IP Library Granted Patent US 9,311,482
Granted Patent B2
US 9,311,482 · App. 13/200,504 · Granted Apr 12, 2016

Inoculator and antibody for computer security

Inventors: Michael Gregory Hoglund (Monte Sereno, CA); Shawn Michael Bracken (Pinole, CA)
Assignee: COUNTERTACK, INC.
G06F21/568G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,311,482
App. No.
13/200,504
Granted
Apr 12, 2016
Kind
B2
Abstract

In an embodiment of the invention, a method includes: determining, in a computer, an area where an undesired computer program will reside; and providing a data object in the area, so that the data object is an antibody that provides security to the computer and immunity against the undesired program. Another embodiment of the invention also provides an apparatus (or system) that can be configured to perform at least some of the above functionalities.

Claims (44)

1. A method comprising:

determining, in a computer, a location where an undesired computer program is configured to reside upon installation on the computer;

providing, to the computer, a data object to occupy the determined installation location of the undesired computer program in the computer to prevent the undesired computer program from being installed in the determined installation location on the computer; and

providing a null configuration object in a second location in the computer, wherein the null configuration object is associated with the data object.

2. The method of claim 1 , wherein the null configuration object comprises a null registry key.

3. The method of claim 1 , wherein the null configuration object comprises a null configuration information.

4. The method of claim 1 , further comprising: preventing a deletion or modification of the data object.

5. The method of claim 4 , wherein preventing the deletion or modification of the data object comprises:

setting a security permission for the data object.

6. The method of claim 4 , wherein preventing the deletion or modification of the data object comprises:

modifying the data object to an object type that differs from the undesired program.

7. The method of claim 6 , wherein preventing the deletion or modification of the data object comprises:

placing a second data object in the data object type.

8. The method of claim 1 , further comprising:

generating a security event in response to an access of the data object.

9. The method of claim 1 , further comprising:

generating a security event in response to an access of the null configuration object.

10. An apparatus comprising:

a computer device including an inoculator engine configured to determine, in a computer, a location where an undesired computer program is configured to reside upon installation on the computer; provide, to the computer, a data object to occupy the determined installation location of the undesired computer program in the computer to prevent the undesired computer program from being installed in the determined installation location on the computer; and provide a null configuration object in a second location in the computer, wherein the null configuration object is associated with the data object.

11. The apparatus of claim 10 , wherein the null configuration object comprises a null registry key.

12. The apparatus of claim 10 , wherein the null configuration object comprises a null configuration information.

13. The apparatus of claim 10 , further comprising a security subsystem configured to prevent a deletion or modification of the data object.

14. The apparatus of claim 13 , wherein the security subsystem prevents the deletion or modification of the data object by setting a security permission for the data object.

15. The apparatus of claim 13 , wherein the security subsystem prevents the deletion or modification of the data object by modifying the data object to an object type that differs from the undesired program.

16. The apparatus of claim 15 , wherein the security subsystem prevents the deletion or modification of the data object by placing a second data object in the data object type.

17. The apparatus of claim 11 , further comprising: a security subsystem configured to generate a security event in response to an access of the data object.

18. The apparatus of claim 10 , further comprising:

a security subsystem configured to generate a security event in response to an access of the null configuration object.

19. An apparatus comprising:

one or more processors that are operatively coupled to a memory, wherein the one or more processors are configured to:

determine, in a computer, a location where an undesired computer program is configured to reside upon installation on the computer;

cause the apparatus to provide, to the computer, a data object to occupy the determined installation location of the undesired computer program in the computer to prevent the undesired computer program from being installed in the determined installation location on the computer; and

provide a null configuration object in a second location in the computer, wherein the null configuration object is associated with the data object.

20. An article of manufacture, comprising:

a non-transitory computer-readable medium having stored thereon instructions to:

determine, in a computer, a location where an undesired computer program is configured to reside upon installation on the computer;

provide, to the computer, a data object to occupy the determined installation location of the undesired computer program in the computer to prevent the undesired computer program from being installed in the determined installation location on the computer; and

provide a null configuration object in a second location in the computer, wherein the null configuration object is associated with the data object.

21. The method of claim 1 , wherein the location comprises a memory space.

22. The method of claim 1 , wherein the location comprises a file system location.

23. The method of claim 1 , wherein the data object has the same name as the undesired computer program.

24. The apparatus of claim 10 , wherein the location comprises a memory space.

25. The apparatus of claim 10 , wherein the location comprises a file system location.

26. The apparatus of claim 10 , wherein the data object has the same name as the undesired computer program.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS DATA PREVIOUSLY RECORDED AT REEL: 70134 FRAME: 0413. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY TEREST . Recorded Feb 14, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070235/0936 →
SECURITY INTEREST Recorded Feb 6, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070134/0413 →
CHANGE OF NAME Recorded Sep 28, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 065082/0434 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2018
From: PACIFIC WESTERN BANK
To: COUNTERTACK INC.
Reel/Frame 045923/0804 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2018
From: HBGARY, INC.
To: COUNTERTACK, IINC.
Reel/Frame 044562/0511 →
SECURITY INTEREST Recorded Nov 21, 2016
From: COUNTERTACK INC.
To: PACIFIC WESTERN BANK
Reel/Frame 040384/0329 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2015
From: HBGARY, INC.
To: COUNTERTACK, INC.
Reel/Frame 036451/0634 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2012
From: HOGLUND, MICHAEL GREGORY; BRACKEN, SHAWN MICHAEL
To: HBGARY, INC.
Reel/Frame 029287/0538 →
Continuity (2)
Provisional Application 61456192 · Nov 1, 2010
Related Publication 20120110673A1 · May 3, 2012