IP Library Granted Patent US 9,613,213
Granted Patent B2
US 9,613,213 · App. 14/341,183 · Granted Apr 4, 2017

Using telemetry to reduce malware definition package size

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,613,213
App. No.
14/341,183
Granted
Apr 4, 2017
Kind
B2
Abstract

Clients send telemetry data to a cloud server, where the telemetry data includes security-related information such as file creations, timestamps and malware detected at the clients. The cloud server analyzes the telemetry data to identify malware that is currently spreading among the clients. Based on the analysis of the telemetry data, the cloud server segments malware definitions in a cloud definition database into a set of local malware definitions and a set of cloud malware definitions. The cloud server provides the set of local malware definitions to the clients as a local malware definition update, and replies to cloud definition lookup requests from clients with an indication of whether a file identified in a request contains malware. If the file is malicious, the client remediates the malware using local malware definition update.

Claims (38)

1. A computer-implemented method of providing malicious software (malware) definitions to clients, wherein the clients are electronic devices, comprising:

receiving telemetry data from a plurality of clients, the telemetry data describing files created on the clients;

analyzing the telemetry data to identify malware that is currently spreading among the plurality of clients, the analysis based at least in part on whether a particular type of malware is detected on a threshold number of clients within a predetermined time period and an amount of damage caused by the particular type of malware;

identifying a subset of a set of cloud malware definitions responsive to the analysis of the telemetry data, the identified subset containing malware definitions for malware identified as currently spreading among the plurality of clients; and

providing the identified subset of the cloud malware definitions as a set of local malware definitions to the plurality of clients, wherein the plurality of clients are adapted to store the local malware definitions and use the set of local malware definitions to detect malware at the clients.

2. The method of claim 1 , wherein receiving telemetry data from the plurality of clients comprises:

determining whether a file created on a client of the plurality of clients matches a malware definition in the set of malware definitions; and

replying to a cloud definition lookup request from the client indicating whether the created file matches a malware definition in the set of malware definitions.

3. The method of claim 1 , wherein the telemetry data describes at least some files that do not match any known malware.

4. The method of claim 1 , further comprising:

maintaining a cloud definition database storing the set of cloud malware definitions.

5. The method of claim 1 , further comprising:

removing a malware definition from the set of local malware definitions responsive to a determination that malware corresponding to the malware definition is not currently spreading among the plurality of clients.

6. A non-transitory computer-readable storage medium storing executable computer program instructions for providing malicious software (malware) definitions to clients, the computer program instructions comprising instructions for:

receiving telemetry data from a plurality of clients, the telemetry data describing files created on the clients;

analyzing the telemetry data to identify malware that is currently spreading among the plurality of clients, the analysis based at least in part on whether a particular type of malware is detected on a threshold number of clients within a predetermined time period and an amount of damage caused by the particular type of malware;

identifying a subset of a set of cloud malware definitions responsive to the analysis of the telemetry data, the identified subset containing malware definitions for malware identified as currently spreading among the plurality of clients; and

providing the identified subset of the cloud malware definitions as a set of local malware definitions to the plurality of clients, wherein the plurality of clients are adapted to store the local malware definitions and use the set of local malware definitions to detect malware at the clients.

7. The computer-readable storage medium of claim 6 , wherein the computer program instructions for receiving telemetry data from the plurality of clients comprise instructions for:

determining whether a file created on a client of the plurality of clients matches a malware definition in the set of malware definitions; and

replying to a cloud definition lookup request from the client indicating whether the created file matches a malware definition in the set of malware definitions.

8. The computer-readable storage medium of claim 6 , wherein the telemetry data describes at least some files that do not match any known malware.

9. The computer-readable storage medium of claim 6 , further comprising computer program instructions for:

maintaining a cloud definition database storing the set of cloud malware definitions.

10. The computer-readable storage medium of claim 6 , further comprising computer program instructions for:

removing a malware definition from the set of local malware definitions responsive to a determination that malware corresponding to the malware definition is not currently spreading among the plurality of clients.

11. A system for providing malicious software (malware) definitions to clients, the system comprising:

a processor for executing computer program instructions; and

a non-transitory computer-readable storage medium storing executable computer program instructions, the computer program instructions comprising instructions for:

receiving telemetry data from a plurality of clients, the telemetry data describing files created on the clients;

analyzing the telemetry data to identify malware that is currently spreading among the plurality of clients, the analysis based at least in part on whether a particular type of malware is detected on a threshold number of clients within a predetermined time period and an amount of damage caused by the particular type of malware;

identifying a subset of a set of cloud malware definitions responsive to the analysis of the telemetry data, the identified subset containing malware definitions for malware identified as currently spreading among the plurality of clients; and

providing the identified subset of the cloud malware definitions as a set of local malware definitions to the plurality of clients, wherein the plurality of clients are adapted to store the local malware definitions and use the set of local malware definitions to detect malware at the clients.

12. The system of claim 11 , wherein the telemetry data describes at least some files that do not match any known malware.

13. The system of claim 11 , further comprising computer program instructions for:

maintaining a cloud definition database storing the set of cloud malware definitions.

14. The system of claim 11 , further comprising computer program instructions for:

removing a malware definition from the set of local malware definitions responsive to a determination that malware corresponding to the malware definition is not currently spreading among the plurality of clients.

Assignments (6)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NO PREVIOUSLY RECORDED ON REEL 041205 FRAME 0741. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT WAS INCORRECTLY RECORDED FOR 13682288 INSTEAD OF 14341183. Recorded Feb 28, 2017
From: PEREIRA, SHANE; NACHENBERG, CAREY S.
To: SYMANTEC CORPORATION
Reel/Frame 041829/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2017
From: PEREIRA, SHANE; NACHENBERG, CAREY S.
To: SYMANTEC CORPORATION
Reel/Frame 041205/0741 →