IP Library Granted Patent US 8,719,928
Granted Patent B2
US 8,719,928 · App. 13/108,644 · Granted May 6, 2014

Method and system for detecting malware using a remote server

Inventor: Paul A. Gassoway (Norwood, MA)
Assignee: CA, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,719,928
App. No.
13/108,644
Granted
May 6, 2014
Kind
B2
Abstract

The present disclosure is directed to a method and system for detecting malware using a remote server. In accordance with a particular embodiment of the present disclosure a hash value for a file is generated. The hash value is transmitted to a remote server. A notification is received from the remote server indicating whether the file comprises malware. At least one operation on the file is prevented if the notification indicates the file comprises malware.

Claims (45)

1. A method for detecting malware, comprising:

determining, by a malware scanner on a client, that one or more bytes within a header of a non-executable file stored on the client have changed and caused the non-executable file to change into an executable file;

in response to determining that the non-executable file has changed into the executable file:

generating a hash value for a file;

transmitting the hash value to a remote server;

receiving a notification from the remote server indicating whether the file comprises malware; and

preventing at least one operation on the file if the notification indicates the file comprises the malware.

2. The method of claim 1 , further comprising detecting, at the remote server, whether the file comprises the malware by comparing the hash value to one or more permitted files.

3. The method of claim 1 , wherein preventing at least one operation on the file if the notification indicates the file comprises the malware comprises encrypting the file.

4. The method of claim 1 , wherein preventing at least one operation on the file if the notification indicates the file comprises the malware comprises deleting the file.

5. The method of claim 1 , further comprising generating an advisory message for a user that indicates the file comprises the malware in response to receiving the notification from the remote server indicating that the file comprises the malware.

6. The method of claim 1 , further comprising allowing at least one operation on the file if the file does not comprise the malware.

7. A system for detecting malware, comprising:

a storage device; and

a processor, the processor operable to execute a program of instructions operable to:

determine that one or more bytes within a header of a non-executable file stored on the client have changed and caused the non-executable file to change into an executable file;

in response to determining that the non-executable file has changed into the executable file:

generate a hash value for a file;

transmit the hash value to a remote server;

receive a notification from the remote server indicating whether the file comprises malware; and

prevent at least one operation on the file if the notification indicates the file comprises malware.

8. The system of claim 7 , wherein the program of instructions is further operable to detect whether the file comprises the malware by comparing the hash value to one or more permitted files.

9. The system of claim 7 , wherein the program of instructions is further operable to encrypt the file.

10. The system of claim 7 , wherein the program of instructions is further operable to delete the file.

11. The system of claim 7 , wherein the program of instructions is further operable to generate an advisory message for a user that indicates the file comprises the malware, the advisory message generated in response to receiving the notification from the remote server indicating that the file comprises the malware.

12. The system of claim 7 , wherein the program of instructions is further operable to allow at least one operation on the file if the file does not comprise the malware.

13. Logic encoded in non-transitory media, the logic being operable, when executed on a processor, to:

determine that one or more bytes within a header of a non-executable file stored on the client have changed and caused the non-executable file to change into an executable file;

in response to determining that the non-executable file has changed into the executable file:

generate a hash value for a file;

transmit the hash value to a remote server;

receive a notification from the remote server indicating whether the file comprises malware; and

prevent at least one operation on the file if the notification indicates the file comprises malware.

14. The logic of claim 13 , wherein the logic is further operable to detect whether the file comprises the malware by comparing the hash value to one or more permitted files.

15. The logic of claim 13 , wherein the logic is further operable to encrypt the file.

16. The logic of claim 13 , wherein the logic is further operable to delete the file.

17. The logic of claim 13 , wherein the logic is further operable to generate an advisory message for a user that indicates the file comprises the malware in response to receiving the notification from the remote server indicating that the file comprises the malware.

18. The logic of claim 13 , wherein:

the notification from the remote server indicates that the file comprises malware; and

the logic is further operable when executed to restore the executable file back to the non-executable file.

19. The method of claim 13 , wherein the notification from the remote server indicates that the file comprises malware, and the method further comprises:

restoring the executable file back to the non-executable file.

20. The system of claim 7 , wherein:

the notification from the remote server indicates that the file comprises malware; and

the processor is further operable to restore the executable file back to the non-executable file.

Assignments (2)
MERGER Recorded Dec 3, 2012
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 029390/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2011
From: GASSOWAY, PAUL A.
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 026286/0474 →
Continuity (2)
Continuation 11735163 · Apr 13, 2007
Related Publication 20110219238A1 · Sep 8, 2011