The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 03, 2021

Filed:

May. 30, 2018
Applicant:

Cyemptive Technologies, Inc., Woodinville, WA (US);

Inventors:

Stewart P. MacLeod, Woodinville, WA (US);

Robert Pike, Woodinville, WA (US);

Assignee:

CYEMPTIVE TECHNOLOGIES, INC., Snohomish, WA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 11/20 (2006.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01); G06F 11/2038 (2013.01); G06F 21/554 (2013.01); G06F 21/566 (2013.01); H04L 63/0236 (2013.01); H04L 63/1416 (2013.01);
Abstract

A method for real-time detection of malware in a Kernel mode includes detecting a file operation request initiated by a process running in user mode. Malware detection analytics is performed on a file buffer associated with the detected file operation request to detect behavior indicating presence of malware. Responsive to detecting the behavior indicating the presence of the malware, the process responsible for initiating the detected file operation request is identified. A search for the identified process is performed on one or more of a blacklist of programs and a whitelist of programs to determine whether the identified process is a trusted process. Responsive to determining that the identified process is not a trusted process, a malware remediation action is executed against the identified process. Information describing the malware is transmitted to a client device.


Find Patent Forward Citations

Loading…