

querying a local database to obtain the information indicating whether the at least one file is known.

6. A system comprising:

a processor operable to execute computer program instructions;

a memory coupled to the processor and operable to store computer program instructions executable by the processor such that the system is configured for:

scanning a plurality of files to identify at least one file as potential malware;

generating information identifying the at least one file, wherein the generated information comprises a secure hash of the at least one file that is generated using a cryptographic hash function;

querying a database to determine whether the at least one scanned file identified as potential malware is already known to be free from potential malware or known to be representative of malware, wherein the secure hash is evaluated in order to determine its status as being legitimate or representative of malware, wherein the database includes at least one entry representing a file known to legitimate and at least one entry representing a file known to be representative of malware, wherein each entry of the database represents either a file known to be legitimate or a file known to be representative of malware, and wherein each entry further includes information indicating whether the representation of the file is legitimate or representative of malware;

excluding the at least one file from further analysis if the at least one file is known; and

performing further analysis on the at least one file if the at least one file is not known.

7. The system of claim 6 , wherein the querying step comprises the steps of:

querying the database to obtain information indicating whether the at least one file is known.

8. The system of claim 7 , wherein the step of querying the database to obtain information indicating whether the at least one file is known comprises the steps of:

transmitting a query including the generated information identifying the at least one file to a remote database; and

receiving from the remote database the information indicating whether the at least one file is known.

9. The system of claim 6 , wherein the at least one cryptographic hash function comprises at least one of MD5, MD4, SHA1, SHA256, and CRC32.

10. The system of claim 7 , wherein the step of querying the database to obtain information indicating whether the at least one file is known comprises the step of:

querying a local database to obtain the information indicating whether the at least one file is known.

11. A computer program product comprising:

a non-transitory computer readable storage medium;

computer program instructions, recorded on the computer readable storage medium, executable by a processor, for performing:

scanning a plurality of files to identify at least one file as potential malware;

generating information identifying the at least one file, wherein the generated information comprises a secure hash of the at least one file that is generated using a cryptographic hash function;

querying a database to determine whether the at least one scanned file identified as potential malware is already known to be free from potential malware or known to be representative of malware, wherein the secure hash is evaluated in order to determine its status as being legitimate or representative of malware, wherein the database includes at least one entry representing a file known to legitimate and at least one entry representing a file known to be representative of malware, wherein each entry of the database represents either a file known to be legitimate or a file known to be representative of malware, and wherein each entry further includes information indicating whether the representation of the file is legitimate or representative of malware;

excluding the at least one file from further analysis if the at least one file is known; and

performing further analysis on the at least one file if the at least one file is not known.

12. The computer program product of claim 11 , wherein the querying step comprises the steps of:

querying the database to obtain information indicating whether the at least one file is known.

13. The computer program product of claim 12 , wherein the step of querying the database to obtain information indicating whether the at least one file is known comprises the steps of:

transmitting a query including the generated information identifying the at least one file to a remote database; and

receiving from the remote database the information indicating whether the at least one file is known.

14. The computer program product of claim 11 , wherein the at least one cryptographic hash function comprises at least one of MD5, MD4, SHA1, SHA256, and CRC32.

15. The computer program product of claim 12 , wherein the step of querying the database to obtain information indicating whether the at least one file is known comprises the step of:

querying a local database to obtain the information indicating whether the at least one file is known.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2006
From: GRYAZNOV, DMITRY O.
To: MCAFEE, INC.
Reel/Frame 018722/0674 →