IP Library Granted Patent US 8,291,493
Granted Patent B2
US 8,291,493 · App. 11/987,088 · Granted Oct 16, 2012

Windows registry modification verification

Assignee: McAfee, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,291,493
App. No.
11/987,088
Granted
Oct 16, 2012
Kind
B2
Abstract

A method and system is provided by which unauthorized changes to the registry may be detected and that provides the capability to verify whether registry, or other system configuration data, changes that occur on a computer system are undesirable or related to possible malware attack before the changes become effective or are saved on the system. A method for verifying changes to system configuration data in a computer system includes generating an identifier representing an entry in the system configuration data, packaging the identifier, and sending the packaged identifier to a client for verification. The identifier may be generated by hashing the first portion of the entry and the second portion of the entry to generate the identifier, or by filtering the first portion of the entry and hashing the filtered first portion of the entry and the second portion of the entry to generate the identifier.

Claims (63)

1. A method for verifying changes to system configuration data in a computer system comprising:

generating an identifier through a hashing activity, the identifier representing an entry in the system configuration data that is associated with setting a default home page for an Internet connection;

packaging the identifier;

sending the packaged identifier to a client for verification, wherein the client comprises software configured to process the identifier in order to determine whether the entry was authorized, whether the home page has a match in a database that includes a plurality of web pages, and whether the home page is free from malware; and

providing known identifier data to the client to validate a plurality of particular identifiers, wherein at least some of the particular identifiers are merged from a plurality of different register entries in order to package them as either desirable or undesirable.

2. The method of claim 1 , wherein the entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and the identifier is generated by:

hashing the first portion of the entry and the second portion of the entry to generate the identifier.

3. The method of claim 1 , wherein the entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and the identifier is generated by:

filtering the first portion of the entry; and

hashing the filtered first portion of the entry and the second portion of the entry to generate the identifier.

4. The method of claim 1 , wherein the system configuration data comprises a registry.

5. The method of claim 4 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

hashing the key and the value to generate the identifier.

6. The method of claim 4 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

filtering the key; and

hashing the filtered key and the value to generate the identifier.

7. A method for verifying changes to system configuration data, the system configuration data comprising a plurality of entries, in a computer system comprising:

generating an identifier through a hashing activity, the identifier representing an entry in the system configuration data that is associated with setting a default home page for an Internet connection;

packaging the identifier;

sending the packaged identifier to a client for verification, wherein the client comprises software configured to process the identifier in order to determine whether the entry was authorized, whether the home page has a match in a database that includes a plurality of web pages, and whether the home page is free from malware; and

providing known identifier data to the client to validate a plurality of particular identifiers, wherein at least some of the particular identifiers are merged from a plurality of different register entries in order to package them as either desirable or undesirable.

8. The method of claim 7 , wherein an entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and an identifier is generated by:

hashing the first portion of the entry and the second portion of the entry to generate the identifier.

9. The method of claim 7 , wherein an entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and an identifier is generated by:

filtering the first portion of the entry; and

hashing the filtered first portion of the entry and the second portion of the entry to generate the identifier.

10. The method of claim 7 , wherein an entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and an identifier is generated by:

hashing the at least portion of the plurality of entries to generate the identifier.

11. The method of claim 7 , wherein the system configuration data comprises a registry.

12. The method of claim 11 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

hashing the key and the value to generate the identifier.

13. The method of claim 11 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

filtering the key; and

hashing the filtered key and the value to generate the identifier.

14. The method of claim 11 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

hashing the at least portion of the plurality of entries to generate the identifier.

15. A system for handling sharing violations in a computer system comprising:

a processor configured to execute computer program instructions;

a memory configured to store computer program instructions executable by the processor; and

computer program instructions stored in the memory and executable for:

generating an identifier through a hashing activity, the identifier representing an entry in system configuration data that is associated with setting a default home page for an Internet connection;

packaging the identifier;

sending the packaged identifier to a client for verification, wherein the client comprises software configured to process the identifier in order to determine whether the entry was authorized, whether the home page has a match in a database that includes a plurality of web pages, and whether the home page is free from malware; and

providing known identifier data to the client to validate a plurality of particular identifiers, wherein at least some of the particular identifiers are merged from a plurality of different register entries in order to package them as either desirable or undesirable.

16. The system of claim 15 , wherein an entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and an identifier is generated by:

hashing the first portion of the entry and the second portion of the entry to generate the identifier;

filtering the first portion of the entry and hashing the filtered first portion of the entry and the second portion of the entry to generate the identifier.

17. The system of claim 15 , wherein the system configuration data comprises a registry.

18. The system of claim 17 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

hashing the key and the value to generate the identifier;

filtering the key and hashing the filtered key and the value to generate the identifier.

19. A non-transitory computer program product for performing operations comprising:

generating an identifier through a hashing activity, the identifier representing an entry in system configuration data that is associated with setting a default home page for an Internet connection;

packaging the identifier;

sending the packaged identifier to a client for verification, wherein the client comprises software configured to process the identifier in order to determine whether the entry was authorized, whether the home page has a match in a database that includes a plurality of web pages, and whether the home page is free from malware; and

providing known identifier data to the client to validate a plurality of particular identifiers, wherein at least some of the particular identifiers are merged from a plurality of different register entries in order to package them as either desirable or undesirable.

20. The computer program product of claim 19 , wherein an entry in the system configuration data comprises a first portion identifying the entry and a second portion including a value of the entry and an identifier is generated by:

hashing the first portion of the entry and the second portion of the entry to generate the identifier;

filtering the first portion of the entry and hashing the filtered first portion of the entry and the second portion of the entry to generate the identifier.

21. The computer program product of claim 19 , wherein the system configuration data comprises a registry.

22. The computer program product of claim 21 , wherein the entry in the registry comprises a key and a value and the identifier is generated by:

hashing the key and the value to generate the identifier;

filtering the key and hashing the filtered key and the value to generate the identifier.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2007
From: FAIETA, ALESSANDRO; BEACH, JAMESON; BELL, DOUGLAS
To: MCAFEE, INC.
Reel/Frame 020203/0078 →
Continuity (1)
Related Publication 20090138967A1 · May 28, 2009