The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 23, 2019

Filed:

Jan. 21, 2015
Applicant:

Sri International, Menlo Park, CA (US);

Inventors:

Guofei Gu, College Station, TX (US);

Phillip A. Porras, Cupertino, CA (US);

Martin W. Fong, Redwood City, CA (US);

Assignee:

SRI International, Menlo Park, CA (US);

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/00 (2006.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01); G06F 11/34 (2006.01); G06F 21/57 (2013.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01); G06F 21/552 (2013.01); G06F 21/564 (2013.01); G06F 21/566 (2013.01); H04L 63/1416 (2013.01); G06F 11/3495 (2013.01); G06F 21/577 (2013.01); G06F 2221/2101 (2013.01); H04L 63/1458 (2013.01); H04L 2463/144 (2013.01);
Abstract

In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.


Find Patent Forward Citations

Loading…