IP Library Granted Patent US 8,578,496
Granted Patent B1
US 8,578,496 · App. 12/648,853 · Granted Nov 5, 2013

Method and apparatus for detecting legitimate computer operation misrepresentation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,578,496
App. No.
12/648,853
Granted
Nov 5, 2013
Kind
B1
Abstract

A method for detecting legitimate computer operation misrepresentation is provided. In some embodiments, the method comprises monitoring internet activity associated with a user computer, comparing the internet activity with suspicious feature information to produce a comparison result, wherein the suspicious feature information comprises at least one image that misrepresents at least one legitimate computer operation, identifying fraudulent software based on the comparison result, wherein the comparison result indicates a portion of the internet activity that misrepresents the at least one legitimate computer operation and mitigating activities associated with the identified fraudulent software.

Claims (35)

1. A method for using one or more processors to detect legitimate computer operation misrepresentation in memory, comprising:

monitoring internet activity associated with a user computer;

comparing, using at least one computer processor, a first set of at least one computer graphical image received from the internet activity with a second set of at least one computer graphical image associated with electronically stored suspicious feature information to produce a comparison result, wherein the at least one computer graphical image of the second set misrepresents at least one legitimate computer operation to increase a likelihood of malicious computer functions;

identifying fraudulent software based on the comparison result between the first and second sets of computer graphical images, wherein the comparison result indicates a portion of the internet activity associated with the user computer that misrepresents the at least one legitimate computer operation; and

mitigating, on the user computer, activities associated with the identified fraudulent software.

2. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises preventing execution of malware associated with the identified fraudulent software.

3. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises blocking transmission of malware to the user computer.

4. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises terminating at least one webpage associated with the identified fraudulent software.

5. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises terminating the identified fraudulent software.

6. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises determining at least one computer setting modification caused by malware.

7. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises communicating the identified fraudulent software to a backend server.

8. The method of claim 1 , wherein mitigating activities associated with the identified fraudulent software further comprises terminating execution of malware associated with the identified fraudulent software.

9. The method of claim 1 further comprises transforming the internet activity and the suspicious feature information into the comparison result.

10. The method of claim 1 , wherein comparing the internet activity with the suspicious feature information further comprises identifying at least one image depicting at least one of media player software or security software.

11. The method of claim 1 , wherein comparing the internet activity with the suspicious feature information further comprises identifying at least one computer graphical image depicting at least one fraudulent alert associated with at least one of media player software or security software.

12. An apparatus for using one or more processors to detect legitimate computer operation misrepresentation in memory, comprising:

means for monitoring internet activity associated with a user computer;

means for comparing a first set of at least one computer graphical image received from the internet activity with a second set of at least one computer graphical image associated with electronically stored suspicious feature information to produce a comparison result, wherein the at least one computer graphical image of the second set misrepresents a legitimate computer operation to increase a likelihood of malicious computer functions;

means for identifying fraudulent software based on the comparison result between the first and second sets of computer graphical images, wherein the comparison result indicates a portion of the internet activity associated with the user computer that misrepresents the at least one legitimate computer operation; and

means for handling, on the user computer, activities associated with the identified fraudulent software.

13. The apparatus of claim 12 further comprising means for transforming the internet activity and the suspicious feature information into the comparison result.

14. The apparatus of claim 12 further comprising means for preventing execution of malware associated with the identified fraudulent software.

15. The apparatus of claim 12 further comprising means for blocking transmission of malware to the user computer.

16. The apparatus of claim 12 further comprising means for terminating at least one webpage associated with the identified fraudulent software.

17. A non-transitory computer-readable-storage medium comprising one or more processor executable instructions that, when executed by at least one processor, causes the at least one processor to:

monitor internet activity associated with a user computer;

compare a first set of at least one computer graphical image received from the internet activity with a second set of at least one computer graphical image associated with electronically stored suspicious feature information to produce a comparison result, wherein the at least one computer graphical image of the second set misrepresents a legitimate computer operation to increase a likelihood of malicious computer functions;

identify fraudulent software based on the comparison result between the first and second sets of computer graphical images, wherein the comparison result indicates a portion of the internet activity associated with the user computer that misrepresents the at least one legitimate computer operation; and

mitigate, on the user computer, activities associated with the identified fraudulent software.

18. The computer-readable-storage medium of claim 17 further comprising one or more processor-executable instructions that, when executed by the at least one processor, causes the at least one processor to:

terminate execution of the identified fraudulent software.

19. The computer-readable-storage medium of claim 17 further comprising one or more processor-executable instructions that, when executed by the at least one processor, causes the at least one processor to:

prevent execution of malware on the user computer.

20. The computer-readable-storage medium of claim 17 further comprising one or more processor-executable instructions that, when executed by the at least one processor, causes the at least one processor to:

block transmission of malware to the user computer.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2009
From: KRISHNAPPA, BHASKAR
To: SYMANTEC CORPORATION
Reel/Frame 023714/0219 →