IP Library Granted Patent US 11,080,407
Granted Patent B2
US 11,080,407 · App. 16/670,227 · Granted Aug 3, 2021

Methods and systems for analyzing data after initial analyses by known good and known bad security components

Inventor: Kevin Patrick Mahaffey (San Francisco, CA)
Assignee: LOOKOUT, INC.
G06F21/577G06F21/554H04L63/0227H04L63/123H04L63/1425H04L63/1433H04L63/166H04W12/02H04W12/12H04W12/00505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,080,407
App. No.
16/670,227
Granted
Aug 3, 2021
Kind
B2
Abstract

Methods and systems are provided for conditionally allowing a mobile communications device to process received data. Initially, the data is analyzed by a known good component without the component determining that the data is safe, and the data is analyzed by a known bad component without the component determining that the data is malicious. Subsequently, the data is analyzed by a decision component on the mobile communications device. When the decision component determines the data to be safe, the decision component allows the mobile communications device to process the data. When the decision component determined the data to be malicious, the decision component prevents the mobile communications device from processing the data.

Claims (69)

1. A method comprising:

receiving, by a decision component executing on a mobile communications device (MCD), data from a known bad component executing on the MCD, the data including first information regarding a set of requests and second information regarding a set of user responses to the set of requests, after:

the data was analyzed, by a known good component executing on the MCD, in an attempt to determine whether the data is safe, the determination being that the known good component does not consider the data to be safe; and

the data was analyzed, by the known bad component executing on the MCD, in an attempt to determine whether the data is malicious, the determination being that the known bad component does not consider the data to be malicious;

analyzing, by the decision component, the data to determine whether the data is safe or malicious by analyzing the first information and the second information for a temporal component indicative of malicious behavior, the data being determined to be safe when the analysis of the data does not find a temporal component indicative of malicious behavior and the data being determined to be malicious when the analysis of the data finds a temporal component indicative of malicious behavior; and

when the decision component determines that the data is safe, allowing the data to be further processed by the MCD; or

when the decision component determines that the data is malicious, preventing the data from being further processed by the MCD.

2. The method of claim 1 , wherein the analyzing, by the decision component, the data to determine whether the data is safe further includes:

assessing, by the decision component, the data to determine whether the data contains first characteristics that are characteristic of safe data;

assessing, by the decision component, the data to determine whether the data contains second characteristics that are characteristic of malicious data; and

assigning, by the decision component, a degree the data is safe or malicious based on the determined first and second characteristics, the degree representing a location on a scale between the data being safe and the data being malicious.

3. The method of claim 2 , wherein:

the data is determined to be safe when the location on the scale indicates the data is more safe than malicious and when the analysis of the data does not find a temporal component indicative of malicious behavior; and

the data is determined to be malicious when the location on the scale indicates the data is more malicious than safe and when the analysis of the data finds a temporal component indicative of malicious behavior.

4. The method of claim 1 , wherein the temporal component is indicative of one of:

an attempt to frustrate the user;

a denial of service attack; or

a port scan attack.

5. The method of claim 1 , wherein the analyzing the data to determine whether the data is safe includes analyzing the data to determine whether:

the data includes false data, or

a purported origin of the data is not legitimate; and

the data is determined to be safe when the analysis of the data determines the data does not include false data and the purported origin is legitimate and when the analysis of the data does not find a temporal component indicative of malicious behavior; and

the data is determined to be malicious when the analysis of the data determines the data does includes false data or the purported origin is not legitimate and when the analysis of the data finds a temporal component indicative of malicious behavior.

6. A non-transitory, computer-readable storage medium having stored thereon a plurality of instructions, which, when executed by a processor of a mobile communications device (MCD), cause the MCD to:

receive, by a decision component executing on the MCD, data from a known bad component executing on the MCD, the data including first information regarding a set of requests and second information regarding a set of user responses to the set of requests, after:

the data was analyzed, by a known good component executing on the MCD, in an attempt to determine whether the data is safe, the determination being that the known good component does not consider the data to be safe; and

the data was analyzed, by the known bad component executing on the MCD, in an attempt to determine whether the data is malicious, the determination being that the known bad component does not consider the data to be malicious;

analyze, by the decision component, the data to determine whether the data is safe or malicious by analyzing the first information and the second information for a temporal component indicative of malicious behavior, the data being determined to be safe when the analysis of the data does not find a temporal component indicative of malicious behavior and the data being determined to be malicious when the analysis of the data finds a temporal component indicative of malicious behavior; and

allow the data to be further processed when the decision component determines that the data is safe; or

prevent the data from being further processed when the decision component determines that the data is malicious.

7. The computer-readable storage medium of claim 6 , wherein the instructions to analyze, by the decision component, the data to determine whether the data is safe includes further instructions to:

assess, by the decision component, the data to determine whether the data contains first characteristics that are characteristic of safe data;

assess, by the decision component, the data to determine whether the data contains second characteristics that are characteristic of malicious data; and

assign, by the decision component, a degree the data is safe or malicious based on the determined first and second characteristics, the degree representing a location on a scale between the data being safe and the data being malicious.

8. The computer-readable storage medium of claim 7 , wherein:

the data is determined to be safe when the location on the scale indicates the data is more safe than malicious and when the analysis of the data does not find a temporal component indicative of malicious behavior; and

the data is determined to be malicious when the location on the scale indicates the data is more malicious than safe and when the analysis of the data finds a temporal component indicative of malicious behavior.

9. The computer-readable storage medium of claim 6 , wherein the temporal component is indicative of one of:

an attempt to frustrate the user;

a denial of service attack; or

a port scan attack.

10. The computer-readable storage medium of claim 6 , wherein the analyzing the data to determine whether the data is safe includes analyzing the data to determine whether:

the data includes false data, or

a purported origin of the data is not legitimate; and

the data is determined to be safe when the analysis of the data determines the data does not include false data and the purported origin is legitimate and when the analysis of the data does not find a temporal component indicative of malicious behavior; and

the data is determined to be malicious when the analysis of the data determines the data does includes false data or the purported origin is not legitimate and when the analysis of the data finds a temporal component indicative of malicious behavior.

11. A system, comprising a mobile communications device (MCD) with at least one processor and memory and instructions that when executed by the at least one processor cause the MCD to:

receive, by a decision component executing on the MCD, data from a known bad component executing on the MCD, the data including first information regarding a set of requests and second information regarding a set of user responses to the set of requests, after:

the data was analyzed, by a known good component executing on the MCD, in an attempt to determine whether the data is safe, the determination being that the known good component does not consider the data to be safe; and

the data was analyzed, by the known bad component executing on the MCD, in an attempt to determine whether the data is malicious, the determination being that the known bad component does not consider the data to be malicious;

analyze, by the decision component, the data to determine whether the data is safe or malicious by analyzing the first information and the second information for a temporal component indicative of malicious behavior, the data being determined to be safe when the analysis of the data does not find a temporal component indicative of malicious behavior and the data being determined to be malicious when the analysis of the data finds a temporal component indicative of malicious behavior; and

allow the data to be further processed when the decision component determines that the data is safe; or

prevent the data from being further processed when the decision component determines that the data is malicious.

12. The system of claim 11 , wherein the instructions to analyze, by the decision component, the data to determine whether the data is safe includes further instructions to:

assess, by the decision component, the data to determine whether the data contains first characteristics that are characteristic of safe data;

assess, by the decision component, the data to determine whether the data contains second characteristics that are characteristic of malicious data; and

assign, by the decision component, a degree the data is safe or malicious based on the determined first and second characteristics, the degree representing a location on a scale between the data being safe and the data being malicious.

13. The system of claim 12 , wherein:

the data is determined to be safe when the location on the scale indicates the data is more safe than malicious and when the analysis of the data does not find a temporal component indicative of malicious behavior; and

the data is determined to be malicious when the location on the scale indicates the data is more malicious than safe and when the analysis of the data finds a temporal component indicative of malicious behavior.

14. The system of claim 11 , wherein the temporal component is indicative of one from the group of:

an attempt to frustrate the user;

a denial of service attack; and

a port scan attack.

15. The system of claim 11 , wherein the analyzing the data to determine whether the data is safe includes analyzing the data to determine whether:

the data includes false data, or

a purported origin of the data is not legitimate; and

the data is determined to be safe when the analysis of the data determines the data does not include false data and the purported origin is legitimate and when the analysis of the data does not find a temporal component indicative of malicious behavior; and

the data is determined to be malicious when the analysis of the data determines the data does includes false data or the purported origin is not legitimate and when the analysis of the data finds a temporal component indicative of malicious behavior.

Assignments (8)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
SECURITY INTEREST Recorded Nov 18, 2020
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 054475/0906 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2020
From: MAHAFFEY, KEVIN PATRICK
To: LOOKOUT, INC.
Reel/Frame 052074/0498 →
Continuity (43)
Continuation 16443697 · Jun 17, 2019
Continuation 16443682 · Jun 17, 2019
Continuation 16000712 · Jun 5, 2018
Continuation 16000712
Continuation 15687395 · Aug 25, 2017
Continuation 15393089 · Dec 28, 2016
Continuation 14973636 · Dec 17, 2015
Continuation In Part 14473917 · Aug 29, 2014
Continuation 13790402 · Mar 8, 2013
Continuation 13267731 · Oct 6, 2011
Continuation 12255635 · Oct 21, 2008
Continuation In Part 14634115 · Feb 27, 2015
Continuation 14034320 · Sep 23, 2013
Continuation 13742110 · Jan 15, 2013
Continuation 13314032 · Dec 7, 2011
Continuation 12255632 · Oct 21, 2008
Continuation In Part 14455787 · Aug 8, 2014
Continuation 13741988 · Jan 15, 2013
Continuation 13333654 · Dec 21, 2011
Continuation 12255621 · Oct 21, 2008
Continuation In Part 14318450 · Jun 27, 2014
Continuation 13689588 · Nov 29, 2012
Continuation 12868669 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 14688292 · Apr 16, 2015
Continuation 13958434 · Aug 2, 2013
Continuation 12868672 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 13896852 · May 17, 2013
Continuation 12868676 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 14611063 · Jan 30, 2015
Continuation 13033025 · Feb 23, 2011
Continuation In Part 12868669
Continuation In Part 12255621
Continuation In Part 13335779 · Dec 22, 2011
Continuation In Part 12868676
Continuation In Part 12255621
Continuation In Part 14692669 · Apr 21, 2015
Division 13484132 · May 30, 2012
Continuation In Part 12868672 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Related Publication 20200097665A1 · Mar 26, 2020
Cited By (2)
US 12,270,915 US 12,352,869