Prevention and remediation of malware based on selective presentation of files to processes
US12124568B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 20, 2021 |
| Grant date | Oct 22, 2024 |
| Priority date | — |
| Expiry date | Sep 3, 2042 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/577
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
Malware prevention and remediation is provided by monitoring actions performed by processes and maintaining indications of which processes are trusted; selectively presenting canary files to these processes, which includes presenting the canary files to processes not indicated as being trusted and hiding the canary files from processes indicated as being trusted, and where the monitoring includes monitoring for access of canary files with change privileges; scoring each of the processes based on the actions performed, including any access of canary files with change privileges, which scoring produces a malice score for each process; and automatically terminating any process for which its malice score indicates at least a threshold level of malice in the execution of the process.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.