System, method, and computer program product for reacting in response to a detection of an attempt to store a configuration file and an executable file on a removable device

US9531748B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9531748-B2
Application numberUS-201414578543-A
CountryUS
Kind codeB2
Filing dateDec 22, 2014
Priority dateJun 27, 2008
Publication dateDec 27, 2016
Grant dateDec 27, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system, method, and computer program product are provided for reacting in response to a detection of an attempt to store a configuration file and an executable file on a removable device. In use, a first device removably coupled to a second device is identified. Additionally, an attempt to store on the first device a configuration file for the first device and an executable file is detected. Further, a reaction is performed in response to the detection of the attempt.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory, tangible, computer readable medium comprising one or more instructions that, when executed on a processor, configure the processor to perform operations comprising: monitoring, by a security system, file copy or create operations directed to a removable storage device to detect an attempt by a program on a first device to store a configuration file and an executable file on the removable storage device; and, in response to detecting the attempt, displaying, by the security system, an alert including at least a part of text in the configuration file, wherein the part of the text in the configuration file identifies that the executable file is to be executed via the configuration file. 2. The non-transitory, tangible, computer readable medium of claim 1 , wherein the security system does not have a malware signature for the program. 3. The non-transitory, tangible, computer readable medium of claim 1 , wherein the operations further comprise: flagging the program for a review by the security system in response to a selection to prevent the attempt to store the configuration file and the executable file on the removable storage device. 4. The non-transitory, tangible, computer readable medium of claim 1 , wherein the operations further comprise: preventing a storage of the configuration file and the executable file on the removable storage device. 5. The non-transitory, tangible, computer readable medium of claim 1 , wherein the configuration file includes one or more instructions for an operating system of a second device to run the executable file upon the removable storage device being coupled to the second device. 6. The non-transitory, tangible, computer readable medium of claim 1 , wherein the configuration file includes a file for configuring software on a second device. 7. The non-transitory, tangible, computer readable medium of claim 1 , wherein the configuration file includes a setup information (INF) file. 8. The non-transitory, tangible, computer readable medium of claim 1 , wherein the configuration file is a text-based configuration file. 9. The non-transitory, tangible, computer readable medium of claim 1 , wherein the operations further comprise: displaying one or more of the following: a name, a location, and a source of the configuration file. 10. The non-transitory, tangible, computer readable medium of claim 1 , wherein the alert comprises one or more of the following: a name, a location, a source, and content of the executable file. 11. The non-transitory, tangible, computer readable medium of claim 1 , wherein the executable file includes one or more of the following: a malware file, a virus software file, an adware file, and a spyware file. 12. The non-transitory, tangible, computer readable medium of claim 1 , wherein the removable storage device is removably coupled to the first device via a universal serial bus (USB) connection or an Institute of Electrical and Electronics Engineers (IEEE) 1394 connection. 13. The non-transitory, tangible, computer readable medium of claim 1 , wherein the removable storage device is removably coupled to the first device via a Bluetooth wireless connection or a network connection. 14. The non-transitory, tangible, computer readable medium of claim 1 , wherein the removable storage device includes one or more of the following: a portable hard drive device, a flash-based memory device, a shared network drive, and a portable music player. 15. The non-transitory, tangible, computer readable medium of claim 1 , wherein the operations further comprise: monitoring, by the security system, ports of the first device to identify that the removable storage device coupled to the first device. 16. A device, comprising: a processor, and a memory having instructions stored thereon, wherein the instructions are executable by the processor to cause the device to monitor, by a security system, file copy or create operations directed to a removable storage device to detect an attempt by a program on the device to store a configuration file and an executable file on the removable storage device; and, in response to detecting the attempt, display, by the security system, an alert including at least a part of text in the configuration file, wherein the part of the text in the configuration file identifies that the executable file is to be executed via the configuration file. 17. The device of claim 16 , wherein the security system does not have a malware signature for the program. 18. A method, comprising: monitoring, by a security system, file copy or create operations directed to a removable storage device to detect an attempt by a program on a device to store a configuration file and an executable file on the removable storage device; and, in response to detecting the attempt, displaying, by the security system, an alert including at least a part of text in the configuration file, wherein the part of the text in the configuration file identifies that the executable file is to be executed via the configuration file. 19. The method of claim 18 , wherein the security system does not have a malware signature for the program.

Assignees

Inventors

Classifications

  • Access security · CPC title

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • H04L63/145Primary

    the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9531748B2 cover?
A system, method, and computer program product are provided for reacting in response to a detection of an attempt to store a configuration file and an executable file on a removable device. In use, a first device removably coupled to a second device is identified. Additionally, an attempt to store on the first device a configuration file for the first device and an executable file is detected. …
Who is the assignee on this patent?
Mcafee Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/554. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 27 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).