IP Library Granted Patent US 8,839,421
Granted Patent B2
US 8,839,421 · App. 12/806,737 · Granted Sep 16, 2014

System and method for controlling applications to mitigate the effects of malicious software

Inventors: Oliver Whitehouse (Belmont, GB); Michael Grant Kirkup (Waterloo, CA); Christopher Lyle Bender (Waterloo, CA); Michael Kenneth Brown (Fergus, CA)
Assignee: BlackBerry Limited
G06F21/53G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,839,421
App. No.
12/806,737
Granted
Sep 16, 2014
Kind
B2
Abstract

Methods and systems for mitigating the effects of a malicious software application are disclosed. A dedicated module on the computing device receives from a malicious software detector a message indicating whether the application is malicious or has a malicious component. The dedicated module obtains a set of permissions to be granted to the application, and instructs software on the computing device that controls the permissions of the application to grant the set of permissions.

Claims (41)

1. A method for mitigating the effects of a malicious software application on a handheld wireless communication device, the method being performed by a dedicated module located on the handheld wireless communication device, the method comprising:

the dedicated module executing the application using a program for executing unverified applications;

the dedicated module monitoring a behavior of the application;

the dedicated module recording behavior information pertaining to the monitored behavior of the application;

the dedicated module forwarding the behavior information to a malicious software detector;

the dedicated module receiving from the malicious software detector a message indicating that the application is malicious or has a malicious component; and

in response to receiving the message from the malicious software detector, the dedicated module instructing software on the handheld wireless communication device that controls permissions of the application to inhibit at least one but not all permissions granted to the application.

2. The method of claim 1 , wherein at least one permission is received from the malicious software detector.

3. The method of claim 1 , wherein the malicious software detector is remote from said handheld wireless communication device and the dedicated module communicates with the malicious software detector through a wireless network.

4. The method of claim 1 , wherein the behavior information is compared with data stored on memory on the handheld wireless communication device to determine if the application is malicious or has a malicious component.

5. The method of claim 1 , wherein the program for executing unverified applications provides a controlled set of resources for the application to use while executing.

6. The method of claim 1 , wherein the behavior information comprises at least one of:

a resource consumed by the application;

data accessed by the application; and

another application accessed by the application.

7. A system for mitigating the effects of a malicious software application on a handheld wireless communication device, the system comprising:

a dedicated module on the handheld wireless communication device comprising computer executable instructions for executing the application using a program for executing unverified applications, monitoring a behavior of the application, recording behavior information pertaining to the monitored behavior of the application, forwarding the behavior information to a malicious software detector, and receiving from the malicious software detector a message indicating that the application is malicious or has a malicious component; and

an applications control module on the handheld wireless communication device comprising computer executable instructions for controlling the permissions of the application, the dedicated module configured to instruct the applications control module to inhibit at least one but not all permissions granted to the application in response to receiving the message from the malicious software detector.

8. The system of claim 7 , wherein at least one permission is received from said malicious software detector.

9. The system of claim 7 , wherein the malicious software detector is located on a server remote from said handheld wireless communication device, and the dedicated module and the malicious software detector are configured to communicate through a wireless network.

10. The system of claim 7 , further comprising memory on the handheld wireless communication device for storing data to be compared to the behavior information, the dedicated module being configured to compare the behavior information with said data to determine if the application is malicious or has a malicious component.

11. The system of claim 7 , wherein the program for executing unverified applications provides a controlled set of resources for the application to use while executing.

12. The system of claim 7 , wherein the behavior information comprises at least one of:

a resource consumed by the application;

data accessed by the application; and

another application accessed by the application.

13. A non-transitory computer readable medium having stored thereon computer readable instructions for mitigating the effects of a malicious software application on a handheld wireless communication device, the computer readable instructions comprising instructions for:

executing the application using a program for executing unverified applications;

monitoring a behavior of the application;

recording behavior information pertaining to the monitored behavior of the application;

forwarding the behavior information to a malicious software detector;

receiving from the malicious software detector a message indicating that the application is malicious or has a malicious component; and

in response to receiving the message from the malicious software detector, instructing software on the handheld wireless communication device that controls permissions of the application to inhibit at least one but not all permissions granted to the application.

14. The computer readable medium of claim 13 , wherein at least one permission is received from said malicious software detector.

15. The computer readable medium of claim 13 , wherein the malicious software detector is remote from said handheld wireless communication device and further comprising instructions for communicating with the malicious software detector through a wireless network.

16. The computer readable medium of claim 13 , further comprising instructions for comparing the behavior information with data stored on memory on the handheld wireless communication device to determine if the application is malicious or has a malicious component.

17. The computer readable medium of claim 13 , wherein the program for executing unverified applications provides a controlled set of resources for the application to use while executing.

18. The computer readable medium of claim 13 , wherein the behavior information comprises at least one of:

a resource consumed by the application;

data accessed by the application; and

another application accessed by the application.

Assignments (6)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Jun 11, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 033134/0228 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2013
From: RESEARCH IN MOTION UK LIMITED
To: RESEARCH IN MOTION LIMITED
Reel/Frame 029922/0595 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2013
From: BENDER, CHRISTOPHER LYLE; BROWN, MICHAEL KENNETH; KIRKUP, MICHAEL GRANT
To: RESEARCH IN MOTION LIMITED
Reel/Frame 029894/0900 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2013
From: WHITEHOUSE, OLIVER
To: RESEARCH IN MOTION UK LIMITED
Reel/Frame 029894/0981 →
Continuity (2)
Provisional Application 61238345 · Aug 31, 2009
Related Publication 20110214184A1 · Sep 1, 2011