IP Library Granted Patent US 10,972,497
Granted Patent B1
US 10,972,497 · App. 16/138,957 · Granted Apr 6, 2021

Systems and methods for recovering an infected endpoint

Inventors: Shrikant Pawar (Mumbai, IN); Sharad Mhaske (Maharashtra, IN)
Assignee: NortonLifeLock Inc.
H04L63/1441G06F8/61G06F21/56G06F21/57G10L15/22H04L63/20H04L67/26H04W12/10H04W12/12G10L2015/223
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,972,497
App. No.
16/138,957
Granted
Apr 6, 2021
Kind
B1
Abstract

The disclosed computer-implemented method for recovering an infected endpoint may include receiving an acoustic signal having an embedded command for executing a security application at the infected endpoint, decoding the acoustic signal to obtain the embedded command, and executing the embedded command to start a security application at the infected endpoint, where the security application is operable to mitigate the infected endpoint. Various other methods, systems and computer-readable media are also disclosed.

Claims (37)

1. A computer-implemented method for recovering an infected endpoint, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

receiving an acoustic signal at an infected endpoint experiencing a denial of access to a user interface that persists until a user fulfills a ransom demand, the acoustic signal having encoded therein an embedded command for executing a security application, wherein the acoustic signal comprises ultrasound corresponding to an ultrasonic data over audio solution;

decoding the acoustic signal to obtain the embedded command; and

executing the embedded command to start a security application at the infected endpoint, the security application operable to mitigate the infected endpoint.

2. The computer implemented method of claim 1 , wherein the acoustic signal further comprises at least one of additional embedded commands, metadata, and an authorization token.

3. The computer implemented method of claim 1 , further comprising executing a virtual assistant for activating the security application.

4. The computer implemented method of claim 1 , wherein the acoustic signal having the embedded command encoded therein is received from a mobile device transducer.

5. The computer implemented method of claim 4 , further comprising:

providing credentials to a security application provider, wherein the credentials are provided via a mobile device having the mobile device transducer; and

receiving the acoustic signal having the embedded command encoded therein in response to providing the credentials to the security application provider.

6. The computer implemented method of claim 1 , further comprising receiving the security application by way of a remote application distribution platform pushing the security application to the infected endpoint.

7. The computer implemented method of claim 6 , further comprising installing the security application at the infected endpoint.

8. A system for recovering an infected endpoint, the system comprising:

at least one physical processor;

physical memory comprising computer-executable instructions that, when executed by the physical processor, cause the physical processor to:

receive an acoustic signal at an infected endpoint experiencing a denial of access to a user interface that persists until a user fulfills a ransom demand, the acoustic signal having encoded therein an embedded command for executing a security application, wherein the acoustic signal comprises ultrasound corresponding to an ultrasonic data over audio solution;

decode the acoustic signal to obtain the embedded command; and

execute the embedded command to start a security application at the infected endpoint, the security application operable to mitigate the infected endpoint.

9. The system of claim 8 , wherein the acoustic signal further comprises at least one of additional embedded commands, metadata, and an authorization token.

10. The system of claim 8 , wherein the computer-executable instructions further cause the physical processor to execute a virtual assistant for activating the security application.

11. The system of claim 8 , wherein the acoustic signal having the embedded command encoded therein is received from a transducer communicating with a remote acoustic signal source.

12. The system of claim 8 , wherein the computer-executable instructions further cause the physical processor to:

receive credentials from the user; and

provide the acoustic signal to the user in response to receiving the credentials.

13. The system of claim 8 , wherein the computer-executable instructions further cause the physical processor to receive the security application by way of a remote application distribution platform pushing the security application.

14. The system of claim 13 , wherein the computer-executable instructions further cause the physical processor to install the security application at the infected endpoint.

15. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

receive an acoustic signal at an infected endpoint experiencing a denial of access to a user interface that persists until a user fulfills a ransom demand, the acoustic signal having encoded therein an embedded command for executing a security application, wherein the acoustic signal comprises ultrasound corresponding to an ultrasonic data over audio solution;

decode the acoustic signal to obtain the embedded command; and

execute the embedded command to start a security application at the infected endpoint, the security application operable to mitigate the infected endpoint.

16. The non-transitory computer-readable medium of claim 15 , wherein the acoustic signal further comprises at least one of additional embedded commands, metadata, and an authorization token.

17. The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions further cause the computing device to execute a virtual assistant for activating the security application.

18. The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions further cause the computing device to receive the security application by way of a remote application distribution platform pushing the security application.

19. The non-transitory computer-readable medium of claim 18 , wherein the computer-executable instructions further cause the computing device to install the security application at the infected endpoint.

20. The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions further cause the computing device to:

receive credentials from the user; and

provide the acoustic signal to the user in response to receiving the credentials.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2018
From: PAWAR, SHRIKANT; MHASKE, SHARAD
To: SYMANTEC CORPORATION
Reel/Frame 046945/0648 →