IP Library Granted Patent US 8,914,886
Granted Patent B2
US 8,914,886 · App. 13/663,277 · Granted Dec 16, 2014

Dynamic quarantining for malware detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,914,886
App. No.
13/663,277
Granted
Dec 16, 2014
Kind
B2
Abstract

A method includes detecting a portion of data on an electronic device, determining a first representation of the malware status of the data, quarantining the data for a period of time, estimating whether the data is associated with malware by comparing the first and second representation, and, based on the estimation, releasing the data from quarantine. The first representation indicates that the malware status of the data is not certain to be safe and the malware status of the data is not certain to be malicious.

Claims (78)

1. A method for preventing malware attacks, comprising:

on an electronic device, analyzing a portion of data;

determining a first representation of the malware status of the data, including:

determining that the malware status of the data is not certain to be safe; and

determining that the malware status of the data is not certain to be malicious;

quarantining the data for a period of time based on the determination of the first representation of the malware status of the data;

determining a second representation of the malware status of the same data after the period of time;

estimating whether the data is associated with malware by comparing the first and second representation; and

based on the estimation of whether the data is associated with malware, releasing the data from quarantine.

2. The method of claim 1 , wherein:

comparing the first and second representation includes determining whether representation has changed, indicating an increased likelihood that the data is safe; and

determining whether the data is associated with malware includes estimating that the data is safe based upon the increased likelihood that the data is safe.

3. The method of claim 1 , wherein:

comparing the first and second representation includes determining whether representation has changed, indicating an decreased likelihood that the data is safe; and

determining whether the data is associated with malware includes estimating that the data is malicious based upon the decreased likelihood that the data is safe.

4. The method of claim 3 , wherein the data is blocked from arriving at an intended recipient if the data is associated with malware.

5. The method of claim 3 , wherein comparing the first and second representation includes determining whether the second representation has crossed a threshold value.

6. The method of claim 1 , wherein comparing the first and second representation yields a determination that:

the malware status of the data is not certain to be safe; and

the malware status of the data is not certain to be malicious; and further comprising:

based on the determination, repeating the quarantining and determining a third representation of the malware status of the data;

comparing the third representation to a previously determined representation; and

based on the comparison, estimating the malware status of the data.

7. The method of claim 1 , wherein the representations include a reputation score.

8. At least one non-transitory machine readable storage medium, comprising computer-executable instructions carried on the non-transitory machine readable storage medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

analyze a portion of data;

determine a first representation of the malware status of the data, including:

determining that the malware status of the data is not certain to be safe; and

determining that the malware status of the data is not certain to be malicious;

quarantine the data for a period of time;

determine a second representation of the malware status of the same data after the period of time;

estimate whether the data is associated with malware by comparing the first and second representation; and

based on the estimation of whether the data is associated with malware, release the data from quarantine.

9. The at least one machine readable storage medium of claim 8 , wherein:

comparing the first and second representation includes determining whether representation has changed, indicating an increased likelihood that the data is safe; and

determining whether the data is associated with malware includes estimating that the data is safe based upon the increased likelihood that the data is safe.

10. The at least one machine readable storage medium of claim 8 , wherein:

comparing the first and second representation includes determining whether representation has changed, indicating an decreased likelihood that the data is safe; and

determining whether the data is associated with malware includes estimating that the data is malicious based upon the decreased likelihood that the data is safe.

11. The at least one machine readable storage medium of claim 10 , wherein the data is blocked from arriving at an intended recipient if the data is associated with malware.

12. The at least one machine readable storage medium of claim 10 , wherein comparing the first and second representation includes determining whether the second representation has crossed a threshold value.

13. The at least one machine readable storage medium of claim 8 , wherein:

comparing the first and second representation yields a determination that:

the malware status of the data is not certain to be safe; and

the malware status of the data is not certain to be malicious; and

the processor is further caused to:

based on the determination, repeat the quarantining and determine a third representation of the malware status of the data;

compare the third representation to a previously determined representation; and

based on the comparison, estimate the malware status of the data.

14. The at least one machine readable storage medium of claim 8 , wherein the representations include a reputation score.

15. A system for preventing malware attacks, comprising:

a device including a portion of data;

a processor coupled to a computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by the processor, the instructions, when read and executed, for causing the processor to:

analyze the data;

determine a first representation of the malware status of the data, including:

determining that the malware status of the data is not certain to be safe; and

determining that the malware status of the data is not certain to be malicious;

quarantine the data for a period of time;

determine a second representation of the malware status of the same data after the period of time;

estimate whether the data is associated with malware by comparing the first and second representation; and

based on the estimation of whether the data is associated with malware, release the data from quarantine.

16. The system of claim 15 , wherein:

comparing the first and second representation includes determining whether representation has changed, indicating an increased likelihood that the data is safe; and

determining whether the data is associated with malware includes estimating that the data is safe based upon the increased likelihood that the data is safe.

17. The system of claim 15 , wherein:

comparing the first and second representation includes determining whether representation has changed, indicating an decreased likelihood that the data is safe; and

determining whether the data is associated with malware includes estimating that the data is malicious based upon the decreased likelihood that the data is safe.

18. The system of claim 17 , wherein the data is blocked from arriving at an intended recipient if the data is associated with malware.

19. The system of claim 17 , wherein comparing the first and second representation includes determining whether the second representation has crossed a threshold value.

20. The system of claim 15 , wherein:

comparing the first and second representation yields a determination that:

the malware status of the data is not certain to be safe; and

the malware status of the data is not certain to be malicious; and

the processor is further caused to:

based on the determination, repeat the quarantining and determine a third representation of the malware status of the data;

compare the third representation to a previously determined representation; and

based on the comparison, estimate the malware status of the data.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
CORRECTIVE ASSIGNMENT TO CORRECT THE FIFTH INVENTOR'S NAME PREVIOUSLY RECORDED ON REEL 028207 FRAME 0085. ASSIGNOR(S) HEREBY CONFIRMS THE INVENTOR NAME SHOULD BE CORRECTED TO READ "CHRISTOPHER C. WILLIAMS". Recorded Nov 7, 2012
From: BISHOP, MICHAEL G.; TIDDY, RAOUL J.; MUTTIK, IGOR; HINCHLIFFE, ALEXANDER J.; WILLIAMS, CHRISTOPHER C.
To: MCAFEE, INC.
Reel/Frame 029258/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2012
From: BISHOP, MICHAEL G.; TIDDY, RAOUL J.; MUTTIK, IGOR; HINCHLIFFE, ALEXANDER J.; WILIAMS, CHRISTOPHER C.
To: MCAFEE, INC.
Reel/Frame 029207/0085 →