×

SYSTEM AND METHOD FOR REMOVAL OF MALICIOUS SOFTWARE FROM COMPUTER SYSTEMS AND MANAGEMENT OF TREATMENT SIDE-EFFECTS

  • US 20130247193A1
  • Filed: 10/16/2012
  • Published: 09/19/2013
  • Est. Priority Date: 03/14/2012
  • Status: Active Grant
First Claim
Patent Images

1. A security arrangement for removing malware from a computer system, the security arrangement comprising:

  • computing hardware, including a processor, a data store, and input/output facilities;

    an operating system and application programs executable on the computing hardware;

    an inspection module that monitors operation of the operating system and application programs for a presence of malware, and generates an inspection log representing operational history of the operating system and the application programs;

    wherein the inspection module passes the inspection log to a log analyzer module that responds by detecting a presence of any malware on the computer system based on information contained in the inspection log and in accordance with a malware knowledge base containing indicia of known malware or non-malware programs; and

    a treatment scenario execution module that obtains a pre-evaluated treatment scenario which defines a plurality of actions to be executed for removing any malware present on the computer system, as detected by the log analyzer module, the pre-evaluated treatment scenario having been generated specifically for use by the computer system by a scenario generator module based on the information contained in the inspection log and on a knowledge base of malware removal rules, the generated treatment scenario having been further pre-evaluated by a scenario side-effect evaluation module based on a knowledge base of side-effects relating to malware treatment actions and on the information contained in the inspection log, such that the actions defined in the generated treatment scenario that are associated with a risk of damaging the operating system or the application programs of the computer system are automatically modified to reduce the risk; and

    wherein the treatment scenario execution module executes the pre-evaluated treatment scenario using the computing hardware.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×