U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Icon_funbox Bizarre Patents

Patent No. 6612440

Banana Protective Device

A banana protective device for storing and transporting a banana carefully.

Newsletter  PatentStorm News

Make the Most of Our Site

See this month's Top Inventors and Most Cited Patents.

Stay on top of the latest innovations by subscribing to an RSS feed.

Registered users: Manage your profile.

 

Class 726/24 - Virus detection


Subclass of Class 726 - Information security
Definition: Subject matter wherein the intruder is a virus.
No. of patents: 568
Last issue date: 02/14/2012


1                      
NumberTitleIssue Date
8117659Malicious code infection cause-and-effect analysis
A malware analysis system for automating cause and effect analysis of malware infections is provided. The malware analysis system monitors and records computer system activities. Upon being informed of a suspected malware infection, the malware analysis system creat...
02/14/2012
8112806Detecting network interface card level malware
Computers are monitored for malware communicating directly with the NIC. The infection of computers with NIC level malware is detected. Operating system level network packet transmission statistics are monitored, as are transmission counters maintained by the NIC. T...
02/07/2012
8104089Tracking memory mapping to prevent packers from evading the scanning of dynamically created code
To detect possible malicious code that is unpacked at runtime before it is executed, antivirus software requires that any dynamically created code be scanned before it can be executed by a host computer system. This requirement may be enforced by requiring memory pa...
01/24/2012
8104090Method and system for detection of previously unknown malware components
A system, method, and computer program product for identifying malware components on a computer, including detecting an attempt to create or modify an executable file or an attempt to write to a system registry; logging the attempt as an auditable event; performing ...
01/24/2012
8104088Trusted operating environment for malware detection
Techniques and apparatuses for scanning a computing device for malware are described. In one implementation, a trusted operating environment, which includes a trusted operating system and a trusted antivirus tool, is embodied on a removable data storage medium. A co...
01/24/2012
8099785Method and system for treatment of cure-resistant computer malware
A system, method and computer program product for treating a malware in a computer having multiple copies of the same malicious code activated, where the multiple copies monitor each other's existence, including (a) identifying a presence of the malicious code on th...
01/17/2012
8091135Computer system and virus-scan method
A computer system uses a virus-scan method capable of full-scanning the logical volume of a SUTOSEN PC with high frequency while limiting the number of virus-scan devices. The computer system includes a primary volume storing data from a personal computer, a snapsho...
01/03/2012
8091134System and method for autonomic peer-to-peer virus inoculation
A system, method, and program product is provided that communicates virus information between a computer that detects a virus in a file (the detecting computer system) and the computer that sent the infected file (the infected computer system). When the infected com...
01/03/2012
8091136Packet transfer device, packet transfer method, and program
A packet transfer apparatus is provided with: storage means configured to store a predetermined search pattern and an address identifying a predetermined apparatus; determination means configured to determine whether predetermined data in a packet received from a ne...
01/03/2012
8087086Method for mitigating false positive generation in antivirus software
A method for mitigating false-positives as detected by antivirus software comprising accessing an operating system file that has been identified as malware; creating a signature for the operating system file; comparing the created signature to a signature database; ...
12/27/2011
8087084Security for scanning objects
Scanning is disclosed. A system is monitored to detect object events, and it is determined whether an object event requires an update to a scan list. If an update is required, the scan list is authenticated. The scan list is updated with information regarding object...
12/27/2011
8087085Wireless intrusion prevention system and method
A wireless intrusion prevention system and method to prevent, detect, and stop malware attacks is presented. The wireless intrusion prevention system monitors network communications for events characteristic of a malware attack, correlates a plurality of events to d...
12/27/2011
8087083Systems and methods for detecting a network sniffer
A device (110) records traffic in a communications network. The device (110) monitors traffic received by the device (110) and determines whether the received traffic is unexpected. The device (110) records the traffic when the traffic is...
12/27/2011
8082587Detecting content in files
A method for detecting undesirable content in a computer directory having a digital file includes performing a size check on the digital file, the size check returning a first passing condition or a first failing condition, if the size check returns the first passin...
12/20/2011
8079086Malicious mobile code runtime monitoring system and methods
Protection systems and methods provide for protecting one or more personal computers (“PCs”) and/or other intermittently or persistently network accessible devices or processes from undesirable or otherwise malicious operations of Java TN applets, ActiveX™ con...
12/13/2011
8079085Reducing false positives during behavior monitoring
A program installed on a computer system registers and is placed on an installed program list or an uninstall software list. A check of the uninstall software list (USL) is added as a secondary verification mechanism to a behavior monitoring engine. A signature-base...
12/13/2011
8079084Virus co-processor instructions and methods for using such
Various embodiments of the present invention provide elements that may be utilized for improved virus processing. As one example, a computer readable medium is disclosed that includes a virus signature compiled for execution on a virus co-processor. The virus signat...
12/13/2011
8074281Malware detection with taint tracking
Malware may be identified based on attempts to use tainted data in certain ways, such as by attempting to execute the tainted data, by attempting to modify execution control based on tainted data, or by attempting to apply an existing function to the tainted data. A...
12/06/2011
8069372Simulated computer system for monitoring of software performance
A system S is defined which is capable of simulating a computer (virtual computer, VC) for the purpose of software performance monitoring. The system is implemented as a set of software modules (SM) that can be exchanged to change the behavior of the VC. The VC is d...
11/29/2011
8065738Systems and methods for detecting automated spam programs designed to transmit unauthorized electronic mail via endpoint machines
A computer-implemented method for detecting automated spam programs designed to transmit unauthorized electronic mail via endpoint machines may comprise: 1) monitoring electronic-mail traffic on an endpoint machine, 2) identifying a computer program on the endpoint ...
11/22/2011
8065736Using asynchronous changes to memory to detect malware
A system and method for using asynchronous changes to memory to detect malware is disclosed. The technology initially receives a memory buffer location to be evaluated, the memory buffer location possibly having at least a portion of malware therein. The technology ...
11/22/2011
8065737Virus scanning for block-level distributed application management
Described herein is technology for, among other things virus scanning for block-level distributed application management. The technology involves storing blocks of a root image on a first storage unit and storing blocks of leaf images on respective second storage un...
11/22/2011
8056133Protecting computers from viruses in peer-to-peer data transfers
In one embodiment, a peer-to-peer (P2P) protect server may include a crawler to obtain files available for P2P data transfer. The P2P protect server may employ a scan engine to scan the files for computer viruses, and store the results of the scanning in a database....
11/08/2011
8056135Systems and methods for updating content detection devices and systems
A method of updating a content detection module includes obtaining content detection data, and transmitting the content detection data to a content detection module, wherein the transmitting is performed not in response to a request from the content detection module...
11/08/2011
8056136System and method for detection of malware and management of malware-related information
Disclosed are systems, methods and computer program products for centralized detection and management of malware-related information for use by different security applications. In one example, the centralized security management system comprises a central knowledge ...
11/08/2011
8056134Malware detection and identification via malware spoofing
A malware spoof component may be a formed component which has some but not all characteristics of an actual malware file or other component. Alternately, a spoof component may be an isolated component extracted from actual malware. Malware spoof components may be pl...
11/08/2011
8051484Method and security system for indentifying and blocking web attacks by enforcing read-only parameters
A method for detecting and blocking web attacks, the method comprising identifying read-only parameters by parsing responses received from uniform resource locators. The combinations of binding correlation values (BCVs) of the read-only parameters are compared to th...
11/01/2011
8051483Systems and methods for updating content detection devices and systems
A method of updating a content detection module includes obtaining content detection data, and transmitting the content detection data to a content detection module, wherein the transmitting is performed not in response to a request from the content detection module...
11/01/2011
8051485System and method for optimization of anti-virus scan
A system and method for optimizing a process of synchronization of a database of files checked by an anti-virus (AV) application implemented as a special AV driver. The database is updated by a special interface application using a log file and the AV driver cache. ...
11/01/2011
8046834Method of polymorphic detection
A computer program signature may be determined based on the function flow grammar for a given source code. The function flow grammar may be determined based on reduced control flow graphs generated based on control flow graphs for each function within the source cod...
10/25/2011
8042184Rapid analysis of data stream for malware presence
A system, method and computer program product for anti-malware processing of data stream that includes a plurality of logical data streams formed from a primary data stream; and a plurality of stream buffers, each buffering data of a corresponding logical data strea...
10/18/2011
8042186System and method for detection of complex malware
Disclosed are systems, methods and computer program products for detection of malware with complex infection patterns. The system provides enhanced protection against malware by identifying potentially harmful software objects, monitoring execution of various proces...
10/18/2011
8042185Anti-virus blade
An anti-virus blade provides anti-virus services to a storage system and eliminates the need to develop an interface to initiate a scan operation at the blade. An anti-virus engine executed at the blade receives a request to scan data maintained by the storage syste...
10/18/2011
8037535System and method for detecting malicious executable code
A system and method for detecting malicious executable software code. Benign and malicious executables are gathered; and each are encoded as a training example using n-grams of byte codes as features. After selecting the most relevant n-grams for prediction, a plura...
10/11/2011
8037534Strategies for ensuring that executable content conforms to predetermined patterns of behavior (“inverse virus checking”)
Security provisions are described which determine whether or not executable content is likely to perform undesirable actions. The security provisions assess that an executable content item poses an acceptable risk when it conforms to an allow list of predetermined p...
10/11/2011
8032938Method and system to verify data received, at a server system, for access and/or publication via the server system
A method and system to compare rendered publication data. The publication data are accessed from a database and then rendered to produce rendered publication data. The rendered publication data are stored to provide a reference version. After a periodic time interva...
10/04/2011
8032937Method, apparatus, and computer program product for detecting computer worms in a network
A worm is a malicious process that autonomously spreads itself from one host to another. To infect a host, a worm must somehow copy itself to the host. The method in which a worm transmits a copy of itself produces network traffic patterns that can be generalized as...
10/04/2011
8028338Modeling goodware characteristics to reduce false positive malware signatures
A set of likelihood values associated with a set of characteristics associated with the set of goodware entities is determined. The set of characteristics is stored in association with the set of likelihood values as a model. A set of relative information gain value...
09/27/2011
8020209System and method of monitoring and controlling application files
A system and method for updating a system that controls files executed on a workstation. The workstation includes a workstation management module configured to detect the launch of an application. A workstation application server receives data associated with the ap...
09/13/2011
8011010Using antimalware technologies to perform offline scanning of virtual machine images
Methods and systems for scanning a virtual machine image. The virtual machine image may be stored as a collection of one or more virtual hard disk files. The virtual machine image may be stored by taking the virtual machine off-line or may be stored by taking a chec...
08/30/2011
1                      
 
Sign InRegister
Username  
Password   
forgot password?