IP Library › Granted Patent US 11,487,868
Granted Patent B2
US 11,487,868 · App. 17/069,979 · Granted Nov 1, 2022

System, method, and apparatus for computer security

Inventor: Robert J. Woodworth, Jr. (Charleston, SC)
Assignee: PC MATIC, INC.
G06F21/54G06F21/51G06F21/53G06F21/554G06F21/561H04L63/145H04L63/1416H04L63/101H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,487,868
App. No.
17/069,979
Granted
Nov 1, 2022
Kind
B2
Abstract

A super-shield system for protecting a computer from malicious software uses a whitelist to determine if a program is safe to run. As new malicious software is created, inadvertent attempts at execution of executables including such malicious software is prevented being that the new malicious software are not listed in the whitelist. When attempts are made to run unknown software, the executable is forwarded to a server where further analysis is performed to determine if the executable contains suspect code (e.g., malicious software).

Claims (52)

1. A system for computer security, the system comprising:

two whitelists, a first whitelist of the two whitelists for signed executables and a second whitelist of the two whitelists for unsigned executables;

a server, the server having a server processor and storage containing the two whitelists;

a computer protected by the system for computer security, the computer having a processor and memory, the processor is configured to:

detect an attempt to run an executable,

determine when the executable includes a digital signature stored within the executable, the digital signature having been issued by a certification authority;

when the executable includes the digital signature, search the first whitelist for the executable and when the executable is present on the first whitelist, allow the executable to run;

when the executable is without the digital signature, search the second whitelist for the executable and when the executable is present on the second whitelist, allow the executable to run;

when the executable is not found in a respective whitelist of the two whitelists, forward the executable, a metadata of the executable, or all or a portion of the executable to the server;

the server processor is configured to:

further analyze the executable and when malicious software exists in the executable, send an email to a user of the computer to notify the user of the malicious software and block the executable;

when no malicious software exists in the executable, update the respective whitelist of the two whitelists and send a transaction to the computer;

responsive to the computer receiving the transaction, the processor is configured to allow the executable to run;

when there may be the malicious software in the executable, the server processor is configured to queue the executable for further research and execution of the executable is blocked;

wherein the further research includes the server processor being further configured to install the executable on a clean computer that is isolated, to run the executable on the clean computer, and to analyze a file system and registry of the clean computer to determine if the executable includes the malicious software; and

wherein the email includes a link to training on how to prevent future intrusions of the malicious software into the computer.

2. The system of claim 1 , wherein the email further comprises training regarding malware.

3. The system of claim 2 , wherein the storage associated with the server is cloud storage.

4. The system of claim 1 , wherein the further research includes human analysis of the executable.

5. The system of claim 1 , wherein the further research includes the server processor being further configured to install the executable on the clean computer that is isolated and scanning the executable using a commercially available virus scanning software to determine if the executable includes the malicious software.

6. The system of claim 1 , wherein the email includes a description of the malicious software.

7. A method of protecting a computer, the method comprising:

providing two whitelists, a first whitelist of the two whitelists for signed executables and a second whitelist of the two whitelists for unsigned executables;

providing a server, the server having a server processor and storage containing the two whitelists;

providing a computer for being protected, the computer having a processor and memory;

the processor is configured for detecting an attempt to run an executable and determining when the executable includes a digital signature stored within the executable, the digital signature having been issued by a certification authority;

when the executable includes the digital signature, the processor searching the first whitelist for the executable and when the executable is present on the first whitelist, the processor allowing the executable to run;

when the executable is without the digital signature, the processor searching the second whitelist for the executable and when the executable is present on the second whitelist, the processor allowing the executable to run;

when the executable is not found in a respective whitelist of the two whitelists, the processor forwarding the executable, a metadata of the executable, or all or a portion of the executable to the server;

the server processor is configured for further analyzing the executable and when malicious software exists in the executable, the server processor sending an email to a user of the computer to notify the user of the malicious software and the computer blocking the executable;

when no malicious software exists in the executable, the server processor updating the respective whitelist of the two whitelists and sending a transaction to the computer;

responsive to the computer receiving the transaction, the processor allowing the executable to run; and

when there may be the malicious software in the executable, the server processor queuing the executable for further research and blocking execution of the executable;

wherein the further research includes the server processor further installing the executable on a clean computer that is isolated, running the executable on the clean computer, and analyzing a file system and registry of the clean computer, determining if the executable includes the malicious software; and

wherein the email includes a link to training on how to prevent future intrusions of the malicious software into the computer.

8. The method of claim 7 , wherein the further research comprises scanning the executable using commercially available virus scanning software to determine if the executable includes the malicious software.

9. A computer program product comprising:

a non-transitory storage medium of a computer having computer readable instructions stored therewith and two whitelists, a first whitelist of the two whitelists for signed executables and a second whitelist of the two whitelists for unsigned executables, the computer readable instructions being executable by a processor of a computer and comprising:

computer readable instructions running on the processor cause the processor to detect an attempt to run an executable,

the computer readable instructions running on the processor cause the processor to determine when the executable includes a digital signature stored within the executable, the digital signature having been issued by a certification authority;

when the executable includes the digital signature, the computer readable instructions running on the processor search the first whitelist for the executable and when the executable is present on the first whitelist, allow the executable to run;

when the executable is without the digital signature, the computer readable instructions running on the processor search the second whitelist for the executable and when the executable is present on the second whitelist, allow the executable to run;

when the executable is not found in a respective whitelist of the two whitelists, the computer readable instructions running on the processor forwards the executable, a metadata of the executable, or all or a portion of the executable to a server computer;

a second non-transitory storage medium of the server computer having computer readable instructions stored therewith, the computer readable instructions being executable by a server processor of the server computer and comprising:

computer readable instructions running on the server processor analyze the executable and when malicious software exists in the executable, send an email to a user of the computer to notify the user of the malicious software and block the executable;

when no malicious software exists in the executable, the computer readable instructions running on the server processor update the respective whitelist of the two whitelists and send a transaction to the computer;

responsive to the computer receiving the transaction, the computer readable instructions running on the processor allow the executable to run; and

when there may be the malicious software in the executable, the computer readable instructions running on the server processor queue the executable for further research and execution of the executable is blocked;

wherein the further research includes the computer readable instructions running on the server processor further install the executable on a clean computer that is isolated, then run the executable on the clean computer, and analyze a file system and registry of the clean computer to determine if the executable includes the malicious software; and

wherein the email includes a link to training on how to prevent future intrusions of the malicious software into the computer.

10. The computer program product of claim 9 , wherein the further research is performed by a human being.

11. The computer program product of claim 9 , wherein the further research includes the computer readable instructions running on the server processor cause the server processor to install the executable on a clean computer that is isolated from a wide area network and to scan the executable with a commercially available malicious software scan system to determine when the executable includes malicious software and when the executable include the malicious software, the computer readable instructions running on the server processor cause the server processor to send the email to the user of the computer, the email including a description of the malicious software.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2020
From: WOODWORTH, ROBERT J., JR.
To: PC MATIC, INC.
Reel/Frame 054048/0304 →
Continuity (2)
Continuation In Part 15666212 · Aug 1, 2017
Related Publication 20210026951A1 · Jan 28, 2021