IP Library Granted Patent US 8,918,888
Granted Patent B2
US 8,918,888 · App. 14/156,887 · Granted Dec 23, 2014

Agent based application reputation system for operating systems

Inventor: Pirkka Palomaki (Saratoga, CA)
Assignee: F-Secure Corporation
G06F21/56G06F21/577G06F21/565G06F21/567
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,918,888
App. No.
14/156,887
Granted
Dec 23, 2014
Kind
B2
Abstract

A method for implementing a security agent on behalf of a device, the method comprising: obtaining a list of applications installed on the device from a remote repository; for each respective application on the list, comparing reputation attributes obtained from a reputation database against attributes of the application installed on the device; and for any of the respective applications for which it is determined from the comparing that the application installed on the device is malicious, taking action to limit malicious activity by the respective application installed on the device.

Claims (35)

1. A method for implementing a security agent on behalf of a device, the method comprising:

obtaining, by a processor, a list of applications installed on the device from a repository remote from the security agent and device, wherein the repository is located on another device independent from the security agent and the device;

for each respective application on the list, comparing reputation attributes obtained from a reputation database against attributes of the application installed on the device; and

for any of the respective applications for which it is determined from the comparing that the application installed on the device is malicious, taking action to limit malicious activity by the respective application installed on the device;

wherein the security agent is not installed on the device.

2. The method according to claim 1 , wherein the security agent obtains the list of applications installed on the device using security credentials provided by a user of the device.

3. The method according to claim 2 , wherein the security agent obtains the list of applications installed on the device from at least one of a virtual application store and a virtual social networking site from which the installed applications were downloaded to the device.

4. The method according to claim 1 , wherein the reputation attributes for each respective application on the list that are obtained from the reputation database comprise at least:

whether the respective application is malicious or safe;

battery consumption due to execution of the respective application; and

resources on the device that are accessed by the respective application.

5. The method according to claim 4 , wherein the reputation attributes are obtained from the reputation database by deriving a unique identifier for each respective application on the list and submitting each of the derived unique identifiers to the reputation database.

6. A non-transitory computer readable memory storing a set of executable instructions for implementing a security agent on behalf of a device, the set of executable instructions comprising:

code for obtaining, by a processor, a list of applications installed on the device from a repository remote from the security agent and the device, wherein the repository is located on another device independent from the security agent and the device;

code for comparing, for each respective application on the list, reputation attributes obtained from a reputation database against attributes of the application installed on the device; and

for any of the respective applications for which it is determined from executing the code for comparing that the application installed on the device is malicious, code for taking action to limit malicious activity by the respective application installed on the device.

7. The computer readable memory according to claim 6 , wherein the code for obtaining operates to obtain the list of applications installed on the device using security credentials provided by a user of the device.

8. The computer readable memory according to claim 7 , wherein the code for obtaining operates to obtain the list of applications installed on the device from at least one of a virtual application store and a virtual social networking site from which the installed applications were downloaded to the device.

9. The computer readable memory according to claim 6 , wherein the reputation attributes for each respective application on the list that are obtained from the reputation database comprise at least:

whether the respective application is malicious or safe;

battery consumption due to execution of the respective application; and

resources on the device that are accessed by the respective application.

10. The computer readable memory according to claim 9 , wherein the reputation attributes are obtained from the reputation database by deriving a unique identifier for each respective application on the list and submitting each of the derived unique identifiers to the reputation database.

11. At least one security server comprising at least one memory storing a set of computer executable instructions and at least one processor, wherein the memory with the set of computer executable instructions is configured with the at least one processor to cause the security server to at least:

obtain, by the processor, a list of applications installed on a device from a repository remote from the security server and the device, wherein the repository is located on another device independent from the security server and the device;

for each respective application on the list, compare reputation attributes obtained from a reputation database against attributes of the application installed on the device; and

for any of the respective applications for which it is determined from the comparing that the application installed on the device is malicious, take action to limit malicious activity by the respective application installed on the device.

12. The at least one security server according to claim 11 , wherein the security agent obtains the list of applications installed on the device using security credentials provided by a user of the device.

13. The at least one security server according to claim 12 , wherein the security agent obtains the list of applications installed on the device from at least one of a virtual application store and a virtual social networking site from which the installed applications were downloaded to the device.

14. The at least one security server according to claim 11 , wherein the reputation attributes for each respective application on the list that are obtained from the reputation database comprise at least:

whether the respective application is malicious or safe;

battery consumption due to execution of the respective application; and

resources on the device that are accessed by the respective application.

15. The at least one security server according to claim 14 , wherein the reputation attributes are obtained from the reputation database by deriving a unique identifier for each respective application on the list and submitting each of the derived unique identifiers to the reputation database.

16. The security server according to claim 11 , wherein the set of computer executable instructions operate in conjunction with a security agent client application resident on the device to implement a personal cloud security service on behalf of the device using security credentials provided by a user of the device.

Assignments (2)
CHANGE OF NAME Recorded Aug 31, 2023
From: F-SECURE CORPORATION
To: WITHSECURE CORPORATION (A/K/A WITHSECURE OYJ)
Reel/Frame 064789/0594 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2014
From: PALOMAKI, PIRKKA
To: F-SECURE CORPORATION
Reel/Frame 031985/0930 →
Priority Claims (1)
GB 1301016.0 · Jan 21, 2013 · national
Continuity (1)
Related Publication 20140208425A1 · Jul 24, 2014