IP Library › Granted Patent US 8,782,793
Granted Patent B2
US 8,782,793 · App. 13/477,283 · Granted Jul 15, 2014

System and method for detection and treatment of malware on data storage devices

Inventor: Oleg V. Zaitsev (Smolensk, RU)
Assignee: Kaspersky Lab ZAO
G06F21/56G06F21/568H04L63/1441H04L63/1416H04L63/14G06F21/564G06F21/561G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,793
App. No.
13/477,283
Granted
Jul 15, 2014
Kind
B2
Abstract

Disclosed are systems and methods for detection and repair of malware on data storage devices. The system includes a controller, a communication interface for connecting an external data storage device, and a memory for storing antivirus software. The antivirus software is configured to scan the data contained in the data storage device, perform repair or removal of malicious files or programs found on the data storage device, identify suspicious files or programs on the data storage device and malicious files or programs that cannot be repaired or removed from the data storage device, send information about these files or programs to the antivirus software provider, receive updates for the antivirus software from the antivirus software provider, and rescan the suspicious files or programs and malicious files or programs that cannot be repaired or removed using updated antivirus software.

Claims (67)

1. A computer-implemented method for detection and repair of malware on data storage devices, the method comprising:

connecting an external data storage device to a processing device;

storing a backup copy of at least a portion of the data contained on the external data storage device to a memory of the processing device;

scanning the data contained in the data storage device using antivirus software deployed on the processing device;

performing by the antivirus software repair or removal of one or more malicious files or programs found on the data storage device;

if one or more files or programs are corrupted during at least one of said scanning, repairing and removing, replacing by the antivirus software at least a portion of corrupted data in the data storage device with the backup copy stored in the memory of the processing device;

identifying one or more suspicious files or programs found on the data storage device and one or more malicious files or programs that cannot be repaired or removed from the data storage device by the antivirus software;

sending information about the suspicious files or programs and malicious files or programs that cannot be repaired or removed to an antivirus software provider;

receiving updates for the antivirus software from the antivirus software provider; and

rescanning at least the suspicious files or programs and malicious files or programs that

cannot be repaired or removed by an updated antivirus software.

2. The method of claim wherein connecting an external data storage device to a processing device further comprises at least:

identifying the connected data storage device, including identifying one or more of the name of the data storage device, the size of the memory of the data storage device, the type of the memory of the data storage device, and the manufacturer of data storage device.

3. The method of claim 1 , wherein storing a backup copy of at least a portion of the data contained on the external data storage device to a memory of the processing device, further comprises at least:

creating a dedicated partition or folder in the memory of the processing device; and

storing a backup copy of at least a portion of the data from the data storage device in the created partition or folder in the memory of the processing device.

4. The method of claim 1 , further comprising reporting the one or more suspicious files or programs and one or more malicious files or programs that cannot be repaired or removed to a user.

5. The method of claim 4 , wherein reporting the one or more suspicious files or programs and one or more malicious files or programs that cannot be repaired or removed to the user further comprises at least:

providing user-recommendations for dealing with the suspicious files or programs and with the malicious files or programs that cannot be repaired or removed.

6. The method of claim of 1 , wherein updating antivirus software further comprises at least:

updating signatures of known clean and malicious programs; and

updating heuristic analysis algorithms.

7. A computer-based system for detection and repair of malware on data storage devices, the system comprising:

a communication interface for connecting an external data storage device;

a memory storing an antivirus software; and

a controller coupled to the communication interface and the memory, the controller being configured to:

store a backup copy of at least a portion of the data contained on the external data storage device to the memory;

scan the data contained in the data storage device using the antivirus software;

perform by the antivirus software repair or removal of one or more malicious files or programs found on the data storage device;

if one or more files or programs are corrupted during at least one of said scanning, repairing and removing, replace by the antivirus software at least a portion of corrupted data in the data storage device with the backup copy stored in the memory of the processing device;

identify one or more suspicious files or programs found on the data storage device and one or more malicious files or programs that cannot be repaired or removed from the data storage device by the antivirus software;

send information about the suspicious files or programs and malicious files or programs that cannot be repaired or removed to an antivirus software provider;

receive updates for the antivirus software from the antivirus software provider; and

rescan at least the suspicious files or programs and malicious files or programs that cannot be repaired or removed by an updated antivirus software.

8. The system of claim 7 , wherein the controller being further configured to at least:

identify the connected data storage device, including identify one or more of the name of the data storage device, the size of the memory of the data storage device, the type of the memory of the data storage device, and the manufacturer of data storage device.

9. The system of claim 7 , wherein to store a backup copy of at least a portion of the data contained on the external data storage device to the memory, the controller further configured to at least:

create a dedicated partition or folder in the memory; and

store a backup copy of the data from the data storage device in the created partition or folder in the memory.

10. The system of claim 7 , wherein the controller further configured to report the one or more suspicious files or programs and one or more malicious files or programs that cannot be repaired or removed to a user.

11. The system of claim 10 , wherein to report the one or more suspicious files or programs and one or more malicious files or programs that cannot be repaired or removed to the user, the controller further configured to at least:

provide user-recommendations for dealing with the suspicious files or programs and with the malicious files or programs that cannot be repaired or removed.

12. The system of claim 7 , wherein to update antivirus software, the controller further configured to at least:

update signatures of known dean and malicious programs; and

update heuristic analysis algorithms.

13. A computer program product embedded in a non-transitory computer-readable storage medium, the computer-readable storage medium comprising computer-executable instructions for detection and repair of malware on data storage devices, the medium comprising instructions for:

connect an external data storage device to a processing device;

store a backup copy of at least a portion of the data contained on the external data storage device to a memory of the processing device;

scan the data contained in the data storage device using antivirus software deployed on the processing device;

perform by the antivirus software repair or removal of one or more malicious files or programs found on the data storage device;

if one or more files or programs are corrupted during at least one of said scanning, repairing and removing, replace by the antivirus software at least a portion of corrupted data in the data storage device with the backup copy stored in the memory of the processing device;

identify one or more suspicious files or programs found on the data storage device and one or more malicious files or programs that cannot be repaired or removed from the data storage device by the antivirus software;

send information about the suspicious files or programs and malicious files or programs that cannot be repaired or removed to an antivirus software provider;

receive updates for the antivirus software from the antivirus software provider; and

rescan at least the suspicious files or programs and malicious files or programs that

cannot be repaired or removed by an updated antivirus software.

14. The product of claim 13 , wherein instruction for connecting the data storage device further comprise instructions for at least:

identifying the connected data storage device, including identifying one or more of the name of the data storage device, the size of the memory of the data storage device, the type of the memory of the data storage device, and the manufacturer of data storage device.

15. The product of claim 13 , wherein instructions for storing a backup copy of at least a portion of the data contained on the external data storage device to a memory of the processing device, further comprise instructions for at least:

creating a dedicated partition or folder in the memory of the processing device; and

storing a backup copy of the data from the data storage device in the created partition or folder in the memory of the processing device.

16. The product of claim 13 , further comprising instructions for reporting the one or more suspicious files or programs and one or more malicious files or programs that cannot be repaired or removed to a user.

17. The product of claim 16 , wherein instructions for reporting the one or more suspicious files or programs and one or more malicious files or programs that cannot be repaired or removed to the user further comprise instructions for at least:

providing user-recommendations for dealing with the suspicious files or programs and with the malicious files or programs that cannot be repaired or removed.

18. The product of claim 13 , wherein instructions for updating antivirus software further comprise instructions for at least:

updating signatures of known clean and malicious programs; and

updating heuristic analysis algorithms.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2012
From: ZAITSEV, OLEG V.
To: KASPERSKY LAB ZAO
Reel/Frame 028247/0236 →
Continuity (1)
Related Publication 20130318610A1 · Nov 28, 2013