IP Library Granted Patent US 8,856,505
Granted Patent B2
US 8,856,505 · App. 13/460,655 · Granted Oct 7, 2014

Malware management through kernel detection during a boot sequence

Inventor: Jerome L. Schneider (Boulder, CO)
Assignee: Webroot Inc.
G06F21/566G06F21/56G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,856,505
App. No.
13/460,655
Granted
Oct 7, 2014
Kind
B2
Abstract

A system and method for managing pestware on a protected computer is described. The method in one variation includes monitoring events during a boot sequence of the computer; managing pestware-related events before native applications can run and after a kernel is loaded; managing pestware-related events when native applications can run; and scanning a registry of the computer for pestware when native applications can run. In variations, a pestware management engine is initialized after an operating system of the protected computer is initialized and the pestware management system both receives an event log of the monitored events and compiles the set of behavior rules utilized by kernel-level monitor.

Claims (48)

1. A method for managing pestware on a computer comprising:

monitoring events during a boot sequence of the computer;

managing pestware-related events during a first period in a boot sequence of the computer, the first period in the boot sequence occurring before the computer becomes configured to run native applications, before a subsystem of an operating system is loaded, and after a kernel is loaded;

managing pestware-related events in accordance with a set of behavior rules during a second period in the boot sequence occurring when the computer is configured to run native applications;

generating, in response to the monitoring, a record of events, the record of events including the pestware-related events;

analyzing the record of events so as to identify the pestware-related events

modifying the set of behavior rules so as to prevent the pestware related events; and

scanning data in a registry of the computer for pestware during the second period in the boot sequence.

2. The method of claim 1 , further comprising launching, after an operating system is initiated, a pestware management engine; and

wherein the set of behavior rules includes behavior rules compiled by the pestware management engine.

3. The method of claim 1 , wherein the record of events includes information selected from a group consisting of: process identification information, file identification information, and hook generation information.

4. The method of claim 1 , further comprising:

managing pestware-related events after the computer becomes configured to run native applications.

5. The method of claim 1 , wherein the monitoring includes monitoring the boot sequence while boot drivers are initiated.

6. A system for managing pestware on a computer comprising:

a processor;

a memory comprising:

a first instruction set configured to monitor events during a boot sequence of the computer;

a second instruction set configured to manage pestware-related events during first period in a boot sequence of the computer, the first period in the boot sequence occurring before the computer becomes configured to run native applications, before a WIN32 subsystem is loaded, and after a kernel is loaded;

a third instruction set configured to manage pestware-related events in accordance with a set of behavior rules during a second period in the boot sequence occurring when the computer is configured to run native applications;

a fourth instruction set configured to generate, in response to the monitoring, a record of events, the record of events including the pestware-related events;

a fifth instruction set configured to analyze the record of events so as to identify the pestware-related events; and

a sixth instruction set configured to modify the set of behavior rules so as to prevent the pestware related events; and

a seventh instruction set configured to scan data in a registry of the computer for pestware during the second period in the boot sequence.

7. The system of claim 6 , wherein the memory further comprises an eighth instruction set configured to launch, after an operating system is initiated, a pestware management engine; and wherein the set of behavior rules includes behavior rules compiled by the pestware management engine.

8. The system of claim 1 , wherein the record of events includes information selected from a group consisting of: process identification information, file identification information, and hook generation information.

9. The system of claim 6 , wherein the memory further comprises:

a ninth instruction set configured to manage pestware-related events after the computer becomes configured to run native applications.

10. The system of claim 6 , wherein the first instruction set is further configured to monitor the boot sequence while boot drivers are initiated.

11. A non-transitory tangible computer-readable storage medium comprising program instructions for:

monitoring events during a boot sequence of a computer;

managing pestware-related events during a first period in a boot sequence of the computer, the first period in the boot sequence occurring before the computer becomes configured to run native applications, before a WIN32 subsystem is loaded, and after a kernel is loaded;

managing pestware-related events in accordance with a set of behavior rules during a second period in the boot sequence occurring when the computer is configured to run native applications;

generating, in response to the monitoring, a record of events, the record of events including the pestware-related events;

analyzing the record of events so as to identify the pestware-related events;

modifying the set of behavior rules so as to prevent the pestware related events; and

scanning data in a registry of the computer for pestware during the second period in the boot sequence.

12. The non-transitory tangible computer-readable storage medium of claim 11 further comprising program instructions for launching, after an operating system is initiated, a pestware management engine; and

wherein the set of behavior rules includes behavior rules compiled by the pestware management engine.

13. The non-transitory tangible computer-readable storage medium of claim 11 , wherein the record of events includes information selected from a group consisting of: process identification information, file identification information, and hook generation information.

14. The non-transitory tangible computer-readable storage medium of claim 11 further comprising program instructions for:

managing pestware-related events after the computer becomes configured to run native applications.

15. The non-transitory tangible computer-readable storage medium of claim 11 , wherein the monitoring includes monitoring the boot sequence while boot drivers are initiated.

16. The method of claim 2 , further comprising modifying, by the pestware management engine, the behavior rules utilized by a kernel-level monitor, wherein the kernel-level monitor manages pestware-related events in the first and second periods in the boot sequence.

17. The method of claim 1 , further comprising modifying the set of behavior rules based on the scanned registry so as to prevent the pestware-related events.

18. The method of claim 1 , wherein the pestware-related invents include events associated with at least one of loading pestware, executing pestware, and one or more behaviors of pestware.

19. The system of claim 6 , wherein the pestware-related invents include events associated with at least one of loading pestware, executing pestware, and one or more behaviors of pestware.

20. The non-transitory tangible computer-readable storage medium of claim 11 , wherein the pestware-related invents include events associated with at least one of loading pestware, executing pestware, and one or more behaviors of pestware.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Oct 2, 2012
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 029066/0457 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2012
From: SCHNEIDER, JEROME L.
To: WEBROOT SOFTWARE, INC.
Reel/Frame 028201/0093 →
Continuity (2)
Continuation 11462827 · Aug 7, 2006
Related Publication 20120216027A1 · Aug 23, 2012