EP2629232A2

Methods and apparatus for dealing with malware

Abstract

In one aspect, a method of classifying a computer object as malware includes receiving at a base computer data about a computer object from each of plural remote computers on which the object or similar objects are stored. The data about the computer object received from the plural computers is compared in the base computer. The computer object is classified as malware on the basis of said comparison. In one embodiment, the data about the computer object includes one or more of : executable instructions contained within or constituted by the object; the size of the object; the name of the object; the logical storage location or path of the object on the respective remote computers; the vendor of the object; the software product and version associated with the object; and, events initiated by or involving the object when the object is created, configured or runs on the respective remote computers.

EP2629232A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 30 June 2026, 0.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

7 claims: 2 independent, 5 dependent

  1. 1
    A method of determining the protection that a remote computer has from malware, the method comprising:receiving at a base computer details of all or selected security products operating at a point in time on said remote computer;receiving similar information from other remote computers connected to the base computer;and, identifying any malware processes that were not identified by said other remote computers having that particular combination of security products.
  2. 4
    Apparatus for determining the protection that a remote computer has from malware, the apparatus comprising:a base computer constructed and arranged to receive computer details of all or selected security products operating at a point in time on said remote computer;the base computer being constructed and arranged to receive similar information from other remote computers connected to the base computer;and, the base computer being constructed and arranged to identify any malware processes that were not identified by said other remote computers having that particular combination of security products.
  3. 7
    A computer program comprising program instructions for causing a computer to perform the method of any of claims 1 to 3.