METHODS AND APPARATUS FOR AGENT-BASED MALWARE MANAGEMENT
Methods and apparatus for providing protection against malware are disclosed. An exemplary method includes executing an agent program on a remote computer connected to a network, the agent program being configured to communicate with a base computer via the network, the agent program including a firewall arranged to block communications between the remote computer and entities on the network in accordance with predetermined rules; and configuring the firewall in accordance with rules received from the base computer.
1 . A method of operating a security program on a computer, comprising:
operating the security program to impersonate or use operating system functions in monitoring objects running on the computer;
determining, based upon the monitoring, whether the objects are malware.
2 . A non-transitory, tangible processor readable storage medium, encoded with processor readable instructions to perform a method for fighting malware on a computer, the method comprising:
impersonating operating system functions to monitor objects running on the computer; and
determining whether the objects are malware or not based upon the monitoring.
3 . A method of operating a security program on a computer, comprising:
loading a first component of the security program on the computer;
dynamically creating a second component of the security program on the computer having different attributes from the first component and which will automatically load in the event that the first component fails to load due to malevolent activity.
4 . A method according to claim 3 , wherein the second component is arranged to remove its own digital signature.
5 . A non-transitory, tangible processor readable storage medium, encoded with processor readable instructions to perform a method for fighting malware, the method comprising:
loading a first component of the security program on the computer; and
dynamically creating a second component of the security program on the computer having different attributes from the first component and which will automatically load in the event that the first component fails to load due to malevolent activity.
6 . The non-transitory, tangible processor readable storage medium according to claim 5 , wherein the second component is arranged to remove its own digital signature.
7 . A method of providing protection against malware, the method comprising:
executing an agent program on a remote computer connected to a network, the agent program being configured to communicate with a base computer via the network, the agent program including a firewall arranged to block communications between the remote computer and entities on the network in accordance with predetermined rules; and
configuring the firewall in accordance with rules received from the base computer.
8 . A method according to claim 7 , comprising:
receiving at the remote computer from the base computer information that an object on the remote computer and or an entity on the network is unsafe; and
including a rule at the remote computer so that intended network communications involving the unsafe object and or unsafe entity are blocked by the firewall.
9 . The method according to claim 8 , comprising:
receiving at the remote computer from the base computer information that an object on the remote computer and or an entity on the network is unsafe;
asking permission from the user of the remote computer for details of intended network communications involving the unsafe object and or unsafe entity to be shared with a third party; and,
intercepting intended network communications involving the unsafe object and or the unsafe entity and sharing them with a third party.
10 . A non-transitory, tangible processor readable storage medium, encoded with processor readable instructions to perform a method for providing protection against malware, the method comprising:
communicating with a base computer via the network,
creating a firewall arranged to block communications between the remote computer and entities on the network in accordance with predetermined rules; and
configuring the firewall in accordance with rules received from the base computer.
11 . The non-transitory, tangible processor readable storage medium according to claim 10 , the method including:
receiving at the remote computer from the base computer information that an object on the remote computer and or an entity on the network is unsafe; and
including a rule at the remote computer so that intended network communications involving the unsafe object and or unsafe entity are blocked by the firewall.
12 . The non-transitory, tangible processor readable storage medium according to claim 10 , the method including:
receiving at the remote computer from the base computer information that an object on the remote computer and or an entity on the network is unsafe;
asking permission from the user of the remote computer for details of intended network communications involving the unsafe object and or unsafe entity to be shared with a third party; and
intercepting intended network communications involving the unsafe object and or the unsafe entity and sharing them with a third party.