×

Backward researching time stamped events to find an origin of pestware

DC
  • US 8,181,244 B2
  • Filed: 04/20/2006
  • Issued: 05/15/2012
  • Est. Priority Date: 04/20/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for identifying an origin of suspected pestware activity on a computer, the method comprising:

  • monitoring, with a kernel-mode driver, activity on the computer;

    generating an activity log on a file storage device of the computer from the kernel-mode driver;

    receiving, from a user via an interface of the computer, a time of interest relating to a suspicion of pestware on the computer, wherein the time of interest includes a time interval;

    issuing a timestamp after receiving the time of interest;

    identifying, based upon the time of interest, indicia of pestware, wherein the identifying is initiated by the issuing the timestamp; and

    accessing, using a hardware processor of the computer, at least a portion of a recorded history of externally networked sources that the computer received files from so as to identify, based at least in part upon the identified indicia of pestware, a reference to an identity of an externally networked source that is suspected of originating pestware;

    wherein the recorded history of externally networked sources is stored on the file storage device.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×