IP Library Granted Patent US 8,646,089
Granted Patent B2
US 8,646,089 · App. 13/276,086 · Granted Feb 4, 2014

System and method for transitioning to a whitelist mode during a malware attack in a network environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,646,089
App. No.
13/276,086
Granted
Feb 4, 2014
Kind
B2
Abstract

A method is provided in one example embodiment that includes receiving a signal to enable a whitelist mode on a host in a network, terminating a process executing on the host if the process is not verified, and blocking execution of software objects on the host if the software objects are not represented on the whitelist. In more particular embodiments, the method also includes identifying the process on a process list that enumerates one or more processes executing on the host. Yet further embodiments include quarantining the host if a second process on the process list is a critical process and if the second process is not verified. More specific embodiments include identifying and restarting another process on the process list if process memory was modified.

Claims (60)

1. A method, comprising:

receiving at least one signal to enable a whitelist mode and disable an antivirus mode on a host in a network;

enabling the whitelist mode on the host and disabling the antivirus mode on the host, wherein the whitelist mode includes:

preventing execution of a software object on the host responsive to determining the software object is not represented on a whitelist; and

allowing another software object to be executed responsive to determining the other software object is represented on the whitelist;

identifying a first process of a plurality of processes on a process list of the host, the first process associated with one or more first software objects, wherein each one of the plurality of processes was invoked prior to the whitelist mode being enabled and the antivirus mode being disabled;

allowing the first process to continue running unimpeded on the host after the whitelist mode is enabled on the host, wherein the first process is allowed to continue running responsive to determining each of the one or more first software objects is represented on the whitelist and process memory associated with the first process has not been modified;

identifying a second process on the process list of the host, the second process associated with one or more second software objects;

terminating the second process on the host after the whitelist mode is enabled on the host, wherein the second process is terminated responsive to determining any of the one or more second software objects is not represented on the whitelist and the one or more second software objects are not part of a critical process;

identifying a third process on the process list of the host, the third process associated with one or more third software objects;

restarting the third process on the host after the whitelist mode is enabled on the host, wherein the third process is restarted responsive to determining each of the one or more third software objects is represented on the whitelist and process memory associated with the third process was modified before the whitelist mode was enabled,

identifying a fourth process on the process list of the host, the fourth process associated with one or more fourth software objects;

wherein the host is quarantined if any of the one or more fourth software objects is not represented on the whitelist and any of the one or more fourth software objects is part of a critical process.

2. The method of claim 1 , wherein the antivirus mode is disabled on the host after the whitelist mode is enabled on the host.

3. The method of claim 1 , further comprising:

receiving a second signal to enable the antivirus mode after enabling the whitelist mode; and

disabling the whitelist mode.

4. The method of claim 1 , wherein the whitelist is dynamically updated.

5. The method of claim 1 , wherein at least one of the one or more first software objects corresponds to a sub-process of the first process.

6. An apparatus, comprising:

a protection module;

a memory element configured to store software objects;

one or more processors operable to execute instructions, associated with the software objects and the protection module, comprising:

receiving at least one signal to enable a whitelist mode and disable an antivirus mode on a host in a network;

enabling the whitelist mode on the host and disabling the antivirus mode on the host, wherein the whitelist mode includes:

preventing execution of a software object on the host responsive to determining the software object is not represented on a whitelist; and

allowing another software object to be executed responsive to determining the other software object is represented on the whitelist;

identifying a first process of a plurality of processes on a process list of the host, the first process associated with one or more first software objects, wherein each one of the plurality of processes was invoked prior to the whitelist mode being enabled and the antivirus mode being disabled;

allowing the first process to continue running unimpeded on the host after the whitelist mode is enabled on the host, wherein the first process is allowed to continue running responsive to determining each of the one or more first software objects is represented on the whitelist and process memory associated with the first process has not been modified;

identifying a second process on the process list of the host, the second process associated with one or more second software objects;

terminating the second process on the host after the whitelist mode is enabled on the host, wherein the second process is terminated responsive to determining any of the one or more second software objects is not represented on the whitelist and the one or more second software objects are not part of a critical process;

identifying a third process on the process list of the host, the third process associated with one or more third software objects;

restarting the third process on the host after the whitelist mode is enabled on the host, wherein the third process is restarted responsive to determining each of the one or more third software objects is represented on the whitelist and process memory associated with the third process was modified before the whitelist mode was enabled,

identifying a fourth process on the process list of the host, the fourth process associated with one or more fourth software objects;

wherein the host is quarantined if any of the one or more fourth software objects is not represented on the whitelist and any of the one or more fourth software objects is part of a critical process.

7. The apparatus of claim 6 , wherein the antivirus mode is disabled on the host after the whitelist mode is enabled on the host.

8. The apparatus of claim 6 , wherein the one or more processors are operable to perform further operations comprising:

receiving a second signal to enable the antivirus mode after enabling the whitelist mode; and

disabling the whitelist mode.

9. The apparatus of claim 6 , wherein the whitelist is dynamically updated.

10. The apparatus of claim 6 , wherein at least one of the one or more second software objects corresponds to a sub-process of the second process.

11. Logic encoded in non-transitory media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:

receiving at least one signal to enable a whitelist mode and disable an antivirus mode on a host in a network;

enabling the whitelist mode on the host and disabling the antivirus mode on the host, wherein the whitelist mode includes:

preventing execution of a software object on the host responsive to determining the software object is not represented on a whitelist; and

allowing another software object to be executed responsive to determining the other software object is represented on the whitelist;

identifying a first process of a plurality of processes on a process list of the host, the first process associated with one or more first software objects, wherein each one of the plurality of processes was invoked prior to the whitelist mode being enabled and the antivirus mode being disabled;

allowing the first process to continue running unimpeded on the host after the whitelist mode is enabled on the host, wherein the first process is allowed to continue running responsive to determining each of the one or more first software objects is represented on the whitelist and process memory associated with the first process has not been modified;

identifying a second process on the process list of the host, the second process associated with one or more second software objects;

terminating the second process on the host after the whitelist mode is enabled on the host, wherein the second process is terminated responsive to determining any of the one or more second software objects is not represented on the whitelist and the one or more second software objects are not part of a critical process;

identifying a third process on the process list of the host, the third process associated with one or more third software objects;

restarting the third process on the host after the whitelist mode is enabled on the host, wherein the third process is restarted responsive to determining each of the one or more third software objects is represented on the whitelist and process memory associated with the third process was modified before the whitelist mode was enabled,

identifying a fourth process on the process list of the host, the fourth process associated with one or more fourth software objects;

wherein the host is quarantined if any of the one or more fourth software objects is not represented on the whitelist and any of the one or more fourth software objects is part of a critical process.

12. The logic of claim 11 , wherein the antivirus mode is disabled on the host after the whitelist mode is enabled on the host.

13. The logic of claim 11 , wherein the one or more processors are operable to perform further operations comprising:

receiving a second signal to enable the antivirus mode after enabling the whitelist mode; and

disabling the whitelist mode.

14. The logic of claim 11 , wherein the whitelist is dynamically updated.

15. The logic of claim 11 , wherein at least one of the one or more third software objects corresponds to a sub-process of the third process.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2011
From: JAYANTHI, SRIDHAR; KHARE, PRANEET; SRINIVASA, GANGADHARASA
To: MCAFEE, INC.
Reel/Frame 027220/0405 →