IP Library Granted Patent US 10,303,876
Granted Patent B2
US 10,303,876 · App. 15/391,387 · Granted May 28, 2019

Persistence probing to detect malware

Inventors: Craig Schmugar (Hillsboro, OR); John Teddy (Beaverton, OR); Cedric Cochin (Portland, OR)
Assignee: McAfee, LLC
G06F21/566G06F21/568G06F21/575G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,303,876
App. No.
15/391,387
Granted
May 28, 2019
Kind
B2
Abstract

A technique for detecting malware looks at startup hooks that may be created by malware to assist in ensuring that the malware is started upon a reboot of a programmable device. After enumerating startup hooks in the system, startup hooks associated with untrusted executables are deleted. If the startup hook is restored, that is an indication that the untrusted executable may be malware. An indication may then be passed to an anti-malware software to analyze the executable further.

Claims (62)

1. A storage device or storage disk comprising instructions that, when executed, cause a machine to at least:

identify a startup hook associated with a target executable based on a reputation of the target executable;

remove the startup hook;

determine whether the startup hook is restored within a period after the removal, a length of the period associated with the reputation of the target executable; and

when the startup hook is determined to be restored within the period, update the reputation of the target executable to a negative reputation.

2. The machine readable medium of claim 1 , wherein the instructions, when executed, identify the startup hook by:

enumerating a plurality of startup hooks at startup of an operating system of the machine.

3. The machine readable medium of claim 1 , wherein the instructions, when executed, identify the startup hook by:

evaluating the reputation of the startup hook or target executable; and

ignoring the startup hook in response to the reputation.

4. The machine readable medium of claim 1 , wherein the instructions, when executed, identify the startup hook by:

determining whether the startup hook has been evaluated previously; and

ignoring the startup hook in response to the determination.

5. The machine readable medium of claim 1 , wherein the instructions cause the machine to:

backup the startup hook prior to removal of the startup hook; and

restore the startup hook in response to a determination that the startup hook has not been restored within the period.

6. The machine readable medium of claim 5 , wherein the instructions cause the machine to:

when the startup hook is determined to not be restored, update the reputation of the target executable to a positive reputation.

7. The machine readable medium of claim 1 , wherein the instructions are to execute upon a reboot of the machine.

8. A method of detecting malware in a programmable device, the method comprising:

identifying, by the programmable device, a startup hook associated with a target executable based on a reputation of the target executable;

removing, by the programmable device, the startup hook; and

updating, by the programmable device, a reputation of the target executable to a negative reputation in response to a determination that the startup hook is restored within a period after the removal, a length of the period associated with the reputation of the target executable.

9. The method of claim 8 , wherein the identifying of the startup hook includes:

enumerating a plurality of startup hooks.

10. The method of claim 8 , wherein the identifying of the startup hook further includes:

evaluating a reputation of the startup hook or target executable; and

ignoring the startup hook based on to the evaluation of the reputation.

11. The method of claim 8 , wherein the identifying of the startup hook further includes:

determining whether the startup hook has previously been evaluated; and

ignoring the startup hook when the startup hook has previously been evaluated.

12. The method of claim 8 , further including:

backing up the startup hook prior to removal of the startup hook; and

restoring the startup hook in response to a determination that the startup hook has not been restored.

13. The method of claim 12 , further including:

updating the reputation of the target executable to a positive reputation.

14. The method of claim 8 , further including rebooting the programmable device.

15. A programmable device to detect malware, the device comprising:

a processor;

a memory, in communication with the processor, the memory including instructions that, when executed, cause the processor to at least:

identify, based on a reputation of a target executable, a startup hook associated with the target executable;

remove the startup hook;

determine whether the startup hook is restored within a period after the removal, a length of the period associated with the reputation of the target executable; and

when the startup hook is restored within the period, update the reputation of the target executable to a negative reputation.

16. The programmable device of claim 15 , wherein the processor is to identify the startup hook by:

enumerating a plurality of startup hooks at startup of an operating system of the processor.

17. The programmable device of claim 15 , wherein the processor is to identify the startup hook by:

evaluating the reputation of the startup hook or target executable; and

ignoring the startup hook in response to the reputation.

18. The programmable device of claim 15 , wherein the processor is to:

determine whether the startup hook has been evaluated previously; and

ignore the startup hook when the startup hook has been previously evaluated.

19. The programmable device of claim 15 , wherein the processor is to:

backup the startup hook prior to removal of the startup hook; and

restore the startup hook in response to the determination that the startup hook has not been restored.

20. The programmable device of claim 19 , wherein the processor is to:

update the reputation of the target executable to a positive reputation.

21. The programmable device of claim 15 , wherein the instructions are to execute upon a reboot of the processor.

22. The programmable device of claim 15 , wherein the processor is to:

replace the startup hook associated with the target executable with a replacement startup item;

execute, using the replacement startup item, the target executable; and

monitor the execution of the target executable to update the reputation of the target executable.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2017
From: SCHMUGAR, CRAIG; TEDDY, JOHN; COCHIN, CEDRIC
To: MCAFEE, INC.
Reel/Frame 041372/0220 →
Continuity (1)
Related Publication 20180181753A1 · Jun 28, 2018