IP Library Granted Patent US 12,632,574
Granted Patent B1
US 12,632,574 · App. 18/220,174 · Granted May 19, 2026

System, method, and computer program for using malware to defend data

Inventor: Adi Lachman (Tel Mond, IL)
Assignee: AMDOCS DEVELOPMENT LIMITED
G06F21/604G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,574
App. No.
18/220,174
Granted
May 19, 2026
Kind
B1
Abstract

As described herein, a system, method, and computer program are provided for using malware to protect data. A dormant malware embedded in data detects that a preconfigured condition has been satisfied for self-activation. Responsive to detecting that the preconfigured condition has been satisfied, the dormant malware performs self-activation.

Claims (25)

1 . A non-transitory computer-readable media storing computer instructions which when executed by one or more processors of a device cause the device to:

access a malware that is configured to be embedded in data to:

detect a theft of the data when the malware is copied to a storage location that is not a predefined location allowed for the data, and

perform self-activation in response to detecting the theft to make the data unusable;

embed the malware in a file that includes the data;

detect, by the malware embedded in the file, the theft of the data by detecting that the malware has been relocated to the storage location that is not the predefined location allowed for the data;

responsive to detecting the theft of the data, perform self-activation by the malware to cause the malware to make the data unusable at the storage location that is not the predefined location allowed for the data, where the data is made unusable by one of: encrypting the data, deleting the data, or corrupting the data.

2 . The non-transitory computer-readable media of claim 1 , wherein the storage location is a network domain that is not a predefined network domain allowed for the data.

3 . A method, comprising:

at a computer system:

accessing a malware that is configured to be embedded in data to:

detect a theft of the data when the malware is copied to a storage location that is not a predefined location allowed for the data, and

perform self-activation in response to detecting the theft to make the data unusable;

embedding the malware in a file that includes the data;

detecting, by the malware embedded in the file, the theft of the data by detecting that the malware has been relocated to the storage location that is not the predefined location allowed for the data;

responsive to detecting the theft of the data, performing self-activation by the malware to cause the malware to make the data unusable at the storage location that is not the predefined location allowed for the data, where the data is made unusable by one of: encrypting the data, deleting the data, or corrupting the data.

4 . A system, comprising:

a non-transitory memory storing instructions; and

one or more processors in communication with the non-transitory memory that execute the instructions to:

access a malware that is configured to be embedded in data to:

detect a theft of the data when the malware is copied to a storage location that is not a predefined location allowed for the data, and

perform self-activation in response to detecting the theft to make the data unusable;

embed the malware in a file that includes the data;

detect, by the malware embedded in the file, the theft of the data by detecting that the malware has been relocated to the storage location that is not the predefined location allowed for the data;

responsive to detecting the theft of the data, perform self-activation by the malware to cause the malware to make the data unusable at the storage location that is not the predefined location allowed for the data, where the data is made unusable by one of: encrypting the data, deleting the data, or corrupting the data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2023
From: LACHMAN, ADI
To: AMDOCS DEVELOPMENT LIMITED
Reel/Frame 064865/0473 →
References Cited (10)
US 20050015668A1 · Doyle · 2005 [cited by examiner]
US 20100250497A1 · Redlich · 2010 [cited by examiner]
US 20130336483A1 · Buckley · 2013 [cited by examiner]
US 20160183155A1 · Breuer · 2016 [cited by examiner]
US 20210360032A1 · Crabtree · 2021 [cited by examiner]
US 20240089292A1 · Ghosh · 2024 [cited by examiner]
US 20240146530A1 · Cheng · 2024 [cited by examiner]
US 20240320340A1 · Vt · 2024 [cited by examiner]
US 20240338425A1 · Rao · 2024 [cited by examiner]
WO WO2013095596A1 · 2013 [cited by examiner]