Invention Grant
- Patent Title: Malware and spyware attack recovery system and method
- Patent Title (中): 恶意软件和间谍软件攻击恢复系统和方法
-
Application No.: US11266528Application Date: 2005-11-03
-
Publication No.: US07756834B2Publication Date: 2010-07-13
- Inventor: Daniel Masters , Chris Neill
- Applicant: Daniel Masters , Chris Neill
- Applicant Address: US CA Santa Clara
- Assignee: I365 Inc.
- Current Assignee: I365 Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Weaver Austin Villeneuve & Sampson LLP
- Main IPC: G06F12/00
- IPC: G06F12/00 ; G06F17/30 ; G06F12/14 ; G06F12/16

Abstract:
A method and computer program product with encoded instructions provides for repeatedly making data backups for files by making a series of snapshots of file storage volumes containing the files. The method and computer product further provide for determining that a malware attack has occurred, identifying corrupted files and, for each corrupted file, scanning the series of snapshots to identify an uncorrupted version of the file. Each corrupted file is restored to an uncorrupted version thereof. An event log contains write events and snapshot creation events corresponding to creation of each of the snapshots. A forensic scan scans the event log to determine modifying writes made by the corrupted files and which modified further files. The further files are restored to unmodified versions thereof. A list of at-risk files includes the corrupted files and the further files and the forensic scan is repeated on the at-risk files.
Public/Granted literature
- US20070100905A1 Malware and spyware attack recovery system and method Public/Granted day:2007-05-03
Information query