IP Library Granted Patent US 48,043
Granted Patent E1
US 48,043 · App. 14/583,642 · Granted Jun 9, 2020

System, method and computer program product for sending unwanted activity information to a central system

Inventor: Ahmed Said Sallam (Cupertino, CA)
Assignee: McAfee, LLC
G06F21/552G06F21/566H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 48,043
App. No.
14/583,642
Granted
Jun 9, 2020
Kind
E1
Abstract

A system, method and computer program product are provided for sending, to a central system, information associated with unwanted activity. In use, information associated with unwanted activity is identified utilizing a plurality of different types of security systems. Further, the information is sent to a central system.

Claims (46)

1. A method, comprising:

receiving one or more rules from a central system;

identifying information associated with unwanted activity, utilizing a plurality of different types of security systems of a client system, which includes a processor and a memory, and which is configured with a plurality of rules for resolving the unwanted activity independent of instructions provided by a the central system, wherein at least one of the different types of security systems utilizes behavioral monitoring that includes heuristics of the unwanted activity to detect the unwanted activity without utilizing the one or more rules, and the client system is further configured to detect the unwanted activity utilizing the one or more rules;

sending the information to the central system for aggregating the information with additional information sets provided by additional client systems; and

receiving a response sent from the central system to the client system and to the additional client systems, wherein the response is based on the information and is indicative of whether the information was verified as being associated with the unwanted activity, and wherein the response includes a rule for removing code associated with the unwanted activity, and the response includes a rule for detecting future instances of the information, and the response includes a rule for adding the information to a blacklist.

2. The method of claim 1 , wherein the plurality of different types of security systems include two or more of a firewall, an intrusion prevention system, an anti-spyware system, and a virus scanner.

3. The method of claim 1 , wherein the information is correlated prior to sending the information to the central system.

4. The method of claim 1 , wherein the information includes a source of the unwanted activity.

5. The method of claim 1 , wherein the information includes a decision made in response to the unwanted activity.

6. The method of claim 5 , wherein the decision is to block execution of the unwanted activity.

7. The method of claim 1 , wherein the information includes an alert.

8. The method of claim 1 , further comprising detecting the unwanted activity, utilizing the plurality of different security systems.

9. The method of claim 8 , wherein the unwanted activity is detected utilizing at least one rule received from the central system.

10. The method of claim 1 , wherein the information is sent to a database via the central system.

11. The method of claim 1 , wherein the information is sent to the central system for correlation with other information associated with at least one network security system.

12. A computer program product embodied on a non-transitory computer readable medium for performing operations, comprising:

receiving one or more rules from a central system;

identifying information associated with unwanted activity, utilizing a plurality of different types of security systems of a client system, which includes a processor and a memory, and which is configured with a plurality of rules for resolving the unwanted activity independent of instructions provided by a the central system, wherein at least one of the different types of security systems utilizes behavioral monitoring that includes heuristics of the unwanted activity to detect the unwanted activity without utilizing the one or more rules, and the client system is further configured to detect the unwanted activity utilizing the one or more rules;

sending the information to the central system for aggregating the information with additional information sets provided by additional client systems; and

receiving a response sent from the central system to the client system and to the additional client systems, wherein the response is based on the information and is indicative of whether the information was verified as being associated with the unwanted activity, and wherein the response includes a rule for removing code associated with the unwanted activity, and the response includes a rule for detecting future instances of the information, and the response includes a rule for adding the information to a blacklist.

13. An apparatus, comprising:

a client system including a processor, wherein the apparatus is configured for and a memory; and

logic that is executable by the processor for:

receiving one or more rules from a central system;

identifying information associated with unwanted activity, utilizing a plurality of different types of security systems of a the client system, which includes a processor and a memory, and which is configured with a plurality of rules for resolving the unwanted activity independent of instructions provided by a the central system, wherein at least one of the different types of security systems utilizes behavioral monitoring that includes heuristics of the unwanted activity to detect the unwanted activity without utilizing the one or more rules, and the client system is further configured to detect the unwanted activity utilizing the one or more rules;

sending the information to the central system configured for aggregating the information with additional information sets provided by additional client systems; and

receiving a response sent from the central system to the client system and to the additional client systems, wherein the response is based on the information and is indicative of whether the information was verified as being associated with the unwanted activity, and wherein the response includes a rule for removing code associated with the unwanted activity, and the response includes a rule for detecting future instances of the information, and the response includes a rule for adding the information to a blacklist.

14. The apparatus of claim 13 , wherein the processor remains in communication with the memory and a display via a bus.

15. The computer program product of claim 12, wherein the plurality of different types of security systems includes two or more of a firewall, an intrusion prevention system, an anti-spyware system, and a virus scanner.

16. The computer program product of claim 12, wherein the information is correlated prior to sending the information to the central system.

17. The computer program product of claim 12, wherein the information includes a source of the unwanted activity.

18. The computer program product of claim 12, wherein the information includes a decision made in response to the unwanted activity.

19. The computer program product of claim 18, wherein the decision is to block execution of the unwanted activity.

20. The computer program product of claim 12, wherein the information includes an alert.

21. The computer program product of claim 12, wherein the computer program product is embodied on the non-transitory computer readable medium for performing further operations comprising detecting the unwanted activity, utilizing the plurality of different types of security systems.

22. The computer program product of claim 12, wherein the information is sent to a database via the central system.

23. The computer program product of claim 12, wherein the information is sent to the central system for correlation with other information associated with at least one network security system.

24. The apparatus of claim 13, wherein the plurality of different types of security systems includes two or more of a firewall, an intrusion prevention system, an anti-spyware system, and a virus scanner.

25. The apparatus of claim 13, wherein the information is correlated prior to sending the information to the central system.

26. The apparatus of claim 13, wherein the information includes a source of the unwanted activity.

27. The apparatus of claim 13, wherein the information includes a decision made in response to the unwanted activity.

28. The apparatus of claim 27, wherein the decision is to block execution of the unwanted activity.

29. The apparatus of claim 13, wherein the information includes an alert.

30. The apparatus of claim 13, wherein the apparatus is further configured for detecting the unwanted activity, utilizing the plurality of different types of security systems.

31. The apparatus of claim 13, wherein the information is sent to a database via the central system.

32. The apparatus of claim 13, wherein the information is sent to the central system for correlation with other information associated with at least one network security system.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →