IP Library Patent Application 16786692
Patent Application
App. No. 16/786,692

METHODS AND APPARATUS FOR MALWARE THREAT RESEARCH

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/786,692
Abstract

Methods for classifying computer objects as malware and the associated apparatus are disclosed. An exemplary method includes, at a base computer, receiving data about a computer object from each of plural remote computers on which the object or similar objects are stored and or processed and counting the number of times in a given time period objects having one or more common attributes or behaviors that have been seen by the remote computers. The counted number is then compared with the expected number based on past observations, and if the comparison exceeds a predetermined threshold, the objects are flagged as unsafe or as suspicious.

Claims (30)

1 . A computer program product comprising a non-transitory computer-readable medium storing thereon a set of instructions executable by a processor, the set of instructions comprising instructions for:

receiving checksum data about a computer object from each of plural remote computers on which the computer object is located;

storing said checksum data in a database; and

presenting, on a display and in response to receiving a selection of a first group of plural objects having commonality amongst an attribute, information relating to a second group of plural objects including the first group of plural objects and additional objects not in the first group of plural objects, and information relating to one or more checksummed attributes of the objects of the second group of plural objects from the database, the information relating to the second group of plural objects being arranged such that one or more values of the one or more checksummed attributes and one or more symbols are shown, wherein the one or more symbols are assigned to the one or more values based on at least one of a uniqueness and a commonality among the one or more values of the one or more checksummed attributes of the second group of plural objects, wherein information relating to another group of plural objects comprises a number of known objects that are not malware, a number of known malware objects, and a number of unknown objects;

presenting on the display, a first symbol assigned to one or more values based on the uniqueness of the one or more values among the second group of plural objects when one or more values of the one or more checksummed attributes is unique amongst the second group of plural objects; and

presenting on the display, a second symbol, different from the first symbol, when one or more values of the one or more checksummed attributes is common amongst the second group of plural objects.

2 . The computer program product of claim 1 , wherein the information relating to the second group of plural objects is displayed in tabular form with rows of the table corresponding to objects and columns of the table corresponding to attributes of the objects.

3 . The computer program product of claim 1 , wherein at least one of the first and second symbols comprises a symbol having at least one of a shape and a color different than another symbol.

4 . The computer program product of claim 1 , wherein the set of instructions further comprises instructions for:

identifying commonality of one or more attribute values between the second group of plural objects; and

refining a query in accordance with said identified commonality.

5 . The computer program product of claim 1 , wherein the set of instructions further comprises instructions for creating a rule from a user query if it is determined that the user query is deterministic in identifying malware.

6 . The computer program product of claim 5 , wherein the set of instructions further comprises instructions for:

monitoring user groupings of objects along with any and all user actions taken such as classifying the objects of the second group of plural objects as being safe or unsafe; and

automatically applying said groupings and actions in generating new rules for classifying objects as malware.

7 . The computer program product of claim 5 , wherein the set of instructions further comprises instructions for applying the rule to an object at a first computer.

8 . The computer program product of claim 7 , wherein the set of instructions further comprises instructions for:

storing a classification of the object as safe or unsafe according to the rule in the database.

9 . The computer program product of claim 8 , wherein the set of instructions further comprises instructions for:

receiving an indication from a remote computer that an object classified as malware by said rule is believed not to be malware; and

amending or deleting the rule in accordance with said indication.

10 . The computer program product of claim 5 , wherein the set of instructions further comprises instructions for sending the rule to a remote computer such that the remote computer can apply the rule to an object at the remote computer.

11 . The computer program product of claim 10 , wherein the set of instructions further comprises instructions for:

storing a classification of the object as safe or unsafe according to the rule in the database.

12 . The computer program product of claim 11 , wherein the set of instructions further comprises instructions for:

receiving an indication from the remote computer that an object classified as malware by said rule is believed not to be malware; and

amending or deleting the rule in accordance with said indication.

13 . The computer program product of claim 1 , wherein the set of instructions further comprises instructions for receiving actor information pertaining to an actor object performing an act and victim information pertaining to a victim object upon which the act is being performed.

14 . The computer program product of claim 1 , wherein the one or more checksummed attributes correspond to an object pathname and an object filename.

15 . The computer program product of claim 1 , where the set of instructions further comprises instructions for displaying a third symbol, different from the first symbol and the second symbol, when one or more values of the one or more checksummed attributes is common amongst the second group of plural objects.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2020
From: MORRIS, MELVYN; JAROCH, JOSEPH
To: WEBROOT INC.
Reel/Frame 051804/0580 →