IP Library Granted Patent US 9,754,102
Granted Patent B2
US 9,754,102 · App. 14/507,657 · Granted Sep 5, 2017

Malware management through kernel detection during a boot sequence

Inventor: Jerome L. Schneider (Boulder, CO)
Assignee: Webroot Inc.
G06F21/51G06F21/554G06F21/56G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,754,102
App. No.
14/507,657
Granted
Sep 5, 2017
Kind
B2
Abstract

A system and method for managing pestware on a protected computer is described. The method in one variation includes monitoring events during a boot sequence of the computer; managing pestware-related events before native applications can run and after a kernel is loaded; managing pestware-related events when native applications can run; and scanning a registry of the computer for pestware when native applications can run. In variations, a pestware management engine is initialized after an operating system of the protected computer is initialized and the pestware management system both receives an event log of the monitored events and compiles the set of behavior rules utilized by kernel-level monitor.

Claims (43)

1. A device-comprising:

at least one processor; and

a memory encoding computer executable instructions that, when executed by the at least one processor, perform a method comprising:

monitoring events during a boot sequence of the computer; managing pestware-related events during a first period in a boot sequence of the computer, the first period in the boot sequence occurring before the computer becomes configured to run native applications, before a subsystem of an operating system is loaded, and after a kernel is loaded;

managing pestware-related events in accordance with a set of behavior rules during a second period in the boot sequence occurring when the computer is configured to run native applications;

generating, in response to the monitoring, a record of events, the record of events including the pestware-related events;

analyzing the record of events so as to identify the pestware-related events; modifying the set of behavior rules so as to prevent the pestware related events;

and

scanning a registry of the computer for pestware during the second period in the boot sequence.

2. The device of claim 1 , wherein the method further comprises launching, after an operating system is initiated, a pestware management engine; and

wherein the set of behavior rules includes behavior rules compiled by the pestware management engine.

3. The device of claim 1 , wherein the record of events includes information selected from the group consisting of: process identification information, file identification information, and hook generation information.

4. The device of claim 1 , wherein the method further comprises managing pestware-related events after the computer becomes configured to run native applications.

5. The device of claim 1 , wherein the monitoring includes monitoring the boot sequence while boot drivers are initiated.

6. A system for managing pestware on a computer comprising:

at least one processor;

a memory encoding computer executable instructions that, when executed by the at least one processor, perform a method comprising:

monitoring events during a boot sequence of the computer;

managing pestware-related events during first period in a boot sequence of the computer, the first period in the boot sequence occurring before the computer becomes configured to run native applications, before a subsystem is loaded, and after a kernel is loaded;

managing pestware-related events in accordance with a set of behavior rules during a second period in the boot sequence occurring when the computer is configured to run native applications;

generating, in response to the monitoring, a record of events, the record of events including the pestware-related events;

analyzing the record of events so as to identify the pestware-related events; and

modifying the set of behavior rules so as to prevent the pestware related events; and

scanning a registry of the computer for pestware during the second period in the boot sequence.

7. The system of claim 6 , wherein the method further comprises launching, after an operating system is initiated, a pestware management engine; and wherein the set of behavior rules includes behavior rules compiled by the pestware management engine.

8. The system of claim 6 , wherein the record of events includes information selected from the group consisting of: process identification information, file identification information, and hook generation information.

9. The system of claim 6 , wherein the method further comprises

managing pestware-related events after the computer becomes configured to run native applications.

10. The system of claim 6 , wherein the method further comprises monitoring the boot sequence while boot drivers are initiated.

11. A hard drive comprising computer executable instructions that, when executed by at least one processor, perform a method comprising:

monitoring events during a boot sequence of a computer;

managing pestware-related events during a first period in a boot sequence of the computer, the first period in the boot sequence occurring before the computer becomes configured to run native applications, before a subsystem is loaded, and after a kernel is loaded;

managing pestware-related events in accordance with a set of behavior rules during a second period in the boot sequence occurring when the computer is configured to run native applications;

generating, in response to the monitoring, a record of events, the record of events including the pestware-related events;

analyzing the record of events so as to identify the pestware-related events; and

modifying the set of behavior rules so as to prevent the pestware related events; and

scanning a registry of the computer for pestware during the second period in the boot sequence.

12. The hard drive of claim 11 further comprising program instructions for launching, after an operating system is initiated, a pestware management engine; and

wherein the set of behavior rules includes behavior rules compiled by the pestware management engine.

13. The hard drive of claim 11 , wherein the record of events includes information selected from the group consisting of: process identification information, file identification information, and hook generation information.

14. The hard drive of claim 11 further comprising program instructions for:

managing pestware-related events after the computer becomes configured to run native applications.

15. The hard drive of claim 11 , wherein the monitoring includes monitoring the boot sequence while boot drivers are initiated.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2015
From: SCHNEIDER, JEROME L.
To: WEBROOT SOFTWARE, INC.
Reel/Frame 034905/0309 →
CHANGE OF NAME Recorded Feb 6, 2015
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 034919/0706 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
Continuity (3)
Continuation 13460655 · Apr 30, 2012
Continuation 11462827 · Aug 7, 2006
Related Publication 20150089648A1 · Mar 26, 2015