IP Library Granted Patent US 8,667,586
Granted Patent B2
US 8,667,586 · App. 13/460,648 · Granted Mar 4, 2014

Backward researching time stamped events to find an origin of pestware

Inventor: Matthew L. Boney (Longmont, CO)
Assignee: Webroot Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,667,586
App. No.
13/460,648
Granted
Mar 4, 2014
Kind
B2
Abstract

A system and method for identifying an origin of suspected pestware activity on a computer is described. One embodiment includes establishing a time of interest relating to a suspicion of pestware on the computer; issuing a timestamp in response to the establishing the time of interest; identifying, in response to the issuing the timestamp, indicia of pestware; and accessing at least a portion of a recorded history of sources that the computer received files from so as to identify, based at least in part upon the identified indicia of pestware, a reference to an identity of a source that is suspected of originating pestware.

Claims (34)

1. A method for identifying an origin of suspected pestware activity on a computer comprising:

receiving, from a user via an interface of the computer, a time of interest relating to a suspicion of pestware on the computer;

issuing a timestamp in response to the receiving the time of interest;

identifying, in response to the issuing the timestamp, indicia of pestware, wherein the identifying includes:

accessing at least one log of historical events on the computer;

locating an indication of at least one event in at least one log that corresponds to the time of interest; and

determining that the at least one event is associated with the indicia of pestware, wherein the determining that the at least one event is associated with the indicia of pestware includes following references in the at least one log to a suspected pestware object; and

accessing at least a portion of a recorded history of sources that the computer received files from so as to identify, based at least in part upon the identified indicia of pestware, a reference to an identity of a source that is suspected of originating pestware.

2. The method of claim 1 , wherein following the references includes following at least one reference in an activity log from the event to a suspected pestware process.

3. The method of claim 2 , wherein the activity log is generated from a kernel-mode driver.

4. The method of claim 1 , wherein the at least one log includes at least one log selected from a group consisting of an activity log, a browser history, browser cache, browser settings, operating system settings, an event log, a debugging log, a firewall log, file information and monitoring software logs.

5. The method of claim 1 , wherein the time of interest is established from a user input.

6. The method of claim 3 , wherein a user input is in response to an alert provided to the user.

7. The method of claim 1 , wherein the time of interest is established from a time stamp of an instant moment in time.

8. The method of claim 1 , including:

reporting the identity of the source to a pestware research entity so as to enable the pestware research entity to research whether the source is a source of pestware.

9. The method of claim 1 , wherein the source is identified by an identifier selected from a group consisting of an I.P. address, a URL, an email client and a program name.

10. A non-transitory tangible computer-readable storage system comprising program instructions for:

receiving, from a user via an interface of a computer, a time of interest relating to a suspicion of pestware on the computer;

issuing a timestamp in response to the receiving the time of interest;

identifying, in response to the issuing the timestamp, indicia of pestware;

accessing at least a portion of a recorded history of sources that the computer received files from so as to identify, based at least in part upon the identified indicia of pestware, a reference to an identity of a source that is suspected of originating pestware;

accessing at least one log of historical events on the computer;

locating an indication of at least one event in at least one log that corresponds to the time of interest; and

determining that the at least one event is associated with the indicia of pestware, wherein the program instructions for the determining that the at least one event is associated with the indicia of pestware include program instructions for following references in the at least one log to a suspected pestware object.

11. The non-transitory tangible computer-readable storage system of claim 10 , wherein the program instructions for following the references includes program instructions for following at least one reference in an activity log from the event to a suspected pestware process.

12. The non-transitory tangible computer-readable storage system of claim 11 , wherein the activity log is generated from a kernel-mode driver.

13. The non-transitory tangible computer-readable storage system of claim 10 , wherein the at least one log includes at least one log selected from a group consisting of an activity log, a browser history, browser cache, browser settings, operating system settings, an event log, a debugging log, a firewall log, file information and monitoring software logs.

14. The non-transitory tangible computer-readable storage system of claim 10 , wherein the time of interest is established from a user input.

15. The non-transitory tangible computer-readable storage system of claim 12 , wherein a user input is in response to an alert provided to the user.

16. The non-transitory tangible computer-readable storage system of claim 10 , wherein the time of interest is established from a time stamp of an instant moment in time.

17. The non-transitory tangible computer-readable storage system of claim 10 , further comprising program instructions for:

reporting the identity of the source to a pestware research entity so as to enable the pestware research entity to research whether the source is a source of pestware.

18. The non-transitory tangible computer-readable storage system of claim 10 , wherein the source is identified by an identifier selected from a group consisting of an I.P. address, a URL, an email client and a program name.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Oct 2, 2012
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 029066/0457 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2012
From: BONEY, MATTHEW L.
To: WEBROOT SOFTWARE, INC.
Reel/Frame 028201/0042 →
Continuity (2)
Continuation 11408145 · Apr 20, 2006
Related Publication 20120216279A1 · Aug 23, 2012