IP Library Granted Patent US 8,370,941
Granted Patent B1
US 8,370,941 · App. 12/116,063 · Granted Feb 5, 2013

Rootkit scanning system, method, and computer program product

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,370,941
App. No.
12/116,063
Granted
Feb 5, 2013
Kind
B1
Abstract

A rootkit scanning system, method, and computer program product are provided. In use, at least one hook is traversed. Further, code is identified based on the traversal of the at least one hook. In addition, the code is scanned for at least one rootkit.

Claims (37)

1. A computer program product embodied on a non-transitory computer readable medium for performing operations, comprising:

traversing a chain of hooks, the chain of hooks including a plurality of hooks in which a succeeding hook is called by a previous hook in the chain, each hook having an associated calling address;

identifying code, based on the traversal of the chain of hooks, by identifying that the calling address is associated with the code;

determining that the chain of hooks is associated with at least one detour, which involves a redirection from an intended destination of a computer to a different location that points to the code;

scanning the code identified by the traversing of the chain of hooks for at least one rootkit, which includes malicious code, wherein the scanning includes a comparison activity associated with a plurality of signatures associated with a plurality of rootkits;

restoring the hook from pointing to the detour to pointing to the intended destination of the computer;

determining whether the at least one detour is destined for at least one additional detour; and

traversing the at least one additional detour, based on the determination.

2. The computer program product of claim 1 , wherein the intended destination includes a kernel space or a user space.

3. The computer program product of claim 1 , wherein the identified code is identified by following code to which the at least one detour points.

4. The computer program product of claim 1 , wherein the traversing and the identifying occurs in kernel space or user space.

5. The computer program product of claim 1 , wherein the scanning occurs in kernel space or user space.

6. The computer program product of claim 1 , wherein the code includes one of driver code, dynamic link library code, a system service, a function, an application programming interface (API), a library, a process, a file on disk, and a registry.

7. The computer program product of claim 1 , wherein the code is in memory.

8. The computer program product of claim 1 , and further comprising computer code for reacting, based on the scanning.

9. The computer program product of claim 8 , wherein the reacting includes preventing the code from further executing.

10. The computer program product of claim 8 , wherein the reacting includes deleting the code.

11. The computer program product of claim 10 , wherein a file including the code is flagged for being deleted in response to a reboot event.

12. A method, comprising:

traversing a chain of hooks, the chain of hooks including a plurality of hooks in which a succeeding hook is called by a previous hook in the chain, each hook having an associated calling address;

identifying code, based on the traversal of the chain of hooks, by identifying that the calling address is associated with the code;

determining that the chain of hooks is associated with at least one detour, which involves a redirection from an intended destination of a computer to a different location that points to the code;

scanning the code identified by the traversing of the chain of hooks for at least one rootkit, which includes malicious code, wherein the scanning includes a comparison activity associated with a plurality of signatures associated with a plurality of rootkits;

restoring the hook from pointing to the detour to pointing to the intended destination of the computer;

determining whether the at least one detour is destined for at least one additional detour; and

traversing the at least one additional detour, based on the determination.

13. A system, comprising:

a first module configured for:

traversing a chain of hooks, the chain of hooks including a plurality of hooks in which a succeeding hook is called by a previous hook in the chain, each hook having an associated calling address;

identifying code, based on the traversal of the chain of hooks, by identifying that the calling address is associated with the code; and

determining that the chain of hooks is associated with at least one detour, which involves a redirection from an intended destination of a computer to a different location that points to the code;

a second module in communication with the first module, the second module configured for:

scanning the code identified by the traversing of the chain of hooks for at least one rootkit, which includes malicious code, wherein the scanning includes a comparison activity associated with a plurality of signatures associated with a plurality of rootkits;

restoring the hook from pointing to the detour to pointing to the intended destination of the computer;

determining whether the at least one detour is destined for at least one additional detour; and

traversing the at least one additional detour, based on the determination;

wherein the first module and the second module are installed on a computer including a processor, and memory in communication via a bus.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2008
From: PHAM, KHAI N.; KAPOOR, ADITYA; RAMACHETTY, HARINATH V.; MATHUR, RACHIT
To: MCAFEE, INC.
Reel/Frame 020910/0332 →