IP Library Granted Patent US 8,087,085
Granted Patent B2
US 8,087,085 · App. 11/946,003 · Granted Dec 27, 2011

Wireless intrusion prevention system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,087,085
App. No.
11/946,003
Granted
Dec 27, 2011
Kind
B2
Abstract

A wireless intrusion prevention system and method to prevent, detect, and stop malware attacks is presented. The wireless intrusion prevention system monitors network communications for events characteristic of a malware attack, correlates a plurality of events to detect a malware attack, and performs mitigating actions to stop the malware attack.

Claims (17)

1. A malware detection and mitigation system, comprising:

a plurality of mobile devices configured to execute a respective plurality of monitors operably adapted to scan network communications to determine destinations of the network communications, amounts of network traffic including one or more of the network communications to the destinations over time intervals, and average packet size of the network communications;

a plurality of detection agents each executing on a respective one of the mobile devices and operably adapted to communicate with at least one of the plurality of monitors of the respective one of the plurality of mobile devices, to determine normal amounts of network traffic over the time intervals to the destinations, to determine normal average packet size of the network communications to the destinations, to detect changes in the amounts of network traffic over the time intervals to a particular destination relative to the determined normal amount of network traffic to the particular destination over the time intervals, to detect changes in the average packet size of the network communications to the particular destination relative to the determined normal average packet size of the network communications to the particular detection, to detect a malware attack based on at least one of detected changes in the amount of network traffic over the time intervals, detected changes in the average packet size, and the destinations of the network communications, and to communicate an attack indication when the malware attack is detected; and

a network device separate from the one of the plurality of mobile devices, wherein the network device comprises a mitigating agent operably adapted to communicate with the plurality of detection agents via a mobile network to receive the attack indication and to trigger a mitigating action in response in the mobile network to the attack indication.

2. The malware detection and mitigation system of claim 1 , wherein the mitigating action comprises at least one mitigating action directed to the one of the plurality of mobile devices and at least one mitigating action directed to a network element.

3. The malware detection and mitigation system of claim 1 , wherein the network communications are wireless network communications.

4. The malware detection and mitigation system of claim 1 , wherein the malware attack is selected from the group consisting of a battery draining malware attack, a denial of service malware attack, and a mobile worm malware attack.

5. The malware detection and mitigation system of claim 1 , wherein the plurality of detection agents are configured to detect changes in the amount of the network traffic over the time intervals and changes in the average packet size of the communications that are correlated with a characteristic of the malware attack, the characteristic selected from the group consisting of an increase in network traffic to the particular destination and an increase in network traffic to the particular destination and a decrease in the average packet size of the network communications to the particular destination.

6. The malware detection and mitigation system of claim 1 , further comprising one or more network elements configured to execute respective ones of a second plurality of monitors.

7. The malware detection and mitigation system of claim 6 , wherein the one or more network elements are each selected from the group consisting of a handset, a mobile device, a gateway, a traffic sniffer, a honeypot, a router, a switch, and a register.

8. The malware detection and mitigation system of claim 1 , wherein the mitigating action is selected from the group consisting of reporting the malware attack, disabling the network communications, restricting the network communications, ignoring the network communications, performing a malware scan, and intercepting the network communications and forwarding to the security center.

9. The malware detection and mitigation system of claim 1 , wherein the plurality of detection agents are configured to detect the malware attack in response to detecting a packet bound for an inactive mobile device.

10. The malware detection and mitigation system of claim 1 , wherein the plurality of detection agents are further configured to detect a malware attack in response to detecting a program sent to a plurality of mobile devices.

11. The malware detection and mitigation system of claim 1 ,

wherein the monitors are further configured to determine senders of the network communications,

wherein the detection agents are configured to determine an identity of a sender associated with the malware attack and to provide information indicative of the identity of a sender in the attack indication, and

wherein the mitigating agent of the network device is configured to instruct the mobile devices to drop packets from the sender associated with the malware attack.

Assignments (19)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034036/0904 →
SECURITY INTEREST Recorded Oct 23, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034037/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2011
From: SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 025693/0282 →
RELEASE OF SECURITY INTEREST Recorded Jul 30, 2010
From: R.H. BOOK, LLC
To: S MOBILE SYSTEMS, INC.
Reel/Frame 024770/0447 →
SECURITY AGREEMENT Recorded Apr 15, 2010
From: S MOBILE SYSTEMS, INC.
To: R.H. BOOK, LLC
Reel/Frame 024239/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2008
From: HU, GUONING; VENUGOPAL, DEEPAK; BHARDWAJ, SHANTANU
To: SMOBILE SYSTEMS, INC.
Reel/Frame 020658/0696 →