IP Library Granted Patent US 8,856,927
Granted Patent B1
US 8,856,927 · App. 12/954,454 · Granted Oct 7, 2014

System and method for using snapshots for rootkit detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,856,927
App. No.
12/954,454
Granted
Oct 7, 2014
Kind
B1
Abstract

A system, method and computer program product for identifying malicious code running on a computer, including an operating system running on the computer with a data storage device; and a trusted software component running simultaneously with the operating system. An online snapshot process of a current state of the data storage device copies data blocks from the storage device to intermediate storage. Processes running under the control of the operating system have access to the data storage device. A scanning procedure runs under control of the trusted software component that has access to data representing the snapshot of the data storage device from the trusted software component. The scanning procedure analyzes the snapshot of the data storage device for the malicious code, and, in response to a “write” directed to a data block in the snapshot area of the storage device, that data block is written to the intermediate storage.

Claims (32)

1. A method for identifying malicious code running on a computer having a data storage device, the method comprising:

starting an operating system on the computer;

starting a trusted software component running simultaneously with the operating system; performing an online snapshot process of a current state of the data storage device to store a snapshot of the storage media in a backup storage area, performing the snapshot process including:

creating a map of the storage drive absent using drivers of the operating system, the map identifying areas of the data storage device to be copied;

upon receipt of a write request to write a block into an area, determining if the area has been previously copied to the backup storage area by the snapshot process;

for areas not previously copied by the snapshot process, copying data blocks that need to be re-written from the storage device to intermediate storage and updating a pointer in the map of the snapshot;

analyzing data representing the snapshot of the storage media via the trusted software component for snapshot area to detect malicious code; and

replacing files with detected malicious code with trusted/malicious code-free copies of the files.

2. The method of claim 1 , wherein a backup is created based on the snapshot, and further comprising performing an analysis of data representing the backup of the storage media via the trusted software component for backup area to detect malicious code.

3. The method of claim 1 , wherein, after detection of the malicious code the malicious code is removed from the file in which the malicious code was detected, without otherwise damaging the file.

4. The method of claim 1 , further comprising deleting the file in which the malicious code was detected.

5. The method of claim 2 , wherein contents of the intermediate storage are used for restoring a previous state of a storage device and are copied to the backup storage as an incremental backup upon user command.

6. The method of claim 2 , wherein data blocks of the intermediate storage are copied to the backup storage as an incremental backup.

7. The method of claim 1 , wherein the trusted software component is an antivirus.

8. The method of claim 7 , wherein the malicious code is detected by the trusted software component using a comparison with a database of names, fingerprints, signatures, control sums, or CRCs.

9. The method of claim 8 , wherein the malicious code is rootkit.

10. The method of claim 8 , wherein the malicious code is a computer virus.

11. The method of claim 8 , wherein the files being analyzed are hidden files.

12. The method of claim 8 , wherein the files being analyzed are hidden from the file system.

13. The method of claim 8 , wherein the files being analyzed are hidden from an antivirus program.

14. The method of claim 1 , wherein the trusted software component includes a procedure that compares characteristic properties of files on the storage medium with properties stored in a database.

15. A method for identifying malicious code running on a computer having a data storage device, the method comprising:

starting a trusted software component running simultaneously with the operating system, wherein the trusted software component has access to the data storage device;

performing a backup process of a current state of the data storage device, performing the backup process including:

creating a map of the storage drive absent using drivers of the operating system, the map identifying areas of the data storage device to be copied;

upon receipt of a write request to write a block into an area, determining if the area has been previously copied to the backup storage area by the backup process; and

for areas not previously copied by the backup process, copying data blocks that need to be re-written from the storage device to intermediate storage and updating a pointer in the map of the snapshot; and

copying the data from the intermediate storage to the backup storage area;

providing access to the data storage device to processes running under the control of the operating system;

using a trusted software component to scan the backup of the storage media via the trusted software component for detecting malicious code.

16. The method of claim 1 , wherein the trusted software component has the same privilege level as the operating system.

17. The method of claim 1 , wherein performing the online snapshot process further comprises copying the data from the intermediate storage to the backup storage area.

Assignments (11)
REAFFIRMATION AGREEMENT Recorded Aug 28, 2022
From: ACRONIS AG; ACRONIS INTERNATIONAL GMBH; ACRONIS SCS, INC.; ACRONIS, INC.; GROUPLOGIC, INC.; NSCALED INC.; ACRONIS MANAGEMENT LLC; 5NINE SOFTWARE, INC.; ACRONIS GERMANY GMBH; ACRONIS NETHERLANDS B.V.; ACRONIS BULGARIA EOOD; DEVICELOCK, INC.; DEVLOCKCORP LTD; ACRONIS INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 061330/0818 →
SECURITY INTEREST Recorded Dec 19, 2019
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 051418/0119 →
RELEASE OF SECURITY INTEREST Recorded Oct 21, 2019
From: OBSIDIAN AGENCY SERVICES, INC.
To: ACRONIS INTERNATIONAL GMBH; GROUPLOGIC, INC.
Reel/Frame 050783/0893 →
SECURITY INTEREST Recorded Jul 26, 2017
From: ACRONIS INTERNATIONAL GMBH; GROUPLOGIC, INC.
To: OBSIDIAN AGENCY SERVICES, INC., AS COLLATERAL AGENT
Reel/Frame 043350/0186 →
PATENT SECURITY AGREEMENT Recorded Feb 27, 2014
From: ACRONIS INTERNATIONAL GMBH
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 032366/0328 →
RELEASE OF SECURITY INTEREST Recorded Feb 25, 2014
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: ACRONIS INC.; ACRONIS, INC.; ACRONIS INTERNATIONAL GMBH
Reel/Frame 032296/0397 →
SECURITY AGREEMENT Recorded Apr 20, 2012
From: ACRONIS INTERNATIONAL GMBH
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 028081/0061 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2012
From: ACRONIS INC.
To: ACRONIS INC. LTD.
Reel/Frame 027898/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2012
From: ACRONIS INC. LTD.
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 027898/0795 →
SECURITY AGREEMENT Recorded Jun 20, 2011
From: ACRONIS INC.
To: SILICON VALLEY BANK
Reel/Frame 026465/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2010
From: BELOUSSOV, SERGUEI M.; LYADVINSKY, MAXIM V.
To: ACRONIS INC.
Reel/Frame 025422/0507 →