IP Library Granted Patent US 9,112,899
Granted Patent B2
US 9,112,899 · App. 14/264,148 · Granted Aug 18, 2015

Remedial action against malicious code at a client facility

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,112,899
App. No.
14/264,148
Granted
Aug 18, 2015
Kind
B2
Abstract

Aspects of this invention may relate to a malicious application remedial action request application where a network site interaction may be requested from a client computing facility; the network site interaction from the client computing facility may be determined to be unacceptable based on an acceptance policy at a gateway facility; access to the network site from the client computing facility may be denied; information relating to the attempted interaction with the network site may be sent from the gateway facility to the client computing facility, wherein the information may indicate that the attempted interaction occurred; and the client computing facility may interpret the information relating to the attempted interaction, determine whether the attempted interaction was the result of an automatically generated request, and take remedial action in the event that the attempted interaction was the result of the automatically generated request.

Claims (30)

1. A method for externally initiating remediation against malicious code executing undetected on a client, the method comprising:

originating a request for an interaction with a network site by a client computing facility;

determining by the client computing facility that the interaction is unacceptable based on an acceptance policy for an enterprise;

denying access to the network site by the client computing facility;

receiving, by the client computing facility, an information file from a gateway facility to the enterprise including information relating to the requested interaction with the network site, wherein the information indicates that the interaction was requested;

interpreting, by the client computing facility, in response to receipt of the information file, the information relating to the requested interaction;

determining, by the client computing facility, whether the requested interaction was the result of an automatically generated request by malicious code; and

taking, by the client computing facility, remedial action in the event that the attempted interaction was the result of the automatically generated request by malicious code.

2. The method of claim 1 , wherein the acceptance policy includes at least one of an unacceptable network site database, an acceptable network site database, or a network site reputation database.

3. The method of claim 1 , wherein the acceptance policy is based on at least one of a block list or an acceptance list.

4. The method of claim 1 , wherein the acceptance policy includes a rule evaluation of the requested interaction acceptability.

5. The method of claim 1 , wherein the interaction is an access request to a network system.

6. The method of claim 1 , wherein the information is stored on the client computing facility.

7. The method of claim 6 , wherein the stored information is parsed by a client computer facility malicious code analysis application using a virus identity file (IDE).

8. The method of claim 7 , wherein the IDE parsed information is used to determine an appropriate action by the client computing facility.

9. The method of claim 1 , wherein the remedial action taken by the client computing facility is a result of a client computer facility resident malicious code detection application accessing information using IDE information.

10. The method of claim 1 , wherein the information includes data adapted to be interpreted by the client computing facility.

11. The method of claim 1 , wherein the information includes at least one command to be executed by the client computing facility.

12. The method of claim 11 , wherein the command is to isolate the client computing facility.

13. The method of claim 1 , wherein the remedial action includes scanning the client computing facility for malware.

14. The method of claim 1 , wherein the remedial action includes any action determined by a client computer facility malicious code analysis application interacting with an IDE and the information.

15. The method of claim 1 , wherein the client computing facility is part of a computer network facility.

16. The method of claim 1 , further comprising sending an access approval request from the client computing facility to an acceptance policy facility indicating that the requested interaction was user initiated and requesting a policy change to allow the user initiated interaction.

17. The method of claim 10 , further comprising allowing at least temporary interaction from the client computing facility through the acceptance policy facility based on the requested policy change.

18. A computer program product for externally initiating remediation against malicious code executing undetected on a client, the computer program product embodied in a non-transitory computer readable medium that, when executing on one or more computers, performs the steps of:

originating a request for an interaction with a network site at a client computing facility;

determining at the client computing facility that the interaction is unacceptable based on an acceptance policy for an enterprise;

denying access to the network site from the client computing facility;

receiving an information file from a gateway facility to the enterprise at the client computing facility including information relating to the requested interaction with the network site, wherein the information indicates that the interaction was requested; and

causing the client computing facility, in response to receipt of the information file, to interpret the information relating to the requested interaction, to determine whether the requested interaction was the result of an automatically generated request by malicious code, and to take remedial action in the event that the attempted interaction was the result of the automatically generated request by malicious code.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2014
From: BACCAS, PAUL; HOWARD, FRASER; SVAJCER, VANJA
To: SOPHOS PLC
Reel/Frame 032780/0385 →
CHANGE OF NAME Recorded Apr 29, 2014
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 032780/0485 →