IP Library Granted Patent US 8,726,389
Granted Patent B2
US 8,726,389 · App. 13/543,866 · Granted May 13, 2014

Methods and apparatus for dealing with malware

Inventors: Melvyn Morris (Turnditch, GB); Paul Stubbs (Wyboston, GB); Markus Hartwig (Milton Keynes, GB); Darren Harter (Hucclecote, GB)
Assignee: Prevx Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,726,389
App. No.
13/543,866
Granted
May 13, 2014
Kind
B2
Abstract

In one aspect, a method of classifying a computer object as malware includes receiving at a base computer data about a computer object from each of plural remote computers on which the object or similar objects are stored. The data about the computer object received from the plural computers is compared in the base computer. The computer object is classified as malware on the basis of said comparison. In one embodiment, the data about the computer object includes one or more of: executable instructions contained within or constituted by the object; the size of the object; the name of the object; the logical storage location or path of the object on the respective remote computers; the vendor of the object; the software product and version associated with the object; and, events initiated by or involving the object when the object is created, configured or runs on the respective remote computers.

Claims (71)

1. A method of classifying a computer object as malware, the method comprising:

at a base computer, receiving data about a computer object from a first remote computer on which the computer object or similar computer objects are stored, wherein said data includes information about events initiated or involving the computer object when the computer object is created, configured or runs on the first remote computer, said information including at least an identity of an object initiating the event, the event type, and an identity of an object or other entity on which the event is being performed;

at the base computer, receiving data about the computer object from a second remote computer on which the computer object or similar computer objects are stored, wherein said data includes information about events initiated or involving the computer object when the computer object is created, configured, or runs on the second remote computer, said information including at least an identity of an object initiating the event, the event type, and an identity of an object or other entity on which the event is being performed;

storing, at the base computer, said data received from the first and second remote computers;

correlating, by the base computer, at least a portion of the data about the computer object received from the first remote computer to at least a portion of the data about the computer object received from the second remote computer;

comparing, by the base computer, the correlated data about the computer object received from the first and second remote computers to other objects or entities to identify relationships between the correlated data and the other objects or entities; and

classifying, by the base computer, the computer object as malware on the basis of said comparison.

2. A method according to claim 1 , wherein the relationship is between objects related directly, or between objects related via other objects.

3. A method according to claim 1 , wherein where an object and other objects are found to have a relationship, monitoring those related objects as a homogenous entity and identifying a common object of the homogenous entity as a malware object.

4. A method according to claim 1 , comprising deducing an object to be malware based on the behaviour of a related object.

5. A method according to claim 1 , wherein if at least one other object to which said computer object is related is classed as malware, then classifying said computer object as malware.

6. A method according to claim 1 , wherein said other objects include the object or similar objects stored on at least one of the first and second remote computers.

7. A method according to claim 1 , wherein said other objects include other objects that are parent objects or child objects or otherwise process-related objects to said computer object.

8. A method according to claim 1 , wherein the data about the computer object that is sent from the respective remote computer to the base computer and that is used in the comparison includes one or more of:

executable instructions contained within or constituted by the computer object;

the size of the computer object;

the current name of the computer object;

the physical and folder location of the computer object on disk;

the original name of the computer object;

the creation and modification dates of the computer object;

vendor, product and version and any other information stored within the computer object; and

the computer object header or header held by the respective remote computer.

9. A method according to claim 1 , wherein the data is sent in the form of a key that is obtained by a hashing process carried out in respect of the objects on the respective remote computer.

10. A method according to claim 9 , wherein the key has at least one component that represents executable instructions contained within or constituted by the computer object.

11. A method according to claim 9 , wherein the key has at least one component that represents data about said computer object.

12. A method according to claim 11 , wherein said data about said computer object includes at least one of:

the current name of the computer object;

the physical and folder location of the computer object on disk;

the original name of the computer object;

the creation and modification dates of the computer object;

vendor, product and version and any other information stored within the computer object;

the computer object header or header held by the respective remote computer; and,

events initiated by or involving the computer object when the computer object is created, configured or runs on the respective remote computers.

13. A method according to claim 9 , wherein the key has at least one component that represents the physical size of the computer object.

14. A method according to claim 1 , comprising initially classifying a computer object as not malware, generating a mask for said computer object that defines acceptable behaviour for the computer object, monitoring an operation of the computer object on at least one of the first and second remote computers and reclassifying the computer object as malware if the actual monitored behaviour extends beyond that permitted by the mask.

15. An apparatus for classifying a computer object as malware, the apparatus comprising:

a base computer constructed and arranged to receive data about a computer object from a first remote computer on which the computer object or similar computer objects are stored, wherein said data includes information about events initiated or involving the computer object when the computer object is created, configured, or runs on the first remote computer, said information including at least an identity of an object initiating the event, the event type, and an identity of an object or other entity on which the event is being performed;

the base computer being constructed and arranged to receive data about the computer object from a second remote computer on which the computer object or similar computer objects re stored, wherein said data includes information about events initiated or involving the computer object when the computer object is created, configured, or runs on the second remote computer, said information including at least an identity of an object initiating the event, the event type, and an identity of an object or other entity on which the event is being performed;

the base computer being constructed and arranged to correlate at least a portion of the data about the computer object received from the first remote computer to at least a portion of the data about the computer object received from the second remote computer;

the base computer being constructed and arranged to compare the data about the computer object received from the first and second remote computers to other objects or entities to identify relationships between the correlated data and the other objects or entities; and

the base computer being constructed and arranged to classify the computer object as malware on the basis of said comparison.

16. Tha apparatus according to claim 15 , wherein the base computer is constructed and arranged so as to identify the relationship between objects related directly, or between objects related via other objects.

17. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so as, where an object and other objects are found to have a relationship, to monitor those related objects as a homogenous entity and identify a common object of the homogenous entity as a malware object.

18. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so as to deduce an object to be malware based on the behaviour of a related object.

19. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so that if at least one other object to which said object is related is classed as malware, then said object is classified as malware.

20. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so that said other objects include the object or similar objects stored on at least one of the first and second remote computers.

21. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so that said other objects include other objects that are parent objects or child objects or otherwise process-related objects to said object.

22. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so as to compare the data where the data includes one or more of:

executable instructions contained within or constituted by the computer object;

the size of the computer object;

the current name of the computer object;

the physical and folder location of the computer object on disk;

the original name of the computer object;

the creation and modification dates of the computer object;

vendor, product, and version and any other information stored within the computer object; and

the computer object header or header held by the respective remote computer.

23. The apparatus according to claim 15 , wherein the base computer is constructed and arranged so as to be able to process data that is sent in the form of a key that is obtained by a hashing process carried out in respect of the objects on said respective remote computer.

24. The apparatus according to claim 23 , wherein the key has at least one component that represents executable instructions contained within or constituted by the computer object.

25. The apparatus according to claim 23 , wherein the key has at least one component that represents data about said computer object.

26. Apparatus according to claim 25 , wherein said data about said object includes at least one of:

the current name of the computer object;

the physical and folder location of the computer object on disk;

the original name of the comptuer object;

the creation and modification dates of the computer object;

vendor, product, and version and any other information stored within the computer object;

the computer object header or header held by the respective remote computer; and

events initiated by or involving the computer object when the computer object is created, configured, or runs on the respective remote computers.

27. The apparatus according to claim 23 , wherein the key has at least one component that represents the physical size of the computer object.

28. The apparatus according to claim 15 , wherein the base computer is constructed and arranged to generate a mask for a computer object that is initially classed not as malware, said mask defining acceptable behaviour for the computer object, and the base computer is constructed and arranged to monitor an operation of the computer object on at least one of the first and second remote computers and to reclassify the computer object as malware if the actual monitored behaviour extends beyond that permitted by the mask.

29. A computer program recorded on non-transitory computer readable medium comprising program instructions for causing a computer to perform the method of claim 1 .

30. A method according to claim 1 , wherein the data received about the computer object from the first remote computer is different than the data received about the computer object from the second remote computer.

Assignments (11)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 048668/0070 →
SECURITY INTEREST Recorded May 17, 2016
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 038617/0467 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2016
From: WEBROOT SOLUTIONS LTD
To: WEBROOT INC.
Reel/Frame 037886/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2015
From: MORRIS, MELVYN; STUBBS, PAUL; HARTWIG, MARKUS; HARTER, DARREN
To: PREVX LIMITED
Reel/Frame 035450/0609 →
CHANGE OF NAME Recorded Oct 21, 2014
From: PREVX LTD
To: WEBROOT SOLUTIONS LTD
Reel/Frame 033995/0364 →
CHANGE OF NAME Recorded May 29, 2014
From: PREVX LTD
To: WEBROOT SOLUTIONS LTD
Reel/Frame 032991/0418 →
Priority Claims (1)
GB 0513375.6 · Jun 30, 2005 · national
Continuity (2)
Continuation 11477807 · Jun 30, 2006
Related Publication 20120278895A1 · Nov 1, 2012