IP Library Patent Application 15088931
Patent Application
App. No. 15/088,931

Centralized and Automated Recovery

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/088,931
Filed
Apr 1, 2016
Art Unit
2437
USPC
726/23
Abstract

A system for securing electronic devices includes a processor, a storage medium communicatively coupled to the processor, and a secured storage communicatively coupled to the client. The system further includes a client application including computer-executable instructions on the medium. The instructions are readable by the processor. The application is configured to manage a trusted image of software of a client in a secured storage and, upon a signal indicating malware on the client, restore the trusted image to the client independent of an operating system and user processes of the client.

Claims (75)

1 . At least one non-transitory machine readable storage medium, comprising computer-executable instructions carried on the machine readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

manage a trusted image of software of a client in a secured storage communicatively coupled to the client; and

upon a signal indicating malware on the client, restore the trusted image to the client independent of an operating system and user processes of the client.

2 . The medium of claim 1 , further comprising instructions for causing the processor to:

monitor execution of the client to determine whether malware is indicated during the execution of the client; and

based upon results of determining whether malware is indicated during the execution of the client, send a notification to a server concerning the malware.

3 . The medium of claim 1 , further comprising instructions for causing the processor to:

monitor execution of the client to determine whether malware is indicated during the execution of the client; and

based upon results of determining whether malware is indicated during the execution of the client, send a notification to a server concerning the malware;

wherein the signal indicates malware results from the notification is sent to the server.

4 . The medium of claim 1 , further comprising instructions for causing the processor to restrict visibility of the trusted image to user processes and operating system kernels of the client.

5 . The medium of claim 1 , further comprising instructions for causing the processor to receive the signal indicating malware through a communication channel bypassing the operating system and user processes of the client.

6 . The medium of claim 1 , further comprising instructions for causing the processor to restore the trusted image by:

receiving a reboot command with a restore parameter;

storing the restore parameter;

forcing a reboot of the client into a trusted environment; and

based upon the restore parameter, restoring the trusted image.

7 . The medium of claim 1 , further comprising instructions for causing the processor to restore the trusted image by:

receiving a reboot command with a restore parameter;

storing the restore parameter;

forcing a reboot of the client into a trusted environment;

based upon the restore parameter, securely reading the trusted image from the secured storage;

restoring the trusted image to data partitions of the secured storage accessible by the operating system; and

resetting the restore parameter.

8 . A system for securing electronic devices, comprising:

a processor;

at least one non-transitory machine readable storage medium communicatively coupled to the processor;

a client application comprising computer-executable instructions on the medium, the instructions readable by the processor, the application configured to:

manage a trusted image of software of a client in a secured storage communicatively coupled to the client; and

upon a signal indicating malware on the client, restore the trusted image to the client independent of an operating system and user processes of the client.

9 . The system of claim 8 , wherein the client application is further configured to:

monitor execution of the client to determine whether malware is indicated during the execution of the client; and

based upon results of determining whether malware is indicated during the execution of the client, send a notification to a server concerning the malware.

10 . The system of claim 8 , wherein the client application is further configured to:

monitor execution of the client to determine whether malware is indicated during the execution of the client; and

based upon results of determining whether malware is indicated during the execution of the client, send a notification to a server concerning the malware;

wherein the signal indicates malware results from the notification sent to the server.

11 . The system of claim 8 , wherein the client application is further configured to restrict visibility of the trusted image to user processes and operating system kernels of the client.

12 . The system of claim 8 , wherein the client application is further configured to receive the signal indicating malware through a communication channel bypassing the operating system and user processes of the client.

13 . The system of claim 8 , wherein the client application is further configured to restore the trusted image by:

receiving a reboot command with a restore parameter;

storing the restore parameter;

forcing a reboot of the client into a trusted environment; and

based upon the restore parameter, restoring the trusted image.

14 . The system of claim 8 , wherein the client application is further configured to restore the trusted image by:

receiving a reboot command with a restore parameter;

storing the restore parameter;

forcing a reboot of the client into a trusted environment;

based upon the restore parameter, securely reading the trusted image from the secured storage;

restoring the trusted image to data partitions of the secured storage accessible by the operating system; and

resetting the restore parameter.

15 . A method of computer security, comprising:

managing a trusted image of software of a client in a secured storage communicatively coupled to the client; and

upon a signal indicating malware on the client, restoring the trusted image to the client independent of an operating system and user processes of the client.

16 . The method of claim 15 , further comprising:

monitoring execution of the client to determine whether malware is indicated during the execution of the client; and

based upon results of determining whether malware is indicated during the execution of the client, sending a notification to a server concerning the malware.

17 . The method of claim 15 , further comprising:

monitoring execution of the client to determine whether malware is indicated during the execution of the client; and

based upon results of determining whether malware is indicated during the execution of the client, sending a notification to a server concerning the malware;

wherein the signal indicates malware results from the notification sent to the server.

18 . The method of claim 15 , further comprising restricting visibility of the trusted image to user processes and operating system kernels of the client.

19 . The method of claim 15 , further comprising receiving the signal indicating malware through a communication channel bypassing the operating system and user processes of the client.

20 . The method of claim 15 , further comprising restoring the trusted image by:

receiving a reboot command with a restore parameter;

storing the restore parameter;

forcing a reboot of the client into a trusted environment; and

based upon the restore parameter, restoring the trusted image.

21 . The method of claim 15 , further comprising restoring the trusted image by:

receiving a reboot command with a restore parameter;

storing the restore parameter;

forcing a reboot of the client into a trusted environment;

based upon the restore parameter, securely reading the trusted image from the secured storage;

restoring the trusted image to data partitions of the secured storage accessible by the operating system; and

resetting the restore parameter.

Assignments (8)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2016
From: MEHTA, KUNAL; RUBAKHA, DMITRI; WOODWARD, CARL D.; GROBMAN, STEVEN L.; PEARSON, ADRIAN R.; SIDDIQI, FARAZ A.
To: MCAFEE, INC.
Reel/Frame 040835/0023 →