IP Library › Granted Patent US 11,449,605
Granted Patent B2
US 11,449,605 · App. 16/846,477 · Granted Sep 20, 2022

Systems and methods for detecting a prior compromise of a security status of a computer system

Inventor: Jon Whitmore (Washington, DC)
Assignee: Capital One Services, LLC
G06F21/554G06F16/148G06F21/552G06F21/629G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,449,605
App. No.
16/846,477
Granted
Sep 20, 2022
Kind
B2
Abstract

A computer-implemented method for detecting a security status of a computer system may include: in response to satisfaction of a predetermined trigger condition associated with an electronic application installed on a memory of the computer system, performing a security check process on the computer system; in response to the security check process determining that a security status of the computer system is currently compromised, performing a first security action; and in response to the security check process determining that the security status is formerly compromised, performing a second security action.

Claims (39)

1. A computer-implemented method for detecting a security status of a computer system, comprising:

in response to satisfaction of a predetermined trigger condition associated with an electronic application installed on a memory of the computer system, performing a security check process on the computer system, wherein the security check process includes:

in response to determining that an indicator application is not present on the memory, determining whether an indicator directory is accessible in the memory by performing a search process on the memory to identify at least two indicator directories in the memory, wherein:

the at least two indicator directories includes “etc/apt” and “/private/var/lib/apt/”; and

the search process identifies that at least the indicator directories “/etc/apt” and “/private/var/lib/apt/” are accessible on the memory; and

in response to determining that at least the indicator directories “/etc/apt” and “/private/var/lib/apt/” are accessible on the memory, determining that the security status of the computer system is formerly compromised; and

in response to the security check process determining that the security status is formerly compromised, performing a security action.

2. The computer-implemented method of claim 1 , wherein the security action includes:

enabling access to a first portion of a functionality of the electronic application, and

preventing access to a second portion of the functionality of the electronic application.

3. The computer-implemented method of claim 2 , wherein the security action further includes transmitting a report message to a server system associated with the electronic application that includes information associated with the security status of the computer system.

4. The computer-implemented method of claim 1 , wherein the predetermined trigger condition includes one or more of:

receiving a launch application instruction associated with the electronic application;

determining that a timer has expired; or

receiving an application security check instruction from a server system associated with the electronic application.

5. A system for detecting a security status of a computer system, the system comprising:

a memory storing instructions and an electronic application; and

a processor operatively connected to the memory and configured to execute the instructions to perform acts, the acts including:

in response to satisfaction of a predetermined trigger condition associated with the electronic application installed on the memory of the computer system, performing a security check process on the computer system, wherein the security check process includes:

in response to determining that an indicator application is not present on the memory, determining whether an indicator directory is accessible in the memory by performing a search process on the memory to identify at least two indicator directories in the memory, wherein:

the at least two indicator directories includes “/etc/apt” and “/private/var/lib/apt/”; and

the search process identifies that at least the indicator directories “/etc/apt” and “/private/var/lib/apt/” are accessible on the memory; and

in response to determining that at least the indicator directories “/etc/apt” and “/private/var/lib/apt/” are accessible on the memory, determining that the security status of the computer system is formerly compromised; and

in response to the security check process determining that the security status is formerly compromised, performing a security action.

6. The system of claim 5 , wherein the security action includes:

enabling access to a first portion of a functionality of the electronic application, and

preventing access to a second portion of the functionality of the electronic application.

7. The system of claim 6 , wherein the security action further includes transmitting a report message to a server system associated with the electronic application that includes information associated with the security status of the computer system.

8. The system of claim 5 , wherein the predetermined trigger condition includes one or more of:

receiving a launch application instruction associated with the electronic application;

determining that a timer has expired; or

receiving an application security check instruction from a server system associated with the electronic application.

9. A non-transitory computer-readable medium comprising instructions that are executable by at least one processor of a computer system to perform operations for detecting a security status of the computer system, the operations including:

in response to satisfaction of a predetermined trigger condition associated with an electronic application installed on a memory of the computer system, performing a security check process on the computer system, the security check process including:

in response to determining that an indicator application is not present on the memory, determining whether an indicator directory is present on the memory of the computer system by performing a search process on the memory to identify at least two indicator directories in the memory, wherein:

the at least two indicator directories include “etc/apt” and “/private/var/lib/apt/”; and

the search process identifies that at least the indicator directories “/etc/apt” and “/private/var/lib/apt/” are accessible on the memory; and

in response to determining that at least the indicator directories “/etc/apt” and “/private/var/lib/apt/” are accessible on the memory, determining that the security status of the computer system is formerly compromised; and

in response to the security check process determining that the security status is formerly compromised, performing a security action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2020
From: WHITMORE, JON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 052476/0397 →
Continuity (1)
Related Publication 20210319095A1 · Oct 14, 2021