Patent · US Active

Detection and restoration of files patched by malware

US8499349B1 · kind B1 · utility

42Cited by
6References
42Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 22, 2009
Grant dateJul 30, 2013
Priority date
Expiry dateOct 15, 2030

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/568
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A monitor agent monitors every write request for files that are capable of being patched (executable files). Once a write request is requested for one of these files, the agent creates a copy of the file and also saves the original file version number. If the program that is requesting the write access has not been digitally signed then that program is flagged as being suspicious. The write request is allowed to proceed and the file is modified by the requesting program. After the modification, if the file version number is not higher then the write is flagged as being suspicious. If both the requesting program has been flagged as suspicious and the file version number has been flagged as suspicious, then the requesting program is labeled as being malware. The monitor agent restores the modified file using the original copy. If either the requesting program is flagged as suspicious or the file version number is flagged as suspicious, then the requesting program is labeled as being suspicious.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.