IP Library Granted Patent US 12,652,295
Granted Patent B2
US 12,652,295 · App. 18/536,871 · Granted Jun 9, 2026

Arrangement and a method of threat detection in a computing device or a computer network

Inventors: Jarkko Turkulainen (Helsinki, FI); Pavel Turbin (Helsinki, FI)
Assignee: WITHSECURE CORPORATION
H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,295
App. No.
18/536,871
Filed
Dec 12, 2023
Granted
Jun 9, 2026
Kind
B2
Art Unit
2435
USPC
726/23
Abstract

A method of threat detection in a computing device or network includes determining that a financial related service is accessed with the computing device, determining during an active session or connection to the financial related service that an application of the computing device is requesting network access and checking the reputation of the application. Based thereon, blocking network access if the application or the process is not a trusted application or a trusted process, scanning memory of the computing device used by the application or the process for malicious or unusual content if the application is a trusted application or the process is a trusted process, and if scanning indicates no malicious or unusual content, granting network access to the application or the process, and if scanning of the application or the process indicates malicious or unusual content, blocking network access for the application or the process.

Claims (42)

1 . A method of threat detection in a computing device or a computer network, wherein the method comprises:

determining that a financial related service is accessed with the computing device,

determining during an active session or connection to the financial related service that an application or process of the computing device is requesting use of network access of the computing device,

checking the reputation of the application or process and based on the checked reputation of the application or the process:

blocking network access of the application or the process if the application or the process is not a trusted application or a trusted process,

scanning memory of the computing device used by the application or the process for malicious or unusual content if the application is a trusted application or the process is a trusted process, and

if scanning indicates no malicious or unusual content, granting network access to the application or the process, and

if scanning of the application or the process indicates malicious or unusual content, blocking network access for the application or the process.

2 . The method according to claim 1 , wherein in the method network access for untrusted applications or processes and/or for scanned applications or processes indicating malicious or unusual content is restricted or denied at least as long as the financial related service is accessed.

3 . The method according to claim 1 , wherein only applications, processes and/or services belonging to operating system and/or infrastructure related processes are identified as trusted applications or processes when the computing device is connected to the financial related service.

4 . The method according to claim 1 , wherein scanning of the application or the process comprises detecting remote thread injections by the application or the process.

5 . The method according to claim 1 , wherein determination of thread injections by the application or the process is at least in part based on by recognizing that the application or process has different code execution memory protection and/or is not started or running from the loaded module of the application or the process.

6 . The method according to claim 1 , wherein scanning of the application or the process comprises comparison of in-memory and on disk executable sections.

7 . The method according to claim 1 , wherein scanning of the application or process comprises checking that resources loaded by the application or the process are known and/or trusted.

8 . The method according to claim 1 , wherein checking that a financial related service is accessed with the computing device is at least partly based on a list of financial related services and/or network addresses of the financial related services.

9 . The method according to claim 1 , wherein the finance related service is a banking website or a banking service.

10 . The method according to claim 1 , wherein the unusual content comprises memory usage by the application, which is not according to predefined rules.

11 . An arrangement for threat detection in a computer or computer network, wherein the arrangement comprises at least one computing device, wherein the computing device is configured:

to determine that a financial related service is accessed with the computing device,

to determine during an active session or connection to the financial related service that an application or process of the computing device is requesting use of network access of the computing device,

to check the reputation of the application or the process and based on the checked reputation of the application or the process:

to block network access of the application or the process if the application or process is not a trusted application or a trusted process,

to scan memory of the computing device used by the application for malicious or unusual content if the application is a trusted application or the process is a trusted process, and

if scanning indicates no malicious or unusual content, to grant network access to the application, and

if scanning of the application indicates malicious or unusual content to block network access for the application.

12 . The arrangement according to claim 11 ,

wherein network access for untrusted applications or processes and/or for scanned applications or processes indicating malicious or unusual content is restricted or denied at least as long as the financial related service is accessed.

13 . A non-transitory computer-readable medium on which is stored a computer program comprising instructions which, when executed by a computer, cause the computer to carry out a method of threat detection in a computing device or a computer network, wherein the method comprises:

determining that a financial related service is accessed with the computing device,

determining during an active session or connection to the financial related service that an application or process of the computing device is requesting use of network access of the computing device,

checking the reputation of the application or process and based on the checked reputation of the application or the process:

blocking network access of the application or the process if the application or the process is not a trusted application or a trusted process,

scanning memory of the computing device used by the application or the process for malicious or unusual content if the application is a trusted application or the process is a trusted process, and

if scanning indicates no malicious or unusual content, granting network access to the application or the process, and

if scanning of the application or the process indicates malicious or unusual content, blocking network access for the application or the process.

14 . The method according to claim 2 , wherein only applications, processes and/or services belonging to operating system and/or infrastructure related processes are identified as trusted applications or processes when the computing device is connected to the financial related service.

15 . The method according to claim 14 , wherein scanning of the application or the process comprises detecting remote thread injections by the application or the process.

16 . The method according to claim 15 , wherein determination of thread injections by the application or the process is at least in part based on by recognizing that the application or process has different code execution memory protection and/or is not started or running from the loaded module of the application or the process.

17 . The method according to claim 16 , wherein scanning of the application or the process comprises comparison of in-memory and on disk executable sections.

18 . The method according to claim 17 , wherein scanning of the application or process comprises checking that resources loaded by the application or the process are known and/or trusted.

19 . The method according to claim 18 , wherein checking that a financial related service is accessed with the computing device is at least partly based on a list of financial related services and/or network addresses of the financial related services.

20 . The method according to claim 19 , wherein the finance related service is a banking website or a banking service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2026
From: TURKULAINEN, JARKKO; TURBIN, PAVEL
To: WITHSECURE CORPORATION
Reel/Frame 074538/0830 →
Priority Claims (1)
GB 2300944 · Jan 23, 2023 · national
Continuity (1)
Related Publication 20240250962A1 · Jul 25, 2024
References Cited (15)
US 8590045B2 · Niemela · 2013 [cited by examiner]
US 8752180B2 · Barile · 2014 [cited by examiner]
US 9065826B2 · Colvin · 2015 [cited by examiner]
US 9183383B1 · Yablokov · 2015 [cited by examiner]
US 9495538B2 · Schneider · 2016 [cited by examiner]
US 10334083B2 · Katmor · 2019 [cited by examiner]
US 20090199297A1 · Jarrett et al. · 2009 [cited by applicant]
US 20170329966A1 · Koganti · 2017 [cited by examiner]
CA 3053185A1 · 2018 [cited by examiner]
CA 2968201C · 2021 [cited by examiner]
EP 3029593A1 · 2016 [cited by applicant]
EP 2486507B1 · 2016 [cited by applicant]
WO 2010138641A1 · 2010 [cited by applicant]
WO WO2020142412A1 · 2020 [cited by examiner]
Search Report for GB2300944.2 dated Jul. 21, 2023, 1 page. [cited by applicant]