IP Library Granted Patent US 10,831,883
Granted Patent B1
US 10,831,883 · App. 15/923,880 · Granted Nov 10, 2020

Preventing application installation using system-level messages

Inventors: Shrikant Pawar (Mumbai, IN); Sharad Subhash Mhaske (Ahmednagar, IN); Arif Mohammed Shaikh (Pune, IN)
Assignee: NortonLifeLock Inc.
G06F21/51G06F21/554G06F21/57G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,831,883
App. No.
15/923,880
Granted
Nov 10, 2020
Kind
B1
Abstract

Methods and systems are provided for preventing the installation of malicious applications using system-level messages. One example method generally includes intercepting a request sent via an operating system of the computing device; determining the request is to access an application in a remote application repository; obtaining information associated with the application from the request; transmitting, over a network, the information to a security server; and receiving, over the network, a security recommendation for the application from the security server.

Claims (71)

1. A method for preventing installation of malicious applications on a computing device using system-level messages, comprising:

intercepting, by a local security manager on the computing device, a request sent using an intent class of programming objects and that is directed to a local repository client on the same computing device, the request generated by selection of a link to an application stored in a remote application repository;

determining the request is to access the application in the remote application repository;

obtaining information associated with the application from the request;

requesting, from a remote security server, a security recommendation for the application based on the obtained information;

receiving, over a network, the security recommendation from the security server;

taking one or more actions to allow or disallow access to the application based at least in part on the received security recommendation;

transferring the link to the local repository client using the intent class of programming objects; and

enabling a user to set the security manager as a default service to open links to applications in application repositories.

2. The method of claim 1 , further comprising:

displaying the security recommendation for the user of the computing device; and

displaying a user interface for the user, wherein the user interface provides options to allow the request or deny the request.

3. The method of claim 1 , further comprising:

evaluating the security recommendation;

generating an access decision based on the security recommendation; and

implementing the access decision.

4. The method of claim 1 , further comprising the local security manager prompting a user to open the link with the local security manager instead of opening the link with the local repository client.

5. The method of claim 3 , wherein implementing the access decision comprises:

allowing the request; and

sending the request to the local repository client.

6. The method of claim 1 , further comprising receiving details of the application, wherein the details of the application include at least one of:

behavior of the application;

battery usage of the application;

data usage of the application; or

advertisements displayed by the application.

7. The method of claim 1 , further comprising displaying a user interface for the user, wherein the user interface provides an option to select the security manager as the default service for all requests to access applications.

8. A computing device comprising:

a processor; and

a memory having instructions stored thereon which, when executed by the processor, perform operations for preventing installation of malicious applications on the computing device using system-level messages, the operations comprising:

intercepting, by a local security manager on the computing device, a request sent using an intent class of programming objects and that is directed to a local repository client on the same computing device, the request generated by selection of a link to an application stored in a remote application repository;

determining the request is to access the application in the remote application repository;

obtaining information associated with the application from the request;

requesting, from a remote security server, a security recommendation for the application based on the obtained information;

receiving, over a network, the security recommendation from the security server;

taking one or more actions to allow or disallow access to the application based at least in part on the received security recommendation;

transferring the link to the local repository client using the intent class of programming objects; and

enabling a user to set the security manager as a default service to open links to applications in application repositories.

9. The computing device of claim 8 , the operations further comprising:

displaying the security recommendation for the user of the computing device; and

displaying a user interface for the user, wherein the user interface provides options to allow the request or deny the request.

10. The computing device of claim 8 , wherein taking the one or more actions comprises:

evaluating the security recommendation;

generating an access decision based on the security recommendation; and

implementing the access decision.

11. The computing device of claim 10 , wherein implementing the access decision comprises allowing the request.

12. The computing device of claim 11 , wherein implementing the access decision comprises sending the request to the local repository client.

13. The computing device of claim 8 , the operations further comprising receiving details of the application, wherein the details of the application include at least one of:

behavior of the application;

battery usage of the application;

data usage of the application; or

advertisements displayed by the application.

14. The computing device of claim 8 , further comprising a display, wherein the operations further comprise displaying a user interface for the user on the display, wherein the user interface provides an option to select the security manager as the default service for all requests to access applications.

15. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processor of a computing device, perform operations for preventing installation of malicious applications on the computing device using system-level messages, the operations comprising:

intercepting, by a local security manager on the computing device, a request sent using an intent class of programming objects and that is directed to a local repository client on the same computing device, the request generated by selection of a link to an application stored in a remote application repository;

determining the request is to access the application in the remote application repository;

obtaining information associated with the application from the request;

requesting, from a remote security server, a security recommendation for the application based on the obtained information;

receiving, over a network, the security recommendation from the security server;

taking one or more actions to allow or disallow access to the application based at least in part on the received security recommendation;

transferring the link to the local repository client using the intent class of programming objects; and

enabling a user to set the security manager as a default service to open links to applications in application repositories.

16. The computer-readable medium of claim 15 , the operations further comprising:

displaying the security recommendation for the user of the computing device; and

displaying a user interface for the user, wherein the user interface provides options to allow the request or deny the request.

17. The computer-readable medium of claim 15 , wherein taking the one or more actions comprises:

evaluating the security recommendation;

generating an access decision based on the security recommendation; and

implementing the access decision.

18. The computer-readable medium of claim 17 , wherein implementing the access decision comprises allowing the request.

19. The computer-readable medium of claim 18 , wherein implementing the access decision comprises sending the request to the local repository client.

20. The computer-readable medium of claim 15 , the operations further comprising displaying a user interface for the user, wherein the user interface provides an option to select the security manager as the default service for all requests to access applications.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 10, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052135/0745 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2018
From: PAWAR, SHRIKANT; MHASKE, SHARAD SUBHASH; SHAIKH, ARIF MOHAMMED
To: SYMANTEC CORPORATION
Reel/Frame 045258/0411 →