IP Library Granted Patent US 7,664,924
Granted Patent B2
US 7,664,924 · App. 11/858,752 · Granted Feb 16, 2010

System and method to secure a computer system by selective control of write access to a data storage medium

Assignee: Drive Sentry, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,664,924
App. No.
11/858,752
Granted
Feb 16, 2010
Kind
B2
Abstract

A system and method to securing a computer system from software viruses and other malicious code by intercepting attempts by the malicious code to write data to a storage medium. The invention intercepts the write access requests made by programs and verifies that the program is authorized to write before letting the write proceed. Authorization is determined by using the identity of the program as a query element into a database where permission values are stored. Depending on the presence or value of the permission value, write access is permitted or denied. Permission values can be set by the user, downloaded from a central server, or loaded into the central server by a group of users in order to collectively determine a permission value. The interception code can operate in kernel mode.

Claims (20)

1. In a computer comprising a storage medium and an application running on said computer, a method of controlling write access to said storage medium by said application comprising:

detecting an attempt by the application to write data to said storage medium;

in response to said write attempt, attempting to retrieve a permission value from a database comprised of data elements encoding at least one permission value associated with one or more applications;

in the case that no permission value for the running application is found in the database, transmitting to a central server operatively connected to the computer and to at least one additional computer, a query comprised of an indicia of identity associated with said running application;

receiving from said central server, data that represents the collective response of the user of the at least one additional computer to requests by the same application running on said at least one additional computer to access the storage medium that comprises said at least one additional computer.

2. The method of claim 1 further comprising displaying on the user interface of said computer graphical forms representative of said collective response data.

3. The method of claim 1 where the data that represents the collective response data includes a percentage of other computer users who have approved the application writing to the storage medium associated with their respective at least one additional computer.

4. The method of claim 1 where the data that represents the collective response data includes a number which is the number of other users that have approved the application writing to the storage medium associated their respective at least one additional computer.

5. The method of claim 1 where the data that represents the collective response data includes at least one statement characterizing the reason that said at least one additional computer user selected a particular permission value.

6. The method of claim 5 where the reason is a spyware.

7. The method of claim 5 where the reason is a virus.

8. The method of claim 5 where the reason is a trojan.

9. In a computer comprising a storage medium and an application running on said computer, a method of controlling write access to said storage medium by said application comprising:

detecting an attempt by the application to write data to said storage medium;

in response to said write attempt, attempting to retrieve a permission value from a database comprised of data elements encoding at least one permission value associated with one or more applications;

in the case that no permission value for the running application is found, transmitting to a central server operatively connected to the computer a query comprised of an indicia of identity associated with said running application;

receiving from said central server information collective response data of at least one other computer user's to the request by the same application running on said other computer user's computers to access the storage medium that comprises said at least one other computer user's computers;

receiving from said central server information transmitted to said central server, said information comprising other user's critique of said at least one other computer user's response.

10. A system comprised of a data storage medium, a central processing unit and a main memory, where said central processing unit executes any of the methods of claims 1 - 8 or 9 .

11. A data storage medium containing digital data that, when loaded into a computer and executed as a program, causes the computer to execute any of the methods of claims 1 - 8 or 9 .

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2025
From: DRIVE SENTRY LIMITED
To: VERIBASE LLC
Reel/Frame 072575/0996 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: EIGHTH STREET SOLUTIONS LLC
To: DRIVE SENTRY LIMITED
Reel/Frame 062673/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2021
From: DRIVE SENTRY LIMITED
To: EIGHTH STREET SOLUTIONS LLC
Reel/Frame 054830/0670 →
CHANGE OF ASSIGNEE'S ADDRESS Recorded Feb 1, 2017
From: DRIVE SENTRY LIMITED
To: DRIVE SENTRY LIMITED
Reel/Frame 041581/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2015
From: DRIVE SENTRY, INC.
To: DRIVE SENTRY LIMITED
Reel/Frame 035557/0723 →
SECURITY AGREEMENT Recorded Jun 30, 2010
From: DRIVE SENTRY, INC.
To: STEVENS, RICHARD
Reel/Frame 024611/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2008
From: SAFA, JOHN
To: DRIVE SENTRY, INC.
Reel/Frame 020452/0922 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2007
From: HUTCHINSON, IAN G.; HILDEBRANDT, PETER W.; DUNN, MICHAEL H.
To: POLYVISION CORPORATION
Reel/Frame 018779/0851 →
Continuity (3)
Continuation In Part 1129291000 · Dec 1, 2005
Provisional Application 6082637700 · Sep 20, 2006
Related Publication 20080114957A1 · May 15, 2008