Invention Grant
- Patent Title: Method, system and computer program product for detecting at least one of security threats and undesirable computer files
-
Application No.: US12317056Application Date: 2008-12-18
-
Publication No.: US09055093B2Publication Date: 2015-06-09
- Inventor: Kevin R. Borders
- Applicant: Kevin R. Borders
- Agency: Brooks Kushman P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; G06F21/57

Abstract:
Method, system and computer program product for detecting at least one of security threats and undesirable computer files are provided. A first method includes receiving a data stream which represents outbound, application layer messages from a first computer process to at least one second computer process. The computer processes are implemented on one or more computers. The method further includes monitoring the data stream to detect a security threat based on a whitelist having entries which contain metadata. The whitelist describes legitimate application layer messages based on a set of heuristics. The method still further includes generating a signal if a security threat is detected. A second method includes comparing a set of computer files with a whitelist which characterizes all legitimate computer files. The whitelist contains one or more entries. Each of the entries describe a plurality of legitimate computer files.
Public/Granted literature
Information query