Patent · US Active

Prevention and remediation of malware based on selective presentation of files to processes

US12124568B2 · kind B2 · utility

0Cited by
2References
35Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 20, 2021
Grant dateOct 22, 2024
Priority date
Expiry dateSep 3, 2042

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/577
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Malware prevention and remediation is provided by monitoring actions performed by processes and maintaining indications of which processes are trusted; selectively presenting canary files to these processes, which includes presenting the canary files to processes not indicated as being trusted and hiding the canary files from processes indicated as being trusted, and where the monitoring includes monitoring for access of canary files with change privileges; scoring each of the processes based on the actions performed, including any access of canary files with change privileges, which scoring produces a malice score for each process; and automatically terminating any process for which its malice score indicates at least a threshold level of malice in the execution of the process.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.