IP Library Granted Patent US 8,719,932
Granted Patent B2
US 8,719,932 · App. 13/490,294 · Granted May 6, 2014

Backwards researching activity indicative of pestware

Inventor: Matthew L. Boney (Longmont, CO)
Assignee: Webroot Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,719,932
App. No.
13/490,294
Granted
May 6, 2014
Kind
B2
Abstract

A system and method for researching an identity of a source of activity that is indicative of pestware is described. In one embodiment the method comprises monitoring, using a kernel-mode driver, API call activity on the computer; storing information related to the API call activity in a log; analyzing, heuristically, the API call activity to determine whether one or more weighted factors associated with the API call activity exceeds a threshold; identifying, based upon the API call activity, a suspected pestware object on the computer; identifying, in response to the identifying the suspected pestware object, a reference to an identity of an externally networked source of the suspected pestware object; and reporting the identity of the externally networked source to an externally networked pestware research entity.

Claims (34)

1. A method for identifying an origin of activity on a computer that is indicative of pestware comprising:

monitoring, using a kernel-mode driver, API call activity on the computer;

storing information related to the API call activity in a log;

analyzing, heuristically, the API call activity to determine whether one or more weighted factors associated with the API call activity exceeds a threshold;

identifying, based upon the API call activity, a suspected pestware object on the computer;

identifying, in response to the identifying the suspected pestware object, a reference to an identity of an externally networked source of the suspected pestware object; and

reporting the identity of the externally networked source to an externally networked pestware research entity, wherein

the identity of the externally networked source is selected from a group consisting of an I.P. address, a URL, an email client and a program.

2. The method of claim 1 , wherein the identifying the suspected pestware object includes accessing an activity log that includes information that relates the activity to the suspected pestware object.

3. The method of claim 1 , wherein the identifying a reference includes accessing at least a portion of a recorded history of externally networked sources.

4. The method of claim 3 , wherein the recorded history resides in at least one log selected from the group consisting of an activity log, a browser history, browser cache, browser settings, operating system settings, an event log, a debugging log, a firewall log, file information and monitoring software logs.

5. A system for identifying a source of activity on a computer that is indicative of pestware including:

a kernel-level monitor configured to monitor API call activity on the computer and to store information related to the API call activity in a log;

a heuristics module configured to analyze the API call activity to determine whether one or more weighted factors associated with the API call activity exceeds a threshold;

a research portion configured to identify, in response to a prompt from the heuristics module, a suspected pestware object on the computer; and

a reporting portion configured to generate a report including a reference to an identity of an externally networked source of the suspected pestware object and to report the identity of the externally networked source to an externally networked pestware research entity, wherein

the kernel-level monitor is configured to store information about a relationship between at least one API call of the API call activity and a file.

6. The system of claim 5 , wherein the information comprises an identity of at least one process that made at least one API call in the log.

7. The system of claim 5 , wherein the heuristics module is configured to receive information about the API call activity from the kernel-level monitor and to determine whether the API call activity is indicative of pestware.

8. The system of claim 5 , wherein the kernel-level monitor is configured to intercept at least one API call.

9. The system of claim 5 , wherein the identity of the externally networked source is selected from the group consisting of an I.P. address, a URL, an email client and a program name.

10. The system of claim 5 , wherein the research portion is configured to access at least a portion of a recorded history of externally networked sources.

11. The system of claim 10 , wherein the recorded history resides in at least one log selected from the group consisting of an activity log, a browser history, browser cache, browser settings, operating system settings, an event log, a debugging log, a firewall log, file information and monitoring software logs.

12. A non-transitory computer-readable medium including processor-executable instructions for identifying an origin of activity on a computer that is indicative of pestware, the instructions including instructions for:

monitoring, using a kernel-mode driver, API call activity on the computer;

storing information related to the API call activity in a log;

analyzing, heuristically, the API call activity to determine whether one or more weighted factors associated with the API call activity exceeds a threshold;

identifying, based upon the API call activity, a suspected pestware object on the computer;

identifying, in response to the identifying the suspected pestware object, a reference to an identity of an externally networked source of the suspected pestware object; and

reporting the identity of the externally networked source to an externally networked pestware research entity, wherein

the identity of the externally networked source is selected by an identifier selected from a group consisting of an I.P. address, a URL, an email client and a program.

13. The non-transitory computer-readable medium of claim 12 , wherein the instructions for identifying the suspected pestware object include instructions for accessing an activity log that includes information that relates the activity to the suspected pestware object.

14. The non-transitory computer-readable medium of claim 12 , wherein the instructions for identifying a reference include instructions for accessing at least a portion of a recorded history of externally networked sources.

15. The non-transitory computer-readable medium of claim 14 , wherein the recorded history resides in at least one log selected from the group consisting of an activity log, a browser history, browser cache, browser settings, operating system settings, an event log, a debugging log, a firewall log, file information and monitoring software logs.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Oct 2, 2012
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 029066/0457 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2012
From: BONEY, MATTHEW L.
To: WEBROOT SOFTWARE, INC.
Reel/Frame 028385/0242 →
Continuity (2)
Continuation 11408146 · Apr 20, 2006
Related Publication 20120246722A1 · Sep 27, 2012