IP Library Patent Application 12158103
Patent Application
App. No. 12/158,103

Malicious Software Detection in a Computing Device

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/158,103
Abstract

A method of scanning for viruses in the memory of a computing device in which only memory pages marked as executable need to be scanned. The trigger for the scan can be either via an API that changes a page from writeable to executable, or via a kernel notification that an executable page has been modified. This invention is efficient, in that it makes much previous scanning of file systems redundant; this saves power and causes devices to execute faster. It is also more secure, as it detects viruses that other methods cannot reach, and does so at the point of execution.

Claims (19)

1 . A method of operating a computing device wherein the device is protected from executable malware by

a. separating executable from non-executable memory on the device; and

b. allowing the execution of any code from executable memory only; and

c. using a first software entity that is capable of scanning only the executable memory on the device for malware.

2 . A method according to claim 1 wherein the memory on the computing device is comprised of pages which can be set as either executable or non executable.

3 . A method according to claim 1 wherein the said first software entity scans the executable memory on the device for malware in response to a notification that the contents of executable memory on the device has been altered.

4 . A method according to claim 3 wherein the notification is that a single page of executable memory has been altered and wherein the first software entity responds by scanning only the page that has been altered.

5 . A method according to claim 4 wherein outstanding notifications or requests for pages to be scanned are held in a queue until they can be processed.

6 . A method according to claim 3 wherein a software application seeking to execute code from altered executable memory is blocked from doing so until the altered memory has been scanned for malware.

7 . A method according to claim 6 wherein detection of malware in altered executable pages causes a software application seeking to execute its contents to be aborted.

8 . A method according to claim 6 wherein detection of malware in altered executable code causes the memory detected as containing the malware to be wiped.

9 . A method according to claim 2 wherein the computing device is arranged such that writable memory cannot be executed and executable memory cannot be written to, and wherein a second software entity is enabled to mark pages in the memory as being either writable or executable.

10 . A method according to claim 9 wherein a software application seeking to execute code from one or more writable memory pages makes a request to the said second software entity that the pages be made executable, and wherein the said second software entity does not fulfill the request until the first software entity has first marked the pages as read-only and then scanned the pages for malware.

11 . A method according to claim 10 wherein the detection of malware in memory pages causes the said memory pages to be marked as writable rather than executable.

12 . A method according to claim 10 wherein the detection of malware in memory pages causes a software application seeking to execute its contents to be aborted.

13 . A method according to claim 10 wherein detection of malware in memory pages causes the contents of the pages to be wiped.

14 . A method of operating a computing device comprising a combination of a method according to claim 3 with a method according to claim 9 .

15 . A computing device programmed to implement a method according to claim 1 .

16 . An operating system for causing a computing device to operate in accordance with a method as claimed in claim 1 .

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2009
From: DIXON, JONATHAN
To: SYMBIAN SOFTWARE LIMITED
Reel/Frame 022322/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2009
From: SYMBIAN LIMITED; SYMBIAN SOFTWARE LIMITED
To: NOKIA CORPORATION
Reel/Frame 022240/0266 →