System, method, and computer program for using malware to defend data
As described herein, a system, method, and computer program are provided for using malware to protect data. A dormant malware embedded in data detects that a preconfigured condition has been satisfied for self-activation. Responsive to detecting that the preconfigured condition has been satisfied, the dormant malware performs self-activation.
1 . A non-transitory computer-readable media storing computer instructions which when executed by one or more processors of a device cause the device to:
access a malware that is configured to be embedded in data to:
detect a theft of the data when the malware is copied to a storage location that is not a predefined location allowed for the data, and
perform self-activation in response to detecting the theft to make the data unusable;
embed the malware in a file that includes the data;
detect, by the malware embedded in the file, the theft of the data by detecting that the malware has been relocated to the storage location that is not the predefined location allowed for the data;
responsive to detecting the theft of the data, perform self-activation by the malware to cause the malware to make the data unusable at the storage location that is not the predefined location allowed for the data, where the data is made unusable by one of: encrypting the data, deleting the data, or corrupting the data.
2 . The non-transitory computer-readable media of claim 1 , wherein the storage location is a network domain that is not a predefined network domain allowed for the data.
3 . A method, comprising:
at a computer system:
accessing a malware that is configured to be embedded in data to:
detect a theft of the data when the malware is copied to a storage location that is not a predefined location allowed for the data, and
perform self-activation in response to detecting the theft to make the data unusable;
embedding the malware in a file that includes the data;
detecting, by the malware embedded in the file, the theft of the data by detecting that the malware has been relocated to the storage location that is not the predefined location allowed for the data;
responsive to detecting the theft of the data, performing self-activation by the malware to cause the malware to make the data unusable at the storage location that is not the predefined location allowed for the data, where the data is made unusable by one of: encrypting the data, deleting the data, or corrupting the data.
4 . A system, comprising:
a non-transitory memory storing instructions; and
one or more processors in communication with the non-transitory memory that execute the instructions to:
access a malware that is configured to be embedded in data to:
detect a theft of the data when the malware is copied to a storage location that is not a predefined location allowed for the data, and
perform self-activation in response to detecting the theft to make the data unusable;
embed the malware in a file that includes the data;
detect, by the malware embedded in the file, the theft of the data by detecting that the malware has been relocated to the storage location that is not the predefined location allowed for the data;
responsive to detecting the theft of the data, perform self-activation by the malware to cause the malware to make the data unusable at the storage location that is not the predefined location allowed for the data, where the data is made unusable by one of: encrypting the data, deleting the data, or corrupting the data.