IP Library Granted Patent US 10,079,845
Granted Patent B2
US 10,079,845 · App. 15/087,110 · Granted Sep 18, 2018

IoT and PoS anti-malware strategy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,079,845
App. No.
15/087,110
Granted
Sep 18, 2018
Kind
B2
Abstract

Providing security to a device includes detecting, in a first device, a first function call, determining whether the first function call is forbidden for the first device, and in response to determining that the particular function is forbidden for the first device, preventing the function call from executing.

Claims (49)

1. A non-transitory machine readable medium comprising instructions that, when executed, cause a device to at least:

detect, in the device, a combination of function calls;

determine whether the combination of function calls is a forbidden combination of function calls for the device based on a limited intended functionality of the device, wherein the limited intended functionality of the device represents a subset of overall capabilities of an operating system of the device, the forbidden combination of function calls including a first function call and a second function call, wherein either or both the first function call or the second function call is allowed in isolation from the other; and

in response to determining that the combination of function calls is forbidden for the device, prevent the combination of function calls from executing.

2. The non-transitory machine readable medium of claim 1 , wherein the instructions, when executed, cause the machine to at least determine whether the combination of function calls is forbidden by determining that the combination of function calls is associated with a function that is forbidden for the device based on the function being outside the limited intended functionality of the device.

3. The non-transitory machine readable medium of claim 1 , wherein the instructions, when executed, cause the machine to at least determine whether the combination of function calls is forbidden by determining that the combination of function calls is associated with a forbidden parameter for the device, the forbidden parameter to cause the combination of function calls to represent functionality outside the limited intended functionality of the device.

4. The non-transitory machine readable medium of claim 1 , wherein the instructions, when executed, cause the machine to at least:

generate a notification regarding a determination that the combination of function calls is forbidden; and

transmit the notification to a user device.

5. The non-transitory machine readable medium of claim 1 , wherein the instructions, when executed, cause the machine to at least:

generate a notification regarding a determination that the combination of function calls is forbidden; and

transmit the notification to a remote server, the notification including data regarding the function call for analysis.

6. The non-transitory machine readable medium of claim 1 , wherein the combination of function calls includes one or more API calls.

7. The non-transitory machine readable medium of claim 1 , wherein the device is a point of sale device.

8. A device for providing device security, comprising:

one or more processors; and

a memory including instructions which, when executed, cause the one or more processors to at least:

detect, in the device, a combination of function calls;

determine whether the combination of function calls is a forbidden combination of function calls for the device based on a limited intended functionality of the device, wherein the limited intended functionality of the device represents a subset of overall capabilities of an operating system of the device, the forbidden combination of function calls including a first function call and a second function call, wherein either or both the first function call or second function call is allowed in isolation from the other; and

in response to determining that the combination of function calls is forbidden for the device, prevent the combination of function calls from executing.

9. The device of claim 8 , wherein the instructions, when executed, cause the one or more processors to determine whether the combination of function calls is forbidden by determining that the combination of function calls is associated with a function that is forbidden for the device based on the function being outside the limited intended functionality of the device.

10. The device of claim 8 , wherein the instructions, when executed, cause the one or more processors to determine whether the combination of function calls is forbidden by determining that the combination of function calls is associated with a forbidden parameter for the device, wherein the combination of function calls is rendered forbidden based on the forbidden parameter causing the function call to represent functionality outside the limited intended functionality of the device.

11. The device of any of claim 8 , wherein the instructions, when executed, cause the one or more processors to:

generate a notification regarding a determination that the combination of function calls is forbidden; and

transmit the notification to a user device.

12. The device of any of claim 8 , wherein the instructions, when executed, cause the one or more processors to:

generate a notification regarding a determination that the combination of function calls is forbidden; and

transmit the notification to a remote server, the notification including data regarding the combination of function calls for analysis.

13. The device of claim 8 , wherein the instructions, when executed, cause the one or more processors to:

access, from a remote device, an updated list of forbidden function calls; and

monitor the device to detect a further forbidden function call using the updated list of forbidden functions.

14. The device of claim 13 , wherein the updated list of forbidden functions is specific to an intended functionality of the device.

15. A method to provide security in a device, the method comprising:

detecting, in the device, a combination of function calls;

determining whether the combination of function calls is a forbidden combination of function calls for the device based on a limited intended functionality of the device, wherein the limited intended functionality of the device represents a subset of overall capabilities of an operating system of the device, the forbidden combination of function calls including a first function call and a second function call, wherein either or both the first function call or second function call is allowed in isolation from the other; and

in response to determining that the combination of function calls is forbidden for the device, preventing the combination of function calls from executing.

16. The method of claim 15 , wherein determining whether the function call is forbidden for the device further includes determining that the combination of function calls is associated with a function that is forbidden for the device based on the function being outside the limited intended functionality of the device.

17. The method of claim 15 , wherein determining whether the combination of function calls is forbidden for the device further includes determining that the combination of function calls is associated with a forbidden parameter for the device based on the forbidden parameter causing the function call to represent functionality outside the limited intended functionality of the device.

18. The method of claim 15 , wherein determining whether the function is forbidden for the device includes:

generating a notification regarding a determination that the combination of function calls is forbidden; and

transmitting the notification to a user device.

19. The method of claim 15 , further including:

generating a notification regarding a determination that the combination of function calls is forbidden; and

transmitting the notification to a remote server, the notification including data regarding the function call for analysis.

20. The method of claim 15 , wherein the function call includes one or more API calls.

21. The method of claim 15 , further including:

receiving, from a remote device, an updated list of forbidden function calls; and

monitoring the device to detect a further forbidden function call using the updated list of forbidden functions.

22. The method of claim 21 , wherein the updated list of forbidden function calls is specific to an intended functionality of the device.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →