IP Library Granted Patent US 8,474,039
Granted Patent B2
US 8,474,039 · App. 12/695,011 · Granted Jun 25, 2013

System and method for proactive detection and repair of malware memory infection via a remote memory reputation system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,474,039
App. No.
12/695,011
Granted
Jun 25, 2013
Kind
B2
Abstract

A method for detecting malware memory infections includes the steps of scanning a memory on an electronic device, determining a suspicious entry present in the memory, accessing information about the suspicious entry in a reputation system, and evaluating whether the suspicious entry indicates a malware memory infection. The memory includes memory known to be modified by malware. The suspicious entry is not recognized as a safe entry. The reputation system is configured to store information on suspicious entries. The evaluation is based upon historical data regarding the suspicious entry.

Claims (92)

1. A method for detecting malware memory infections, comprising the steps of:

scanning a memory on an electronic device, the memory comprising memory vulnerable to memory modifications caused by malware;

determining a suspicious entry present in the memory, the suspicious entry not recognized as a safe entry, the suspicious entry comprising a modification to an existing entry in memory;

accessing information about the suspicious entry from a reputation system, the reputation system configured to store information on suspicious entries; and

evaluating whether the suspicious entry indicates a malware memory infection, wherein the evaluation is based upon historical data regarding the suspicious entry, comprising:

comparing the distribution pattern of the suspicious entry against a known distribution pattern, the known distribution pattern indicating a safe memory modification or indicating a malware memory infection;

comparing a determined quantity of devices for which the suspicious entry has been reported against an upper threshold;

comparing the time range of the determined quantity of devices against a lower threshold; and

determining that the suspicious entry does not indicate a malware memory infection if the determined quantity of devices exceeds the upper threshold and the time range of the determined quantity of devices is less than the lower threshold.

2. The method of claim 1 , further comprising the step of adding a suspicious entry data to a whitelist, wherein the evaluation is that the suspicious entry does not indicate a malware memory infection.

3. The method of claim 1 , further comprising the step of adding information concerning suspicious entry to the reputation system, wherein the evaluation is that it is unknown whether the suspicious entry indicates a malware memory infection.

4. The method of claim 1 , further comprising the step of adding suspicious entry to a blacklist, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

5. The method of claim 1 , further comprising the step of cleaning the electronic device of a malware memory infection, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

6. The method of claim 5 , wherein cleaning the electronic device of a malware memory infection comprises repairing the memory of the electronic device.

7. The method of claim 1 , further comprising the step of generating a repair driver for the electronic device, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

8. The method of claim 1 , wherein evaluating whether the suspicious entry indicates a malware memory infection further comprises:

determining a range of networks from which the suspicious entry has been reported; and

if the suspicious entry has been reported from a single network, determining that the suspicious entry does not comprise a malware infection.

9. The method of claim 1 , further comprising the step of sending information concerning unrecognized values associated with the suspicious entry to the reputation system.

10. The method of claim 9 , further comprising the step of sending information identifying the electronic device to the reputation system.

11. A method for detecting malware memory infections, comprising the steps of:

scanning a memory on an electronic device, the memory comprising memory vulnerable to memory modifications caused by malware;

determining a suspicious entry present in the memory, the suspicious entry not recognized as a safe entry, the suspicious entry comprising a modification to an existing entry in memory;

accessing information about the suspicious entry from a reputation system, the reputation system configured to store information on suspicious entries; and

evaluating whether the suspicious entry indicates a malware memory infection, wherein the evaluation is based upon historical data regarding the suspicious entry, comprising:

comparing the distribution pattern of the suspicious entry against a known distribution pattern, the known distribution pattern indicating a safe memory modification or indicating a malware memory infection;

comparing a determined quantity of devices for which the suspicious entry has been reported against a lower threshold;

comparing the time range of the determined quantity of devices against an upper threshold; and

determining that the suspicious entry indicates a malware memory infection if the determined quantity of devices is less than the lower threshold and the time range of the determined quantity of devices exceeds the upper threshold.

12. An article of manufacture, comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the non-transitory computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

scan a memory on an electronic device, the memory comprising memory vulnerable to memory modifications caused by malware;

determine a suspicious entry present in the memory, the suspicious entry not recognized as a safe entry, the suspicious entry comprising a modification to an existing entry in memory;

access information about the suspicious entry from a reputation system, the reputation system configured to store information on suspicious entries; and

evaluate whether the suspicious entry indicates a malware memory infection, wherein the evaluation is based upon historical data regarding the suspicious entry, comprising:

comparing the distribution pattern of the suspicious entry against a known distribution pattern, the known distribution pattern indicating a safe memory modification, or indicating a malware memory infection;

comparing a determined quantity of devices for which the suspicious entry has been reported against an upper threshold;

comparing the time range of the determined quantity of devices against a lower threshold; and

determining that the suspicious entry does not indicate a malware memory infection if the determined quantity of devices exceeds the upper threshold and the time range of the determined quantity of devices is less than the lower threshold.

13. The article of claim 12 , wherein the processor is further caused to add the suspicious entry's information to a whitelist, wherein the evaluation is that the suspicious entry does not indicate a malware memory infection.

14. The article of claim 12 , wherein the processor is further caused to add information concerning the suspicious entry to the reputation system, wherein the evaluation is that it is unknown whether the suspicious entry indicates a malware memory infection.

15. The article of claim 12 , wherein the processor is further caused to add the suspicious entry's information to a blacklist, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

16. The article of claim 12 , wherein the processor is further caused to clean the electronic device of a malware memory infection, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

17. The article of claim 12 , wherein causing the processor to clean electronic device of a malware memory infection comprises causing the processor to repair the memory of the electronic device.

18. The article of claim 12 , wherein the processor is further caused to generate a repair driver for the electronic device, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

19. The article of claim 12 , wherein causing the processor to evaluate whether the suspicious entry indicates a malware memory infection further comprises causing the processor to:

determine a range of networks from which the suspicious entry has been reported; and if the suspicious entry has been reported from a single network, determine that the suspicious entry does not comprise a malware infection.

20. The article of claim 12 , wherein the processor is further caused to send information concerning unrecognized values associated with the suspicious entry to the reputation system.

21. The article of claim 20 , wherein the processor is further caused to send information identifying the electronic device to the reputation system.

22. An article of manufacture, comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the non-transitory computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

scan a memory on an electronic device, the memory comprising memory vulnerable to memory modifications caused by malware;

determine a suspicious entry present in the memory, the suspicious entry not recognized as a safe entry, the suspicious entry comprising a modification to an existing entry in memory;

access information about the suspicious entry from a reputation system, the reputation system configured to store information on suspicious entries; and

evaluate whether the suspicious entry indicates a malware memory infection, wherein the evaluation is based upon historical data regarding the suspicious entry, comprising:

comparing the distribution pattern of the suspicious entry against a known distribution pattern, the known distribution pattern indicating a safe memory modification, or indicating a malware memory infection;

comparing a determined quantity of devices for which the suspicious entry has been reported against a lower threshold;

comparing the time range of the determined quantity of devices against an upper threshold; and

determining that the suspicious entry indicates a malware memory infection if the determined quantity of devices is less than the lower threshold and the time range of the determined quantity of devices exceeds the upper threshold.

23. A system detecting malware memory infections, comprising:

a monitor, the monitor configured to:

scan a memory on an electronic device, the memory comprising memory vulnerable to memory modifications caused by malware

determine a suspicious entry present in the memory, the suspicious entry not recognized as a safe entry, the suspicious entry comprising a modification to an existing entry in memory; and

send information about the suspicious entry to a reputation system configured to access information about the suspicious entry in a reputation database configured to store information on suspicious entries; and

determine, based on information from the reputation system, whether the suspicious entry indicates a malware memory infection based upon historical data regarding the suspicious entry, comprising:

comparing the distribution pattern of the suspicious entry against a known distribution pattern, the known distribution pattern indicating a safe memory modification, or indicating a malware memory infection;

comparing a determined quantity of devices for which the suspicious entry has been reported against an upper threshold;

comparing the time range of the determined quantity of devices against a lower threshold; and

determining that the suspicious entry does not indicate a malware memory infection if the determined quantity of devices exceeds the upper threshold and the time range of the determined quantity of devices is less than the lower threshold.

24. The system of claim 23 , wherein the reputation system is further configured to add the suspicious entry's information to a whitelist, wherein the evaluation is that the suspicious entry does not indicate a malware memory infection.

25. The system of claim 23 , wherein the reputation server is further configured to add information concerning the suspicious entry to the reputation database, wherein the evaluation is that it is unknown whether the suspicious entry indicates a malware memory infection.

26. The system of claim 23 , wherein reputation system is further configured to add the suspicious entry's information to a blacklist, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

27. The system of claim 23 , wherein the monitor is further configured to clean the electronic device of a malware memory infection, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

28. The system of claim 27 , wherein configuring the monitor to clean electronic device of a malware memory infection comprises configuring the monitor to repair the memory of the electronic device.

29. The system of claim 23 , wherein the reputation system is further configured to generate a repair driver for the electronic device, wherein the evaluation is that the suspicious entry indicates a malware memory infection.

30. The system of claim 23 , wherein configuring the reputation system to evaluate whether the suspicious entry indicates a malware memory infection further comprises configuring the reputation system to:

determine a range of networks from which the suspicious entry has been reported; and

if the suspicious entry has been reported from a single network, determine that the suspicious entry does not comprise a malware infection.

31. The system of claim 23 , wherein the monitor is further configured to send information concerning unrecognized values associated with the suspicious entry to the reputation system.

32. The system of claim 31 , wherein the monitor is further configured to send information identifying the electronic device to the reputation system.

33. A system detecting malware memory infections, comprising:

a monitor, the monitor configured to:

scan a memory on an electronic device, the memory comprising memory vulnerable to memory modifications caused by malware

determine a suspicious entry present in the memory, the suspicious entry not recognized as a safe entry, the suspicious entry comprising a modification to an existing entry in memory; and

send information about the suspicious entry to a reputation system configured to access information about the suspicious entry in a reputation database configured to store information on suspicious entries; and

determine, based on information from the reputation system, whether the suspicious entry indicates a malware memory infection based upon historical data regarding the suspicious entry, comprising:

comparing the distribution pattern of the suspicious entry against a known distribution pattern, the known distribution pattern indicating a safe memory modification, or indicating a malware memory infection;

comparing a determined quantity of devices for which the suspicious entry has been reported against a lower threshold;

comparing the time range of the determined quantity of devices against an upper threshold; and

determining that the suspicious entry indicates a malware memory infection if the determined quantity of devices is less than the lower threshold and the time range of the determined quantity of devices exceeds the upper threshold.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2010
From: SALLAM, AHMED SAID
To: MCAFEE, INC.
Reel/Frame 023860/0152 →