IP Library Granted Patent US 8,763,123
Granted Patent B2
US 8,763,123 · App. 13/543,865 · Granted Jun 24, 2014

Methods and apparatus for dealing with malware

Inventors: Melvyn Morris (Turnditch, GB); Paul Stubbs (Wyboston, GB); Markus Hartwig (Milton Keynes, GB); Darren Harter (Hucclecote, GB)
Assignee: Prevx Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,763,123
App. No.
13/543,865
Granted
Jun 24, 2014
Kind
B2
Abstract

In one aspect, a method of determining the protection that a remote computer has from malware includes receiving at a base computer, details of all or selected security products operating on a remote computer, receiving similar information from other remote computers, and identifying malware process that were not identified by the security products installed on the other remote computers and having a same or similar combination of security products installed on the remote computer.

Claims (43)

1. A method comprising:

receiving, at a base computer, details uniquely identifying one or more security products operating at a point in time on a remote computer;

receiving, at the base computer, details uniquely identifying one or more security products operating on other remote computers in communication with the base computer;

receiving, at the base computer, details of a process that has been executed by at least one of the other remote computers;

determining, by the base computer and based on the received details of the process that has been executed by the least one of the other remote computers, that the process is a malware process not identified by the one or more security products operating on the at least one of the other remote computers; and

determining, by the base computer, that the remote computer is vulnerable to the malware process, wherein the determination is based on the at least one of the other remote computers having a same or similar combination of security products as the combination of security products operating on the remote computer.

2. The method according to claim 1 , further comprising:

providing information to the user of the remote computer that the remote computer may be susceptible to attack by the malware processes.

3. The method according to claim 1 , wherein the details of the one or more security products includes the name of the security products, versions, and loaded signature files.

4. An apparatus comprising:

a base computer constructed and arranged to receive details uniquely identifying one or more security products operating at a point in time on a remote computer;

the base computer being constructed and arranged to receive details uniquely identifying one or more security products operating on other remote computers in communication with the base computer;

the base computer being constructed and arranged to receive details of a process that has been executed by at least one of the other remote computers;

the base computer being constructed and arranged to determine, based on the received details of the process that has been executed by the least one of the other remote computers, that the process is a malware process not identified by the one or more security products operating on the at least one of the other remote computers; and

the base computer being constructed and arranged to determine that the remote computer is vulnerable to the malware process, wherein the determination is based on the at least one of the other remote computers having the same or similar combination of security products as the combination of security products operating on the remote computers.

5. The apparatus according to claim 4 , wherein the base computer is constructed and arranged to provide information to the user of the remote computer that the remote computer may be susceptible to attack by the malware process.

6. The apparatus according to claim 4 , wherein the details of the one or more security products includes the name of the security products, versions, and loaded signature files.

7. A computer program recorded on a non-transitory computer readable medium comprising program instructions for causing a computer to perform a method according to claim 1 .

8. A computer program recorded on a non-transitory computer readable medium comprising program instructions for causing a computer to perform a method according to claim 2 .

9. A computer program recorded on a non-transitory computer readable medium comprising program instructions for causing a computer to perform a method according to claim 3 .

10. The method according to claim 3 , wherein the details of all or selected security products further includes settings at a particular point in time.

11. The method according to claim 1 , further comprising:

identifying, by the base computer, one or more of the other remote computers having the same or similar combination of security products as the combination of security products operating on the at least one of the other remote computers; and

determining, by the base computer, that the identified one or more of the other remote computers having the same or similar combination of security products as the combination of security products operating on the at least one of the other remote computers is vulnerable to the malware process.

12. The apparatus according to claim 6 , wherein the details of all or selected security products further includes settings at a point in time.

13. A method comprising:

receiving, at a base computer, details uniquely identifying one or more security products operating at a point in time on a remote computer;

receiving, at the base computer, details uniquely identifying one or more security products operating on other remote computers in communication with the base computer;

receiving, at the base computer, details of a process that has been executed by at least one of the other remote computers;

determining, by the base computer and based on the received details of the process that has been executed by the least one of the other remote computers, that the process is a malware process;

determining, by the base computer, that the remote computer is vulnerable to the malware process, wherein the determination is based on the at least one of the other remote computers having a same or similar combination of security products as the combination of security products operating on the remote computer;

identifying, by the base computer, one or more of the other remote computers having the same or similar combination of security products and settings as the combination of security products operating on the remote computer; and

identifying, by the base computer, one or more malware processes that were not identified by the combination of security products and settings operating on the one or more of the other remote computers having the same or similar combination of security products as the combination of security products operating on the remote computer.

14. The method according to claim 1 , wherein the one or more security products include a firewall product and an antivirus product.

15. The apparatus according to claim 4 , wherein the one or more security products include a firewall product and an antivirus product.

16. A method comprising:

receiving, at a base computer, details of one or more security products operating at a point in time on a remote computer;

receiving, at the base computer, details of one or more security products operating on other remote computers in communication with the base computer;

receiving, at the base computer, details of a process that has been executed by at least one of the other remote computers;

determining, by the base computer and based on the received details of the process that has been executed by the least one of the other remote computers, that the process is a malware process;

determining, by the base computer, that the remote computer is vulnerable to the malware process, wherein the determination is based on the at least one of the other remote computers having a same or similar combination of security products as the combination of security products operating on the remote computer;

identifying, by the base computer, one or more of the other remote computers having the same or similar combination of security products and settings as the combination of security products operating on the remote computer; and

identifying, by the base computer, one or more malware processes that were not identified by the combination of security products and settings operating on the one or more of the other remote computers having the same or similar combination of security products as the combination of security products operating on the remote computer.

Assignments (10)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 048668/0070 →
SECURITY INTEREST Recorded May 17, 2016
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 038617/0467 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2016
From: WEBROOT SOLUTIONS LTD
To: WEBROOT INC.
Reel/Frame 037886/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2015
From: MORRIS, MELVYN; STUBBS, PAUL; HARTWIG, MARKUS; HARTER, DARREN
To: PREVX LIMITED
Reel/Frame 035450/0770 →
CHANGE OF NAME Recorded May 29, 2014
From: PREVX LTD
To: WEBROOT SOLUTIONS LTD
Reel/Frame 032991/0418 →
Priority Claims (1)
GB 0513375.6 · Jun 30, 2005 · national
Continuity (2)
Division 11477807 · Jun 30, 2006
Related Publication 20120278891A1 · Nov 1, 2012