IP Library Granted Patent US 8,881,292
Granted Patent B2
US 8,881,292 · App. 13/741,988 · Granted Nov 4, 2014

Evaluating whether data is safe or malicious

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,881,292
App. No.
13/741,988
Granted
Nov 4, 2014
Kind
B2
Abstract

“Known bad” data, “known good” data, or both can be stored in a database. A technique for evaluating data compares the data to the “known bad” data, “known good” data, or both. Based on the comparison, the data may or may not be allowed to be processed by a mobile device.

Claims (99)

1. In a mobile communications device having a network interface for receiving and sending data, a memory and a microprocessor, and further having software components for processing, analyzing and storing data, including at least a known good component for identifying data that is recognizably safe, a known bad component for identifying data that is recognizably malicious, and a decision component for evaluating whether data is safe or malicious, a method comprising:

providing data on the mobile communications device;

applying a hash function to the data to create a hash identifier for the data; and

comparing by the known good component, the data hash identifier against a database of identifiers of known good data stored in the mobile communications device memory;

if the comparison by the known good component results in a positive match, then allowing the data to be processed by the mobile communications device;

if the comparison by the known good component does not result in a positive match, then comparing by the known bad component, the data hash identifier against a database of identifiers of known bad data stored in the mobile communications device memory; and

if the comparison by the known bad component does not result in a positive match, then transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious.

2. The method of claim 1 , wherein the step of if the comparison by the known good component does not result in a positive match, then comparing by the known bad component, the data hash identifier against the database of identifiers of known bad data stored in the mobile communications device memory further comprises:

comparing by the known bad component the data hash identifier against a database of known bad data signatures stored in the mobile communications device memory, or against a database of known bad data patterns stored in the mobile communications device memory; and

if the comparison by the known bad component results in a positive match, then rejecting the data from being processed by the mobile communications device.

3. The method of claim 1 , further comprising:

if the comparison by the known bad component does not result in a positive match, instead of transmitting a signal from the mobile communication device to a server to indicate that an analysis of the data by the mobile communication device security component has not been able to characterize te data as recognizably safe or malicious, then using the decision component, performing an analysis on the data by the decision component to determine if the data is safe or malicious;

if the analysis determines that the data is safe, then allowing the data to be processed by the mobile communications device; and

if the analysis determines that the data is malicious, then rejecting the data from being processed by the mobile communications device.

4. In a mobile communications device having a network interface for receiving and sending data, a memory and a microprocessor, and further having software components for processing, analyzing and storing data, including at least a known good component for identifying data that is recognizably safe, a known bad component for identifying data that is recognizably malicious, and a decision component for evaluating whether data is safe or malicious, a method comprising:

providing data on the mobile communications device;

applying by the known good component, logic on the data to determine if the data is safe;

if the known good component logic determines that the data is safe, then allowing the data to be processed by the mobile communications device;

if the known good component does not determine that the data is safe, then applying by the known bad component, logic on the data to determine if the data is malicious;

if the known bad component logic determines that the data is malicious, then rejecting the data from being processed by the mobile communications device; and

if the known bad component logic does not determine that the data is malicious, then transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious.

5. The method of claim 4 , further comprising:

if the known bad component logic does not determine that the data is malicious, instead of transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious, then

using the decision component, performing an analysis on the data by the decision component to determine if the data is safe or malicious;

if the analysis shows that the data is safe, then allowing the data to be processed by the mobile communications device; and

if the analysis shows that the data is malicious, then rejecting the data from being processed by the mobile communications device.

6. In a mobile communications device having a network interface for receiving and sending data, a memory and a microprocessor, and further having software components for processing, analyzing and storing data, including at least a known good component for identifying data that is recognizably safe, a known bad component for identifying data that is recognizably malicious, and a decision component for evaluating whether data is safe or malicious, a method comprising:

providing data on the mobile communications device;

applying by the known good component, logic on the data to determine if the data is safe;

if the known good component logic determines that the data is safe, then allowing the data to be processed by the mobile communications device;

if the known good component logic does not determine that the data is safe, then applying, by the known bad component, logic on the data to determine if the data is malicious;

if the known bad component logic determines that the data is malicious, then rejecting the data from being processed by the mobile communications device; and

if the known bad component logic does not determine that the data is malicious, then transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious.

7. The method of claim 6 , further comprising:

if the known bad component logic does not determine that the data is malicious, instead of transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizable safe or malicious, then

using the decision component, performing an analysis on the data by the decision component to determine if the data is safe or malicious;

if the analysis determines that the data is safe, then allowing the data to be processed by the mobile communications device; and

if the analysis determines that the data is malicious, then rejecting the data from being processed by the mobile communications device.

8. In a mobile communications device having a network interface for receiving and sending data, a memory and a microprocessor, and further having software components for processing, analyzing and storing data, including at least a known good component for identifying data that is recognizably safe, a known bad component for identifying data that is recognizably malicious, and a decision component for evaluating whether data is safe or malicious, a method comprising:

providing data on the mobile communications device;

comparing by the known good component, the data against a database of characteristics for known good data stored in the mobile communications device; and

if the comparison by the known good component does not result in a positive match, then rejecting the data from being processed by the mobile communications device;

if the comparison by the known good component does result in a positive match, then comparing by the known bad component, the data against a database of characteristics for known bad data stored in the mobile communications device; and

if the comparison by the known bad component does not result in a positive match, then transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious.

9. The method of claim 8 , further comprising:

if the comparison by the known good component results in a positive match, then comparing by the known bad component, the data against either a database of characteristics for known bad data stored in the mobile communications device memory, or against a database of known bad data signatures stored in the mobile communications device memory, or against a database of known bad data patterns stored in the mobile communications device memory; and

if the comparison by the known bad component results in a positive match, then rejecting the data from being processed by the mobile communications device.

10. The method of claim 9 , further comprising:

if the comparison by the known bad component does not result in a positive match, then using the decision component, performing an analysis on the data by the decision component to determine if the data is safe or malicious;

if the analysis shows that the data is safe, then allowing the data to be processed by the mobile communications device; and

if the analysis shows that the data is malicious, then rejecting the data from being processed by the mobile communications device.

11. In a mobile communications device having a network interface for receiving and sending data, a memory and a microprocessor, and further having software components for processing, analyzing and storing data, including at least a known good component for identifying data that is recognizably safe, a known bad component for identifying data that is recognizably malicious, and a decision component for evaluating whether data is safe or malicious, a method comprising:

providing data on the mobile communications device;

applying a hash function to the data to create a hash identifier for the data; and

comparing by the known good component, the data hash identifier against a database of identifiers of known good data stored in the mobile communications device memory;

if the comparison by the known good component does not result in a positive match, then rejecting the data from being processed by the mobile communications device;

if the comparison by the known good component does result in a positive match, then comparing by the known bad component, the data hash identifier against a database of identifiers for known bad data stored in the mobile communications device memory; and

if the comparison by the known bad component does not result in a positive match, then transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious.

12. The method of claim 11 , further comprising:

if the comparison by the known good component results in a positive match, then comparing by the known bad component, the data hash identifier against a database of identifiers of known bad data stored in the mobile communications device memory, or against a database of known bad data signatures stored in the mobile communications device memory, or against a database of known bad data patterns stored in the mobile communications device memory; and

if the comparison by the known bad component results in a positive match, then rejecting the data from being processed by the mobile communications device.

13. The method of claim 12 , further comprising:

if the known bad component does not result in a positive match, instead of transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizable safe or malicious, then

using the decision component, performing an analysis on the data by the decision component to determine if the data is safe or malicious;

if the analysis shows that the data is safe, then allowing the data to be processed by the mobile communications device; and

if the analysis shows that the data is malicious, then rejecting the data from being processed by the mobile communications device.

14. In a mobile communications device having a network interface for receiving and sending data, a memory and a microprocessor, and further having software components for processing, analyzing and storing data, including at least a known good component for identifying data that is recognizably safe, a known bad component for identifying data that is recognizably malicious, and a decision component for evaluating whether data is safe or malicious, a method comprising:

providing data on the mobile communications device;

applying by the known good component, logic on the data to determine if the data is not safe;

if the known good component logic determines that the data is not safe, then rejecting the data from being processed by the mobile communications device;

if the known good component logic does not determine that the data is not safe, then applying by the known bad component, logic on the data to determine if the data is malicious; and

if the known bad component does not determine that the data is malicious, then transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious.

15. The method of claim 14 , wherein the step of if the known good component logic does not determine that the data is not safe, applying by the known bad component, logic on the data to determine if it is malicious further comprises:

if the known bad component determines that the data is malicious, then rejecting the data from being processed by the mobile communications device.

16. The method of claim 15 , further comprising:

if the known bad component does not determine that the data is malicious, instead of transmitting a signal from the mobile communications device to a server to indicate that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious, then

using the decision component, performing an analysis on the data by the decision component to determine if the data is safe or malicious;

if the analysis shows that the data is safe, then allowing the data to be processed by the mobile communications device; and

if the analysis shows that the data is malicious, then rejecting the data from being processed by the mobile communications device.

17. On a server having a network interface for receiving from and sending data to a mobile communications device having software components for processing and analyzing data, a method comprising:

when the mobile communications device receives data, creates a hash identifier for the data, compares the data hash identifier against a database of known good data stored on the mobile communications device, does not obtain a positive match, compares the data hash identifier against a database stored on the mobile communications device containing hash identifiers of known bad data, and does not obtain a positive match, receiving the data at the server, wherein the data is a signal from the mobile communications device that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious;

at the server, using a decision component, performing an analysis on the data to determine if the data is safe or malicious;

if the analysis by the decision component at the server determines that the data is safe, then sending an instruction from the server to the mobile communications device to allow the data to be processed by the mobile communications device; and

if the analysis by the decision component at the server determines that the data is malicious, then sending an instruction from the server to the mobile communications device to reject the data from being processed by the mobile communications device.

18. On a server having a network interface for receiving from and sending data to a mobile communications device having software components for processing and analyzing data, a method comprising:

after the mobile communications device receives data, creates a hash identifier for the data, using a known bad component, compares the received data hash identifier against a database stored in the mobile communications device memory containing hash identifiers of known bad data, does not obtain a positive match, then compares the data hash identifier against a database of known good data stored on the mobile communications device and does not obtain a positive match, receiving the data at the server, wherein the data is a signal from the mobile communications device that an analysis of the data by the mobile communications device security component has not been able to characterize the data as recognizably safe or malicious;

at the server, using a decision component, performing an analysis on the data to determine if the data is safe or malicious;

if the analysis by the decision component at the server determines that the data is safe, then sending an instruction from the server to the mobile communications device to allow the data to be processed by the mobile communications device; and

if the analysis by the decision component at the server determines that the data is malicious, then sending an instruction from the server to the mobile communications device to reject the data from being processed by the mobile communications device.

19. On a server having a network interface for receiving from and sending data to a mobile communications device having software components for processing and analyzing data, a method comprising:

when the mobile communications device receives data, applies by a known good component logic on the data to determine if the data is safe, does not obtain a positive match, applies by a known bad component logic on the data to determine if the data is recognizably malicious, and does not obtain a positive match, receiving the data from the mobile communications device at the server, wherein the data is a signal from the mobile communications device that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious;

at the server, using a decision component, performing an analysis on the received data to determine if the data is safe or malicious;

if the analysis by the decision component at the server determines that the data is safe, then sending an instruction from the server to the mobile communications device to allow the data to be processed by the mobile communications device; and

if the analysis by the decision component at the server determines that the data is malicious, then sending an instruction from the server to the mobile communications device to reject the data from being processed by the mobile communications device.

20. On a server having a network interface for receiving from and sending data to a mobile communications device having software components for processing and analyzing data, a method comprising:

after the mobile communications device receives data, applying by a known bad component logic to the data to determine whether the data is recognizably malicious, does not obtain a positive match, then applying by known good component logic to the data to determine whether the data is safe and does not obtain a positive match, receiving the data at the server, wherein the data is a signal from the mobile communications device that an analysis of the data by a mobile communications device security component has not been able to characterize the data as recognizably safe or malicious;

at the server, applying by a decision component logic to the data for performing an analysis on the data to determine if the data is safe or malicious;

if the determination by the decision component at the server determines that the data is safe, then sending an instruction from the server to the mobile communications device to allow the data to be processed by the mobile communications device; and

if the determination by the decision component at the server determines that the data is malicious, then sending an instruction from the server to the mobile communications device to reject the data from being processed by the mobile communications device.

Assignments (11)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2020
From: OBSIDIAN AGENCY SERVICES, INC.
To: LOOKOUT INC.
Reel/Frame 054716/0923 →
SECURITY INTEREST Recorded Jun 6, 2019
From: LOOKOUT, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 049408/0861 →
SECURITY INTEREST Recorded Oct 29, 2018
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 048208/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2013
From: MAHAFFEY, KEVIN
To: FLEXILIS, INC.
Reel/Frame 029632/0953 →
CHANGE OF NAME Recorded Jan 15, 2013
From: FLEXILIS, INC.
To: LOOKOUT, INC.
Reel/Frame 029635/0100 →