IP Library Patent Application 12570026
Patent Application
App. No. 12/570,026

AUTOMATED RECOVERY FROM A SECURITY EVENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/570,026
Abstract

In embodiments of the present invention improved capabilities are described for automated recovery from a security event. Automated recovery includes detecting a security event, using metadata to select a target backup for recovery, bringing the recovered environment online in a quarantine mode, initiating automated recovery of the environment, and running at least one of a generic remediation process and a specific remediation process in the quarantine mode prior to releasing the environment from quarantine mode. Related user interfaces, applications, and computer program products are disclosed.

Claims (17)

1 . A computer-implemented method for automated recovery from a security event in a computer environment that maintains separation of user data from other system components to facilitate agent-based backup and restoration of the environment, comprising:

detecting a security event;

using metadata to select a target backup for recovery;

bringing the recovered environment online in a quarantine mode;

initiating automated recovery of the environment; and

running at least one of a generic remediation process and a specific remediation process in the quarantine mode prior to releasing the environment from quarantine mode.

2 . The method of claim 1 , further comprising reviewing the target to confirm the absence of a repetition of the security event.

3 . The method of claim 1 , wherein detection of the security event is by at least one of a detection facility, a HIPS facility, an IPS facility, a content analysis facility, a user detection and a deterministic detection.

4 . The method of claim 1 , wherein selection of a target backup is based on at least one of a time attribute of a known-to-be-infected file, presence of a known malicious element, content analysis to determine a suspicious event, linking of a threat to a specific vulnerability and identification of a configuration change.

5 . The method of claim 1 , wherein the known malicious element is at least one of an infected file, a malicious registry key, an infected system primitive, and a malicious behavior.

6 . The method of claim 1 , wherein the quarantine mode uses at least one of perimeter protection of the environment by firewall and device control, use of the operating system of the environment in safe mode, initiation of a preboot state of the environment, and establishment of a virtualization layer to facilitate cleanup from a hypervisor.

7 . The method of claim 1 , wherein the generic remediation process brings an outdated image to a current image.

8 . The method of claim 1 , wherein the generic remediation process comprises at least one of a system patch, an application patch, an update to an anti-virus facility, running an operational tool, re-applying a corporate configuration, and an operational PC lifecycle management procedure.

9 . The method of claim 1 , wherein the specific remediation process comprises deploying a specific patch based on detection of a requirement for protection, wherein the specific remediation process is based on the metadata.

10 . The method of claim 1 , wherein the specific remediation process comprises changing a configuration of the target to prevent re-infection, wherein the specific remediation process is based on the metadata.

11 . The method of claim 1 , wherein the metadata is at least one of operational and security metadata.

12 . The method of claim 1 , wherein the recovery is at least one of a remediation and a restoration.

Assignments (5)
ASSIGNMENT OF SECURITY INTEREST Recorded Feb 3, 2014
From: JPMORGAN CHASE BANK, N.A.
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032152/0883 →
CHANGE OF NAME Recorded Apr 11, 2013
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 030194/0299 →
SECURITY INTEREST Recorded May 11, 2012
From: RBC EUROPE LIMITED, AS EXISTING ADMINISTRATION AGENT AND COLLATERAL AGENT
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 028198/0285 →
SECURITY AGREEMENT Recorded Aug 8, 2011
From: SOPHOS LIMITED F/K/A SOPHOS PLC
To: ROYAL BANK OF CANADA EUROPE LIMITED, AS COLLATERAL AGENT
Reel/Frame 026717/0424 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2009
From: LYNE, JAMES I.G.; KEENE, DAVID P.; PAICE, SHAUN; MANRING, BRADLEY A.C.
To: SOPHOS PLC
Reel/Frame 023303/0841 →