IP Library Granted Patent US 9,467,470
Granted Patent B2
US 9,467,470 · App. 14/583,509 · Granted Oct 11, 2016

System and method for local protection against malicious software

Inventors: Rishi Bhargava (Cupertino, CA); David P. Reese, Jr. (Sunnyvale, CA)
Assignee: McAfee, Inc.
H04L63/145G06F21/53G06F21/54G06F21/554G06F21/566G06F21/604G06F21/606H04L63/10H04L63/1416G06F2221/2101G06F2221/2115G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,470
App. No.
14/583,509
Granted
Oct 11, 2016
Kind
B2
Abstract

A method in one example implementation includes intercepting a network access attempt on a computing device and determining a software program file associated with the network access attempt. The method also includes evaluating a first criterion to determine whether the network access attempt is permitted and blocking the network access attempt if it is not permitted. The first criterion includes a trust status of the software program file. In specific embodiments, the trust status is defined as trusted if the software program file is included in a whitelist of trustworthy program files and untrusted if the software program file is not included in a whitelist. In more specific embodiments, the method includes blocking the network access attempt if the software program file has an untrusted status. In further embodiments, an event is logged if the software program file associated with the network access attempt has an untrusted status.

Claims (49)

1. One or more non-transitory machine readable media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:

intercepting, on a computing device, a network access attempt associated with

a process executing on the computing device;

determining a plurality of software program files mapped to the process, wherein at least one software program file of the plurality of software program files is an executable file and at least one other software program file of the plurality of software program files is a library module loaded by the process;

determining trust statuses of at least the executable file and the library module;

determining whether the network access attempt is permitted based, at least in part, on the trust statuses of the executable file and the library module; and

performing an action if the network access attempt is not permitted,

wherein if one of the software program files is determined to have an untrusted status, the network access attempt is permitted if a destination address of the network access attempt is contained in a set of allowed destination addresses indicated by a network access policy associated with the one of the software program files.

2. The one or more non-transitory machine readable media of claim 1 , wherein the network access attempt is determined not to be permitted if no policy overrides the untrusted status.

3. The one or more non-transitory machine readable media of claim 2 , wherein the trust status of a particular software program file of the plurality of software program files is defined as untrusted if the particular software program file is not identified in a whitelist.

4. The one or more non-transitory machine readable media of claim 1 , the one or more processors being operable to perform further operations comprising:

searching a local cache that identifies trusted software program files, to determine a trust status of each of the plurality of software program files;

querying a central server for the trust status of each software program file not identified by the local cache; and

updating the local cache with identifications of any software program files determined to be trusted by the central server.

5. The one or more non-transitory machine readable media of claim 1 , wherein the performing the action includes blocking the network access attempt when the network access attempt is determined not to be permitted.

6. The one or more non-transitory machine readable media of claim 1 , wherein at least one network hook, loaded into the process, is to intercept an application programming interface (API) associated with the network access attempt.

7. The one or more non-transitory machine readable media of claim 1 , wherein the network access attempt is one of an outbound network access attempt from the process or an inbound network access attempt to the process.

8. The one or more non-transitory machine readable media of claim 1 , the one or more processors being operable to perform further operations comprising:

using an operating system application programming interface to determine the plurality of software program files mapped to the process.

9. The one or more non-transitory machine readable media of claim 1 , the one or more processors being operable to perform further operations comprising:

responsive to determining the one of the software program files has the untrusted status, evaluating the network access policy to determine whether the network access policy overrides the untrusted status; and

applying the network access policy to the network access attempt if the network access policy is determined to override the untrusted status.

10. The one or more non-transitory machine readable media of claim 1 , wherein the performing the action includes logging information related to the network access attempt if the trust status of at least one of the plurality of software program files is determined to be untrusted.

11. An apparatus, comprising:

a protection module; and

one or more processors operable to execute instructions associated with the protection module, to cause the one or more processors to:

intercept, on a computing device, a network access attempt associated with

a process executing on the computing device;

determine a plurality of software program files mapped to the process, wherein at least one software program file of the plurality of software program files is an executable file and at least one other software program file of the plurality of software program files is a library module loaded by the process;

determine trust statuses of at least the executable file and the library module;

determine whether the network access attempt is permitted based, at least in part, on the trust statuses of the executable file and the library module; and

perform an action if the network access attempt is not permitted,

wherein if one of the software program files is determined to have an untrusted status, the network access attempt is permitted if a destination address of the network access attempt is contained in a set of allowed destination addresses indicated by a network access policy associated with the one of the software program files.

12. The apparatus of claim 11 , wherein the performing the action includes blocking the network access attempt when the network access attempt is determined not to be permitted.

13. The apparatus of claim 11 , wherein at least one network hook, loaded into the process, is to intercept an application programming interface (API) associated with the network access attempt.

14. The apparatus of claim 11 , the one or more processors being operable to execute further instructions associated with the protection module, to cause the one or more processors to:

use an operating system application programming interface to determine the plurality of software program files mapped to the process.

15. The apparatus of claim 11 , wherein the performing the action includes logging information related to the network access attempt if the trust status of at least one of the plurality of software program files is determined to be untrusted.

16. A method comprising:

intercepting, on a computing device, a network access attempt associated with

a process executing on the computing device;

determining a plurality of software program files mapped to the process, wherein at least one software program file of the plurality of software program files is an executable file and at least one other software program file of the plurality of software program files is a library module loaded by the process;

determining trust statuses of at least the executable file and the library module;

determining whether the network access attempt is permitted based, at least in part, on the trust statuses of the executable file and the library module; and

performing an action if the network access attempt is not permitted,

wherein if one of the software program files is determined to have an untrusted status, the network access attempt is permitted if a destination address of the network access attempt is contained in a set of allowed destination addresses indicated by a network access policy associated with the one of the software program files.

17. The method of claim 16 , wherein the performing the action includes blocking the network access attempt when the network access attempt is determined not to be permitted.

18. The method of claim 16 , wherein at least one network hook, loaded into the process, is to intercept an application programming interface (API) associated with the network access attempt.

19. The method of claim 16 , further comprising: using an operating system application programming interface to determine the plurality of software program files mapped to the process.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
Continuity (2)
Continuation 12844892 · Jul 28, 2010
Related Publication 20150180884A1 · Jun 25, 2015