The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 01, 2009

Filed:

Nov. 23, 2004
Applicants:

Douglas Reed Beck, Seattle, WA (US);

Aaron Roy Johnson, Lynnwood, WA (US);

Roussi A. Roussev, Melbourne, FL (US);

Chad E. Verbowski, Redmond, WA (US);

Binh Dou Vo, Berkeley Heights, NJ (US);

Yi-min Wang, Bellevue, WA (US);

Inventors:

Douglas Reed Beck, Seattle, WA (US);

Aaron Roy Johnson, Lynnwood, WA (US);

Roussi A. Roussev, Melbourne, FL (US);

Chad E. Verbowski, Redmond, WA (US);

Binh Dou Vo, Berkeley Heights, NJ (US);

Yi-Min Wang, Bellevue, WA (US);

Assignee:

Microsoft Corporation, Redmond, WA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G08B 23/00 (2006.01);
U.S. Cl.
CPC ...
Abstract

A method and system for detecting that a software system has been infected by software that attempts to hide properties related to the software system is provided. A detection system identifies that a suspect operating system has been infected by malware by comparing properties related to the suspect operating system as reported by the suspect operating system to properties as reported by another operating system that is assumed to be clean. The detection system compares the reported properties to the actual properties to identify any significant differences. A significant difference, such as the presence of an actual file not reported by the suspect operating system, may indicate that the suspect storage device is infected.


Find Patent Forward Citations

Loading…