System and method for protecting a computer system from malicious software
Claim Score by NHIP
Abstract
In a computer system, a first electronic data processor is communicatively coupled to a first memory space and a second memory space. A second electronic data processor is communicatively coupled the second memory space and to a network interface device. The second electronic data processor is capable of exchanging data across a network of one or more computers via the network interface device. A video processor is adapted to combine video data from the first and second electronic data processors and transmit the combined video data to a display terminal for displaying the combined video data in a windowed format. The computer system is configured such that a malware program downloaded from the network and executing on the second electronic data processor is incapable of initiating access to the first memory space.

Term
Term ended
Expired 7 August 2024, 2.1 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
71 claims: 6 independent, 65 dependent
- 1A method of operating a computer system having at least a first and second electronic data processor capable of executing instructions using a common operating system, comprising the steps of:executing instructions in a first logical process within the common operating system using the first electronic data processor, wherein the first logical process is capable of accessing data contained in a first memory space and a second memory space;executing instructions in a second logical process within the common operating system using the second electronic data processor, wherein the second logical process is capable of accessing data contained in the second memory space, the second logical process being further capable of exchanging data across a network of one or more computers;displaying, in a windowed format on a display terminal, data from the first logical process and the second logical process, wherein a video processor is adapted to combine data from the first and second logical processes and transmit the combined data to the display terminal;wherein the computer system is configured such that the second electronic data processor is operating in a protected mode and data residing on the first memory space is protected from corruption by a malware process downloaded from the network and executing as part of the second logical process.
- 10Broadest claimClaim Score 44, average(NHIP)A multi-processor computer system using a common operating system, comprising:a first electronic data processor capable of executing instructions using the common operating system and communicatively coupled to a first memory space and a second memory space;a second electronic data processor capable of executing instructions using the common operating system and communicatively coupled to the second memory space and to a network interface device, wherein the second electronic data processor is capable of exchanging data across a network of one or more computers via the network interface device;a video processor adapted to combine video data from the first and second electronic data processors and transmit the combined video data to a display terminal for displaying the combined video data in a windowed format;wherein the computer system is configured such that the second electronic data processor is operating in a protected mode and data residing on the first memory space is protected from corruption by a malware process downloaded from the network and executing on the second electronic data processor.
- 15A multi-processor computer system using a common operating system, comprising:at least a first and second electronic data processor capable of executing instructions using the common operating system;at least a first and second memory space;a video processor;wherein the first and second electronic data processors, first and second memory space, and video processor are configured for performing the steps of: executing instructions in a first logical process with the first electronic data processor, wherein the first logical process is executing within the common operating system and is capable of accessing data contained in the first memory space and the second memory space;executing instructions in a second logical process with the second electronic data processor, wherein the second logical process is executing within the common operating system and is capable of accessing data contained in the second memory space, the second logical process being further capable of exchanging data across a network of one or more computers;displaying, in a windowed format on a display terminal, data from the first logical process and the second logical process, wherein the video processor is adapted to combine data from the first and second logical processes and transmit the combined data to the display terminal;wherein the computer system is configured such that the second electronic data processor is operating in a protected mode and data residing on the first memory space is protected from corruption by a malware process downloaded from the network and executing as part of the second logical process.
- 21A portable computing and communication device capable of executing instructions using a common operating system, comprising:a network interface device configured to exchange data across a network of one or more computers using a wireless connection;an intelligent cellular telephone capability with a secure web browser including a first web browser process and a second web browser process;at least a first memory space and a second memory space, the first memory space containing at least one system file;and at least one electronic data processor communicatively coupled to the network interface device and to the first and second memory space;the at least one electronic data processor configured to execute the first web browser process within the common operating system, wherein the first web browser process is capable of accessing data of a website via the network, accessing data contained in the first memory space and is further capable of initializing the second web browser process;the at least one electronic data processor further configured to execute the second web browser process within the common operating system, wherein the second web browser process is capable of accessing data contained in the second memory space and is further capable of generating data;the at least one electronic data processor further configured to pass data from the first web browser process to the second web browser process;wherein the portable computing and communication device is configured such that the at least one system file residing on the first memory space is protected from corruption by a malware process downloaded from the network and executing within the second web browser process.
- 30A method of operating a portable computing and communication device capable of executing instructions using a common operating system, comprising:exchanging data across a network of one or more computers with a network interface device using a wireless connection;providing an intelligent cellular telephone capability with a secure web browser including a first web browser process and a second web browser process;storing at least one system file within a first memory space;executing the first web browser process within the common operating system using at least one electronic data processor, wherein the first web browser process is configured to access data of a website via the network, access data contained in the first memory space and is further configured to initialize the second web browser process;executing the second web browser process within the common operating system using the at least one electronic data processor, wherein the second web browser process is configured to access data contained in the second memory space and is capable of generating data;passing data from the first web browser process to the second web browser process;and displaying data from the second web browser process;wherein the portable computing and communication device is configured such that the at least one system file residing on the first memory space is protected from corruption by a malware process downloaded from the network and executing as part of the second web browser process.
- 41A computer program product comprising a program code stored in a non-transitory computer readable medium operable on a portable computer and communication device capable of executing instructions using a common operating system and having at least one electronic data processor communicatively coupled to a first memory space with at least one system file and a second memory space, the portable computer and communication device including a network interface device configured to exchange data across a network of one or more computers using a wireless connection, and an intelligent cellular telephone capability with a secure web browser including a first web browser process and a second web browser process, configured to:open the first web browser process within the common operating system, wherein the first web browser process is capable of accessing data of a website via the network and accessing data contained in the first memory space;open the second web browser process within the common operating system on command from the first web browser process, wherein the second web browser process is capable of accessing data contained in the second memory space and is further capable of generating data;pass data from the first web browser process to the second web browser process;and process data from the second web browser process;wherein the at least one system file residing on the first memory space is protected from corruption by a malware process downloaded from the network and executing as part of the second web browser process.
Independent claims6
79 paragraphs in 7 sections, as filed
id="REI-00001" date="20120703"
CROSS REFERENCE TO MULTIPLE REISSUE APPLICATIONS
id="REI-00001"
0001This application is a reissue application of U.S. Pat. No. 7,484,247, entitled “System and Method for Protecting a Computer System from Malicious Software,” issued on Jan. 27, 2009, and is related to another reissue application designated U.S. patent application Ser. No. 12/720,147 from U.S. Pat. No. 7,484,247 filed concurrently herewith, which are incorporated herein by reference. This application is also related to another reissue application designated U.S. patent application Ser. No. 12/854,149 (now, U.S. Pat. No. Re. 43,103) from U.S. Pat. No. 7,484,247 filed on Aug. 10, 2010 and a continuation application therefrom designated U.S. patent application Ser. No. 13/015,186 filed on Jan. 27, 2011, which are incorporated herein by reference. This application is also related to another reissue application designated U.S. patent application Ser. No. 12/941,067 from U.S. Pat. No. 7,484,247 filed on Nov. 7, 2010, which is incorporated herein by reference.
TECHNICAL FIELD
0002The present invention relates generally to computer hardware and software, and more particularly to a system and method for protecting a computer system from malicious software.
CROSS REFERENCE TO RELATED PATENTS AND APPLICATIONS
0003This application is related to the following U.S. patents and applications:
0004<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="3"><colspec colname="1" colwidth="56pt" align="left" /><colspec colname="2" colwidth="105pt" align="left" /><colspec colname="3" colwidth="56pt" align="left" /><thead><row><entry namest="1" nameend="3" align="center" rowsep="1" /></row><row><entry>U.S. patent or </entry><entry /><entry /></row><row><entry>PUB Application</entry><entry /><entry /></row><row><entry>Number</entry><entry>Title</entry><entry>Inventor(s)</entry></row><row><entry namest="1" nameend="3" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry>5,826,013</entry><entry>Polymorphic virus detection </entry><entry>Nachenberg</entry></row><row><entry /><entry>module.</entry><entry /></row><row><entry>5,978,917</entry><entry>Detection and elimination of macro </entry><entry>Chi</entry></row><row><entry /><entry>viruses.</entry><entry /></row><row><entry>6,735,700</entry><entry>Fast virus scanning using session </entry><entry>Flint, et al</entry></row><row><entry /><entry>stamping.</entry><entry /></row><row><entry>6,663,000</entry><entry>Validating components of a </entry><entry>Muttik, et al.</entry></row><row><entry /><entry>malware scanner.</entry><entry /></row><row><entry>6,553,377</entry><entry>System and process for main-</entry><entry>Eschelbeck, et al.</entry></row><row><entry /><entry>taining a plurality of remote </entry><entry /></row><row><entry /><entry>security applications using a </entry><entry /></row><row><entry /><entry>modular framework in a distributed </entry><entry /></row><row><entry /><entry>computing environment.</entry><entry /></row><row><entry>6,216,112</entry><entry>Method for software distribution </entry><entry>Fuller, et al.</entry></row><row><entry /><entry>and compensation with </entry><entry /></row><row><entry /><entry>replenishable advertisements.</entry><entry /></row><row><entry>4,890,098</entry><entry>Flexible window management on a </entry><entry>Dawes, et al.</entry></row><row><entry /><entry>computer display.</entry><entry /></row><row><entry>5,555,364</entry><entry>Windowed computer display.</entry><entry>Goldstein</entry></row><row><entry>5,666,030</entry><entry>Multiple window generation in </entry><entry>Parson</entry></row><row><entry /><entry>computer display.</entry><entry /></row><row><entry>5,995,103</entry><entry>Window grouping mechanism for </entry><entry>Ashe</entry></row><row><entry /><entry>creating, manipulating and </entry><entry /></row><row><entry /><entry>displaying windows and window </entry><entry /></row><row><entry /><entry>groups on a display screen of a </entry><entry /></row><row><entry /><entry>computer system.</entry><entry /></row><row><entry>5,502,808</entry><entry>Video graphics display system with </entry><entry>Goddard, et al.</entry></row><row><entry /><entry>adapter for display management </entry><entry /></row><row><entry /><entry>based upon plural memory sources.</entry><entry /></row><row><entry>5,280,579</entry><entry>Memory mapped interface between </entry><entry>Nye</entry></row><row><entry /><entry>host computer and graphics system.</entry><entry /></row><row><entry>5,918,039</entry><entry>Method and apparatus for display </entry><entry>Buswell, et al</entry></row><row><entry /><entry>of windowing application programs </entry><entry /></row><row><entry /><entry>on a terminal.</entry><entry /></row><row><entry>6,480,198</entry><entry>Multi-function controller and </entry><entry>Kang</entry></row><row><entry /><entry>method for a computer graphics</entry><entry /></row><row><entry /><entry>display system.</entry><entry /></row><row><entry>6,167,522</entry><entry>Method and apparatus for </entry><entry>Lee, et al.</entry></row><row><entry /><entry>providing security for servers </entry><entry /></row><row><entry /><entry>executing application programs </entry><entry /></row><row><entry /><entry>received via a network</entry><entry /></row><row><entry>6,199,181</entry><entry>Method and system for maintaining </entry><entry>Rechef, et al.</entry></row><row><entry /><entry>restricted operating environments </entry><entry /></row><row><entry /><entry>for application programs or </entry><entry /></row><row><entry /><entry>operating systems.</entry><entry /></row><row><entry>6,275,938</entry><entry>Security enhancement for untrusted </entry><entry>Bond, et al.</entry></row><row><entry /><entry>executable code.</entry><entry /></row><row><entry>6,321,337</entry><entry>Method and system for protecting </entry><entry>Reshef, et al.</entry></row><row><entry /><entry>operations of trusted internal</entry><entry /></row><row><entry /><entry>networks.</entry><entry /></row><row><entry>6,351,816</entry><entry>System and method for securing a </entry><entry>Mueller, et al.</entry></row><row><entry /><entry>program's execution in a network</entry><entry /></row><row><entry /><entry>environment.</entry><entry /></row><row><entry>6,546,554</entry><entry>Browser-independent and </entry><entry>Schmidt, et al.</entry></row><row><entry /><entry>automatic apparatus and method </entry><entry /></row><row><entry /><entry>for receiving, installing and </entry><entry /></row><row><entry /><entry>launching applications from a </entry><entry /></row><row><entry /><entry>browser on a client computer.</entry><entry /></row><row><entry>6,658,573</entry><entry>Protecting resources in a </entry><entry>Bischof, et al</entry></row><row><entry /><entry>distributed computer system.</entry><entry /></row><row><entry>6,507,904</entry><entry>Executing isolated mode </entry><entry>Ellison, et al.</entry></row><row><entry /><entry>instructions in a secure system </entry><entry /></row><row><entry /><entry>running in privilege rings.</entry><entry /></row><row><entry>6,633,963</entry><entry>Controlling access to multiple </entry><entry>Ellison, et al.</entry></row><row><entry /><entry>memory zones in an isolated</entry><entry /></row><row><entry /><entry>execution environment.</entry><entry /></row><row><entry>6,678,825</entry><entry>Controlling access to multiple </entry><entry>Ellison, et al.</entry></row><row><entry /><entry>isolated memories in an isolated</entry><entry /></row><row><entry /><entry>execution environment.</entry><entry /></row><row><entry>5,751,979</entry><entry>Video hardware for protected, </entry><entry>McCrory</entry></row><row><entry /><entry>multiprocessing systems.</entry><entry /></row><row><entry>6,581,162</entry><entry>Method for securely creating, </entry><entry>Angelo, et al.</entry></row><row><entry /><entry>storing and using encryption keys </entry><entry /></row><row><entry /><entry>in a computer system.</entry><entry /></row><row><entry>6,134,661</entry><entry>Computer network security device </entry><entry>Topp</entry></row><row><entry /><entry>and method.</entry><entry /></row><row><entry>6,578,140</entry><entry>Personal computer having a master </entry><entry>Policard</entry></row><row><entry /><entry>computer system and in internet</entry><entry /></row><row><entry /><entry>computer system and monitoring a </entry><entry /></row><row><entry /><entry>condition of said master and</entry><entry /></row><row><entry /><entry>internet computer systems</entry><entry /></row><row><entry>PUB Application #</entry><entry>E-mail software and method and </entry><entry>Jacobs, Paul E., </entry></row><row><entry>20040054588</entry><entry>system for distributing advertise-</entry><entry>et al.</entry></row><row><entry /><entry>ments to client devices that have </entry><entry /></row><row><entry /><entry>such e-mail software installed </entry><entry /></row><row><entry /><entry>thereon.</entry><entry /></row><row><entry>PUB Application #</entry><entry>System and method for compre-</entry><entry>Mayer, Yaron; et </entry></row><row><entry>20040034794</entry><entry>hensive general generic protection </entry><entry>al.</entry></row><row><entry /><entry>for computers against malicious </entry><entry /></row><row><entry /><entry>programs that may steal </entry><entry /></row><row><entry /><entry>information and/or cause damages</entry><entry /></row><row><entry>PUB Application #</entry><entry>System and method for providing </entry><entry>Skrepetos, </entry></row><row><entry>20040006715</entry><entry>security to a remote computer over </entry><entry>Nicholas C.</entry></row><row><entry /><entry>a network browser interface.</entry><entry /></row><row><entry>PUB Application #</entry><entry>Virus protection in an internet </entry><entry>Samman, Ben</entry></row><row><entry>20030177397</entry><entry>environment.</entry><entry /></row><row><entry>PUB Application #</entry><entry>System and method for protecting </entry><entry>Pham, Khai; et </entry></row><row><entry>20030097591</entry><entry>computer users from web sites </entry><entry>al. </entry></row><row><entry /><entry>hosting computer viruses.</entry><entry /></row><row><entry>PUB Application #</entry><entry>Malware infection suppression.</entry><entry>Hinchliffe, </entry></row><row><entry>20030023857</entry><entry /><entry>Alexander James; </entry></row><row><entry /><entry /><entry>et al.</entry></row><row><entry>PUB Application #</entry><entry>Access control for computers.</entry><entry>Riordan, James</entry></row><row><entry>20020066016</entry><entry /><entry /></row><row><entry>PUB Application #</entry><entry>Detecting malicious alteration of </entry><entry>Wolff, Daniel </entry></row><row><entry>20020174349</entry><entry>stored computer files.</entry><entry>Joseph; et al.</entry></row><row><entry namest="1" nameend="3" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0005The above-listed U.S. Patents and U.S. patent applications are incorporated by reference as if reproduced herein in their entirety.
BACKGROUND
0006The very popular and ubiquitous rise of the ‘personal’ computer system as an essential business tool and home appliance, together with the exponential growth of the Internet as a means of providing information flows across a wide variety of connected computing devices, has changed the way people live and work. Information in the form of data files and executable software programs regularly flows across the planetary wide system of interconnected computers and data storage devices.
0007Popular and ubiquitous computer hardware and software architectures have typically been designed to allow for open interconnection via, for example, the internet, a VPN, a LAN, or a WAN, with information often capable of being freely shared between the interconnected computers. This open interconnection architecture has contributed to the adoption and mainstream usage of these computers and the subsequent interconnection of vast networks of computers. This easy to use system has given rise to the explosive popularity of applications such as email, internet browsing, search engines, interactive gaming, instant messaging, and many, many more.
0008Although there are definite benefits to this open interconnection architecture, a lack of security against unwanted incursions into the computers main processing and non-volatile memory space has emerged as a significant problem. An aspect of some current computer architectures that has contributed to the security problem is that by default programs are typically allowed to interact with and/or alter other programs and data files, including critical operating system files, such as the windows registry, for example. Current open interconnection architectures have opened the door to a new class of unwanted malicious software generally known a malware. This malware is capable of infiltrating any computer system which is connected to a network of interconnected computer systems. Malware is comprised of, but not limited to, classes of software files known as viruses, worms, Trojan horses, browser hijackers, adware, spyware, pop-up windows, data miners, etc. Such malware attacks are capable of stealing data by sending user keystrokes or information stored on a user's computer back to a host, changing data or destroying data on personal computers and/or servers and/or other computerized devices, especially through the Internet. In the least, these items represent a nuisance that interferes with the smooth operation of the computer system, and in the extreme, can lead to the unauthorized disclosure of confidential information stored on the computer system, significant degradation of computer system performance, or the complete collapse of computer system function.
0009Malware has recently become much more sophisticated and much more difficult for users to deal with. Once resident on a computer system, many malware programs are designed to protect themselves from deletion. For example, some malware programs comprise a pair of programs running simultaneously, with each program monitoring the other for deletion. If one of the pair of programs is deleted, the other program installs a replacement within milliseconds. In another example, some malware will run as a Windows program with a .dlls extension, which Windows may not allow a user to delete while it is executing. Malware may also reset a user's browser home page, change browser settings, or hijack search requests and direct such requests to another page or search engine. Further, the malware is often designed to defeat the user's attempts to reset the browser settings to their original values. In another example, some malware programs secretly record user input commands (such as keystrokes), then send the information back to a host computer. This type of malware is capable of stealing important user information, such as passwords, credit account numbers, etc.
0010Many existing computers rely on a special set of instructions which define an operating system (O/S) in order to provide an interface for computer programs and computer components such as the computer's memory and central processing unit (CPU). Many current operating systems have a multi-tasking capability which allows multiple computer programs to run simultaneously, with each program not having to wait for termination of another in order to execute instructions. Multi-tasking O/S's allow programs to execute simultaneously by allowing programs to share resources with other programs. For example, an operating system running multiple programs executing at the same time allows the programs to share the computer's CPU time. Programs which run on the same system, even if not simultaneously with other programs, share space on the same nonvolatile memory storage medium. Programs which are executing simultaneously are presently able to place binaries and data in the same physical memory at the same time, limited to a certain degree by the O/S restrictions and policy, to the extent that these are properly implemented. Memory segments are shared by programs being serviced by the O/S, in the same manner. O/S resources, such as threads, process tables and memory segments, are shared by programs executing simultaneously as well.
0011While allowing programs to share resources has many benefits, there are resulting security related ramifications, particularly regarding malware programs. Security problems include allowing the malware program: to capitalize CPU time, leaving other programs with little or no CPU time; to read, forge, write, delete or otherwise corrupt files created by other programs; to read, forge, write, delete or otherwise corrupt executable files of other programs, including the O/S itself; and to read and write memory locations used by other programs to thus corrupt execution of those programs.
0012In the case of a computer connected to the Internet, the computer may run an O/S, with several user applications, together comprising a known and trusted set of programs, concurrently with an Internet browser, possibly requiring the execution of downloaded code, such as Java applets, or EXE/COM executables, with the latter programs possibly containing malware. Many security features and products are being built by software manufacturers and by O/S programmers to prevent malware infiltrations from taking place, and to ensure the correct level of isolation between programs. Among these are architectural solutions such as rings-of-protection in which different trust levels are assigned to memory portions and tasks, paging which includes mapping of logical memory into physical portions or pages, allowing different tasks to have different mapping, with the pages having different trust levels, and segmentation which involves mapping logical memory into logical portions or segments, each segment having its own trust level wherein each task may reference a different set of segments. Since the sharing capabilities using traditional operating systems are extensive, so are the security features. However, the more complex the security mechanism is, the more options a malware practitioner has to bypass the security and to hack or corrupt other programs or the O/S itself, sometimes using these very features that allow sharing and communication between programs to do so.
0013Further, regarding malware programs, for virtually every software security mechanism, a malware practitioner has found a way to subvert, or hack around, the security system, allowing a malware program to cause harm to other programs in the shared environment. This includes every operating system and even the Java language, which was designed to create a standard interface, or sandbox, for Internet downloadable programs or applets.
0014Major vulnerabilities of existing computer systems lies in the architectures of the computer system and of the operating system itself. A typical multi-tasking O/S environment includes an O/S kernel loaded in the computer random access memory (RAM) at start-up of the computer. The O/S kernel is a minimal set of instructions which loads and off-loads resources and resource vectors into RAM as called upon by individual programs executing on the computer. Sometimes, when two or more executing programs require the same resource, such as printer output, for example, the O/S kernel leaves the resource loaded in RAM until all programs have finished with that resource. Other resources, such as disk read and write, are left in RAM while the operating system is running because such resources are more often used than others. The inherent problem with existing architectures is that resources, such as RAM, or a hard disk, are shared by programs simultaneously, giving a malware program a conduit to access and corrupt other programs, or the O/S itself through the shared resource. Furthermore, as many application programs are of a general nature, many features are enabled by default or by the O/S, thus in many cases bypassing the O/S security mechanism. Such is the case when a device driver or daemon is run by the O/S in kernel mode, which enables it unrestricted access to many if not all the resources.
0015The most common state-of the-art solutions for preventing malware infiltration are software based, such as blockers, sweepers and firewalls, for example, and hardware based solutions such as router/firewalls. Examples of software designed to counter malware are Norton Systems Works, distributed by the Symantec Corporation, Ad-aware, distributed by the Lavasoft Corporation of Sweeden, Spy Sweeper, distributed by the Webroot Software Corporation, Spyware Guard, distributed by Javacool Software LLC, among others. Currently there are a plethora of freeware, shareware and purchased software programs designed to counter malware by a variety of means. Such anti-malware programs are limited because they can only detect known malware that has already been identified (usually after the malware has already attacked one or more computers).
0016Network firewalls are typically based on packet filtering, which is limited in principle, since the rules determining which packets to accept and which to reject may contain subjective decisions based on trusting known sites or known applications. However, once security is breached for any reason (for example, due to a software or hardware error, a new piece of malware unrecognized by the anti-malware program or firewall, or an intended deception), a malicious application may take over the computer or server or possibly the entire network and create unlimited damages (directly or indirectly by opening the door to additional malicious applications).
0017The methods in the prior art are typically comprised of embedded software countermeasures that detect and filter unwanted intrusions in real time, or scan the computer system either at the direction of a user or as a scheduled event. Two problems arise from these methods. In the first instance, a comprehensive scan, detect, and elimination of malware from desired incoming data streams could significantly slow or preclude the interactive nature of many applications such a gaming, messaging, and browsing. In the second instance, newly implemented software screens may be quickly circumvented by malware practitioners who are determined to pass their files through the screen. Newly discovered malware leads to the development of additional screens, which lead to more malware, etc., thus creating an escalating cycle of measure, countermeasure. The basic flaw is that all incoming executable data files must be resident on the computers main processor to perform their desired function. Once resident on that processor, access may be gained to non-volatile memory and other basic computer system elements. Malware exploits this key architectural flaw to infiltrate and compromise computer systems.
0018The majority of these applications rely upon a scanning engine which searches suspect files for the presence of predetermined malware signatures. These signatures are held in a database which must be constantly updated to reflect the most recently identified malware. Typically, users regularly download replacement databases, either over the Internet, from a received e-mail, or from a CDROM or floppy disc. Users are also expected to update their software engines every so often in order to take advantage of new virus detection techniques (e.g. which may be required when a new strain of malware is detected).
0019Many of the aforementioned applications are also not effective against security holes, for example, in browsers or e-mail programs, or in the operating system itself. Security holes in critical applications are discovered quite often, and just keeping up with all the patches is cumbersome. Also, without proper generic protection against, for example, Trojan horses, even VPNs (Virtual Private Networks) and other forms of data encryption, including digital signatures, are not totally safe because information can be stolen before or below the encryption layer. Even personal firewalls are typically limited, because once a program is allowed to access the Internet, there are often few limitations on what files may be accessed and transmitted back to a host.
0020A major problem faced by computer users connected to a network is that the network interface program (a browser, for example) is resident on the same processor as the O/S and other trusted programs, and shares space on a common memory storage medium. Even with security designed into the O/S, malware practitioners have demonstrated great skill in circumventing software security measures to create malware capable of corrupting critical files on the shared memory storage medium. When this happens, users are often faced with a lengthy process of restoring their computer systems to the correct configuration, and often important files are simply lost because no backup exists.
0021Therefore, what is needed in the art is a means of isolating the network interface program from the main computer system such that the network interface program does not share a common memory storage area with other trusted programs. The network interface program may be advantageously given access to a separate, protected memory area, while being unable to initiate access to the main computer's memory storage area. With the network interface program constrained in this way, malware programs are rendered unable to automatically corrupt critical system and user files located on the main memory storage area. If a malware infection occurs, a user would be able to completely clean the malware infection from the computer using a variety of methods. A user could simply delete all files contained in the protected memory area, and restore them from an image residing on the main memory area, for example.
0022Other discussions of malware, its effects on computer systems, techniques used by malware practitioners to install malware, and techniques for detection and removal, may be found in the published literature, and in some of the patents and applications previously incorporated by reference. Reference to malware may be found in a technical white paper entitled “Spyware, Adware, and Peer-to-Peer Networks: The Hidden Threat to Corporate Security.”, by Kevin Townsend, © Pest Patrol Inc. 2003. Pest Patrol is a Carlisle; Pa. based developer of software security tools. Another reference is a technical white paper entitled “Beyond Viruses: Why antivirus software is no longer enough.” by David Stang, PhD, © Pest Patrol Inc. 2002. Yet another reference is “The Web: Threat or Menace?” from “Firewalls and Internet Security: Repelling the Wily Hacker”, Second Edition, Addison-Wesley. ISBN 0-201-63466-X, Copyright 2003. The foregoing references are incorporated by reference as if reproduced herein in their entirety.
SUMMARY OF THE INVENTION
0023Embodiments of the present invention achieve technical advantages as a system and method for protecting a computer system from malicious software attacks via a network connection.
0024It is an object of the present invention to provide a computer system capable of preventing malware programs from automatically corrupting critical user and system files.
0025It is another object of the present invention to confine any malware infection that may occur to a separate, protected part of the computer system.
0026It is another object of the present invention to provide a user with an easy and comprehensive method of removing the malware infection, even if the user's anti-malware software is incapable of detecting and/or removing the malware infection.
0027It is another object of the present invention to provide a user with an easy and comprehensive method of restoring critical system and user files that may have been corrupted by a malware infection.
0028It is another object of the present invention to provide a computer system configured such that attempts by malware to record and report data entry by the computer user via input devices such as keyboards, mouse clicks, microphones, or any other data input devices are effectively blocked.
0029It is another object of the present invention to provide a computer system capable of executing instructions in a first logical process, wherein the first logical process is capable of accessing data contained in a first memory space and a second memory space.
0030It is another object of the present invention to provide a computer system capable of executing instructions in a second logical process, wherein the second logical process is capable of accessing data contained in the second memory space, the second logical process being further capable of exchanging data across a network of one or more computers.
0031It is another object of the present invention to provide a computer system capable of displaying, in a windowed format on a display terminal, data from the first logical process and the second logical process, wherein a video processor is adapted to combine data from the first and second logical processes and transmit the combined data to the display terminal
0032It is another object of the present invention to provide a computer system configured such that a malware program downloaded from the network and executing as part of the second logical process is incapable of initiating access to the first memory space.
0033It is another object of the present invention to provide a computer system configured such that corrupted data files residing on the second memory space may be restored from an image residing on the first memory space.
0034It is another object of the present invention to provide a computer system configured such that data files residing on the second memory space may be automatically deleted when the second logical process is terminated.
0035It is another object of the present invention to provide a computer system configured such that the second electronic data processor and the video processor are co-located on a circuit card, the circuit card being communicatively coupled to the first electronic data processor.
0036These objects and other advantages are provided by a preferred embodiment of the present invention wherein a computer system comprising a first electronic data processor is communicatively coupled to a first memory space and to a second memory space, a second electronic data processor is communicatively coupled to the second memory space and to a network interface device, wherein the second electronic data processor is capable of exchanging data across a network of one or more computers via the network interface device, a video processor is adapted to combine video data from the first and second electronic data processors and transmit the combined video data to a display terminal for displaying the combined video data in a windowed format, wherein the computer system is configured such that a malware program downloaded from the network and executing on the second electronic data processor is incapable of initiating access to the first memory space.
BRIEF DESCRIPTION OF THE DRAWINGS
0037For a more complete understanding of the present invention, and the advantages thereof, reference is now made to the following descriptions taken in conjunction with the accompanying drawings, in which:
0038<figref idref="DRAWINGS">FIG. 1</figref> illustrates a preferred embodiment of an exemplary computer system according to the principles of the present invention;
0039<figref idref="DRAWINGS">FIG. 2</figref> illustrates a preferred embodiment of an exemplary protected process flow according to the principles of the present invention;
0040<figref idref="DRAWINGS">FIG. 3</figref> illustrates a preferred embodiment of an exemplary file download process according to the principles of the present invention;
0041<figref idref="DRAWINGS">FIG. 4</figref> illustrates a preferred embodiment of an exemplary memory restoration process according to the principles of the present invention;
0042<figref idref="DRAWINGS">FIG. 5</figref> illustrates a preferred embodiment of an exemplary automatic memory restoration and cleaning process according to the principles of the present invention;
0043<figref idref="DRAWINGS">FIG. 6</figref> illustrates a preferred embodiment of an exemplary interactive network process flow according to the principles of the present invention;
0044<figref idref="DRAWINGS">FIG. 7</figref> illustrates a preferred embodiment of an exemplary computer system according to the principles of the present invention;
0045<figref idref="DRAWINGS">FIG. 8</figref> illustrates a preferred embodiment of an exemplary computer system according to the principles of the present invention;
0046<figref idref="DRAWINGS">FIG. 9</figref> illustrates a preferred embodiment of an exemplary computer system according to the principles of the present invention;
0047<figref idref="DRAWINGS">FIG. 10</figref> illustrates a preferred embodiment of an exemplary protected process flow according to the principles of the present invention.
DETAILED DESCRIPTION OF THE ILLUSTRATED EMBODIMENTS
0048The making and using of the presently preferred embodiments are discussed in detail below. It should be appreciated, however, that the present invention provides many applicable inventive concepts that can be embodied in a wide variety of specific contexts. The specific embodiments discussed are merely illustrative of specific ways to make and use the invention, and do not limit the scope of the invention.
0049A computer system, constructed in accordance with a preferred embodiment of the present invention, is illustrated in <figref idref="DRAWINGS">FIG. 1</figref>. Computer system <b>100</b> may represent, for example, a personal computer (PC) system, a server, a portable computer, such as a notebook computer, or any data processing system, a personal digital assistant (PDA), a communication device such as a cell phone, or device that is capable of being connected to a network of one or more computers. System <b>100</b> comprises a first processor <b>120</b> (P<b>1</b>) communicatively coupled to a first memory and data storage area <b>110</b> (M<b>1</b>). P<b>1</b><b>100</b> may comprise, for example, a microprocessor, such as a Pentium® 4 processor, manufactured by the Intel Corporation, or a Power PC® processor, manufactured by the IBM Corporation. Other electronic data processors manufactured by other companies, including but not limited to electronic data processors realized in Application Specific Integrated Circuits (ASICs) or in Field Programmable Gate Arrays (FPGAs), are within the spirit and scope of the present invention.
0050The first memory and data storage area <b>110</b> may comprise both volatile and nonvolatile memory devices, such as DRAMs and hard drives, respectively. Any memory structure and/or device capable of being communicatively coupled to P<b>1</b> may be advantageously used in the present invention. M<b>1</b> may be used to store, for example, critical operating system files, user data and applications, interim results of calculations, etc. The many uses of computer memory are well understood by those skilled in the art, and will not be discussed further here. One may refer to several of the aforementioned patents and applications incorporated by reference, in addition to other references, for a discussion of existing computer architectures and uses of computer memory. Also part of system <b>100</b> is user interface <b>150</b>, which may comprise, for example, a keyboard, mouse or other pointing device, microphone, pen pad, etc. Any device or method capable of inputting commands and/or data from a user <b>160</b> to computer system <b>100</b> may be used to advantage. A video processor <b>170</b> is used to format information for display and transmit the display information to a video display device <b>180</b>, which is viewed by user <b>160</b>. Video processor <b>170</b> typically includes an associated video memory area, which may be dedicated to the video processor, or shared with other resources. It is understood in the art that the video processor <b>170</b> may be part of processor P<b>1</b><b>120</b>, in that it may be integrated onto the microprocessor chip. Video processor <b>170</b> may also comprise a processor IC located on a video graphics card, which is communicatively coupled to a computer motherboard. Additionally, video processor <b>170</b> may comprise circuitry located on the computer motherboard. Further still, functions of video processor <b>170</b> may be split between the processor, motherboard, or separate video graphics card.
0051It is often desirable to connect computer system <b>100</b> to a network of one or more computer devices <b>195</b>, such as the Internet, a LAN, WAN, VPN, etc. This connection may be accomplished via network interface device <b>190</b>, which may comprise, for example, a telephone modem, a cable modem, a DSL line, a router, gateway, hub, etc. Any device capable of interfacing with the network <b>195</b> may be used, via a wired connection, a wireless connection, or an optical connection, for example. Network interface device <b>190</b> may connect to network <b>195</b> through one or more additional network interface devices (not shown). For example, network interface device <b>190</b> may comprise a gateway or router, connected to a cable modem, with the cable modem connected to network <b>195</b>. Of course, other configurations are within the spirit and scope of the present teachings.
0052In accordance with a preferred embodiment of the present invention, network <b>195</b> is isolated from the first processor <b>120</b> and memory <b>110</b> by a second processor <b>140</b> (P<b>2</b>). Second processor <b>140</b> may comprise any electronic data processor, such as the devices previously described as applicable to first processor <b>120</b>. Communicatively coupled to P<b>2</b><b>140</b> is second memory and data storage area <b>130</b> (M<b>2</b>), which may comprise any memory device or devices, such as the devices previously described as applicable to first memory <b>110</b>.
0053The architecture of computer system <b>100</b> is designed to be capable of protecting memory <b>110</b> from malware initiated intrusions, and preventing malware from initiating unwanted processes on first processor <b>120</b>. This is accomplished by using second processor <b>140</b> to isolate <b>110</b> and <b>120</b> from network <b>195</b>. In a preferred embodiment, P<b>2</b><b>140</b> is communicatively coupled to memory storage area M<b>2</b><b>130</b>, and may be configured such that P<b>2</b><b>140</b> is incapable of initiating access to memory storage area M<b>1</b><b>110</b>. For example, P<b>2</b><b>140</b> may be capable of accessing memory storage area M<b>1</b><b>110</b> with the strict permission of user <b>160</b>, either through a real time interaction or via stored configuration or commands. Such a configuration may be desirable in a multi-core or multi processor system, where user <b>160</b> may wish to use P<b>2</b><b>140</b> in either a protected mode or an unprotected mode, depending on the application. However, user <b>160</b> is capable of denying P<b>2</b><b>140</b> the capability of initiating access to memory storage area M<b>1</b><b>110</b> without the user's permission. P<b>1</b><b>120</b> is communicatively coupled to both memory areas M<b>1</b><b>110</b> and M<b>2</b><b>130</b>, thereby enabling P<b>1</b><b>120</b> to access data downloaded from the network <b>195</b>. In the presently described embodiment, any malware that has intruded the <b>130</b>-<b>140</b> system is thus confined to the <b>130</b>-<b>140</b> system, and may be configured to be incapable of automatically corrupting data contained on M<b>1</b><b>110</b>, or of automatically initiating an unwanted process on P<b>1</b><b>120</b>.
0054This and other features of the present teachings may be illustrated with reference to the example process flow <b>200</b> of <figref idref="DRAWINGS">FIG. 2</figref>. Computer user <b>160</b> wishes to connect to network <b>195</b> via for example, a browser program such as Internet Explorer or Netscape Navigator. Of course, other methods of connecting to network <b>195</b> may be used. User <b>160</b> inputs commands to open a protected process (e.g. a browser program in this example) at step <b>210</b>. At step <b>220</b>, 1<sup>st </sup>processor <b>120</b> instructs 2<sup>nd </sup>processor <b>140</b> to initiate the protected process and open one or more process windows. Second processor <b>140</b>, in conjunction with memory <b>130</b>, then interacts with the network <b>195</b> via network interface device <b>190</b>, receiving and transmitting the data necessary to execute the desired protected process, such as browsing the internet or communication via e-mail. Second processor <b>140</b> and memory <b>130</b> act as a separate computer system, interacting with network <b>195</b> while isolating network <b>195</b> from the first processor <b>120</b> and memory <b>110</b>. Memory <b>130</b> may store critical application and system files required by second processor <b>140</b> to execute the desired tasks. Memory <b>130</b> also stores data necessary to carry out the desired protected process. In the example of <figref idref="DRAWINGS">FIG. 2</figref>, first processor <b>120</b> receives user interface data from user <b>160</b>, and passes user interface data to second processor <b>140</b> when the protected process window is selected or active, illustrated at step <b>230</b>. User interface data, such as keystrokes for example, may be advantageously encrypted by P<b>1</b><b>120</b> before passing the data to P<b>2</b><b>140</b>, with network interface device <b>190</b> possibly decrypting the data prior to transmitting the data to network <b>195</b>. Encrypting, for example keystroke data, may disrupt the efforts of spyware programs designed to store user keystrokes for later transmission to a host computer. Second processor <b>140</b> generates video data for the protected process window(s) and passes the video data to video processor <b>170</b>, for eventual display on video display <b>180</b>, shown at step <b>240</b>. Video processor <b>170</b> then interleaves the video data from all processes being executed by first processor <b>120</b> and second processor <b>140</b>, at step <b>250</b>. While there are many applicable methods for displaying video data from multiple sources, one such method was described in U.S. Pat. No. 5,751,979, entitled “Video hardware for protected, multiprocessing systems”, previously incorporated by reference.
0055In accordance with a preferred embodiment of the present invention, if any malware is downloaded from network <b>195</b>, it is stored in memory <b>130</b>, and/or run as a process on second processor <b>140</b>. In the configuration of computer system <b>100</b>, any downloaded malware is rendered incapable of self initiating access to memory <b>110</b> or first processor <b>120</b>, because second processor <b>140</b> is rendered incapable of initiating access to <b>110</b> and <b>120</b> without a direct or stored command from user <b>160</b>. Any malware infection is thus confined. If a malware attack corrupts files and/or disrupts the operation of the <b>130</b>-<b>140</b> system, the user may easily shut down the corrupted process and restore the corrupted files from a protected image stored on memory <b>110</b>, for example.
0056In accordance with a preferred embodiment of the present invention, the operating system controlling the <b>110</b>-<b>120</b> system may be different from an operating system controlling the protected <b>130</b>-<b>140</b> system. Conversely, a common operating system may control both the <b>110</b>-<b>120</b> system and the protected <b>130</b>-<b>140</b> system.
0057A user <b>160</b> may find it desirable to transfer files from the protected <b>130</b>-<b>140</b> system to the <b>110</b>-<b>120</b> system. User <b>160</b> may find it necessary, for example, to transfer an attachment from an e-mail message stored on memory <b>130</b> to the <b>110</b>-<b>120</b> system for further processing, modification, etc. In this case, the computer system <b>100</b> may go through a process whereby a file or other data is transferred from the <b>130</b>-<b>140</b> system to the <b>110</b>-<b>120</b> system, exemplified by the process <b>300</b> illustrated in <figref idref="DRAWINGS">FIG. 3</figref>.
0058In accordance with a preferred embodiment of the present invention, at step <b>310</b>, user <b>160</b> selects one or more data files to download from network <b>195</b>. The desired data is downloaded to the <b>130</b>-<b>140</b> system at step <b>320</b>. The user <b>160</b> then directs computer system <b>100</b> to move the desired file(s) from the <b>130</b>-<b>140</b> system to the <b>110</b>-<b>120</b> system at step <b>330</b>. P<b>1</b><b>120</b> may then perform a malware scan on the desired files, either in real time as the data is being transferred, or while the data still resides in M<b>2</b><b>130</b> (step <b>340</b>). Alternatively, P<b>2</b><b>140</b> may perform the malware scan. At step <b>350</b>, processor P<b>2</b><b>140</b> (or P<b>1</b><b>120</b>) determines if malware has been detected in the desired file(s), and thus P<b>1</b><b>120</b> makes a decision. If no malware is detected, the file(s) are moved or copied onto M<b>2</b><b>110</b> at step <b>360</b>. If malware is detected, the data file(s) are quarantined on M<b>2</b><b>130</b>, and the data file(s), if transferred to M<b>1</b><b>100</b>, are erased or quarantined. Once malware is detected, the user <b>160</b> may be alerted of the detection (step <b>370</b>). Either as a result of user input or stored configuration commands, the infected file(s) are deleted, cleaned, or quarantined on M<b>2</b><b>130</b>, at step <b>380</b>.
0059The user <b>160</b> would of course understand the dangers inherent in transferring downloaded files from the <b>130</b>-<b>140</b> system to the <b>110</b>-<b>120</b> system. For example, the user's anti-malware software may not be up to date, or may simply be unable to detect certain types of malware. Also, the malware itself may be so new that the user's anti-malware definitions have not been updated as yet. Therefore the user may wish to keep the files on the <b>130</b>-<b>140</b> system for some period of time. Consequently, it may be desirable to have resident on the <b>130</b>-<b>140</b> system a variety of application software such as readers, thereby allowing the user to examine the files without risking transferring the files to the <b>110</b>-<b>120</b> system. These reader programs, such as Adobe Acrobat Reader, by the Adobe Systems Corporation, or Visio reader, by the Microsoft Corporation, are typically subset application programs of the full featured application programs, and may thus require far less memory space than the full application. Additionally, software companies often distribute the reader programs for free (or a nominal fee), thereby providing advertising for the full featured application in the hopes that it will be eventually purchased by the user. This reader application may be opened and executed on the <b>130</b>-<b>140</b> system in a manner similar to the process described in <figref idref="DRAWINGS">FIG. 2</figref>. Of course, a user <b>160</b> may also load a full application into the <b>130</b>-<b>140</b> system, enabling processing and modification of a downloaded file fully in the protected space, without risking a transfer of the file to the <b>110</b>-<b>120</b> system.
0060In the event the <b>130</b>-<b>140</b> system becomes infected with malware, the user <b>160</b> may wish to clean the <b>130</b>-<b>140</b> system. This cleaning may be accomplished by running an anti-malware application on the <b>130</b>-<b>140</b> system. However, if the infection is too severe for the anti-malware software to clean, or if the malware is undetectable by the user's anti-malware software, the user may wish to restore critical system files (or other user data files) for the <b>130</b>-<b>140</b> system from a protected image stored on M<b>1</b><b>100</b>, for example. It is of course understood that the critical system file image may be restored from another device, such as a removable drive or a CD, for example. The user may however consider it more convenient to restore the critical system files from an image on M<b>1</b><b>100</b>.
0061In accordance with a preferred embodiment of the present invention, an exemplary process for restoring M<b>2</b><b>130</b> from M<b>1</b><b>110</b> is illustrated by process <b>400</b> in <figref idref="DRAWINGS">FIG. 4</figref>. At step <b>410</b>, malware is detected or suspected to be infecting the <b>130</b>-<b>140</b> system. The user instructs P<b>1</b><b>120</b> to reload critical system files onto M<b>2</b><b>130</b> from a protected image on M<b>1</b><b>110</b>, at step <b>420</b>. Depending on the severity of the infection, P<b>1</b><b>120</b> may scan all or part of the data contained on M<b>2</b><b>130</b> for malware, and may scan all processes currently running on P<b>2</b><b>140</b>. The scan may be initiated by direct instructions from the user, or by stored configuration commands, for example (step <b>430</b>). P<b>1</b><b>120</b> may delete all or part of the data contained on M<b>2</b>. P<b>1</b><b>120</b> may also reset P<b>2</b><b>140</b> and/or delete the contents of any RAM communicatively coupled to P<b>2</b><b>140</b> (step <b>440</b>). Once the <b>130</b>-<b>140</b> system has been adequately cleaned, clean critical system files are loaded onto M<b>2</b><b>130</b> from any of the sources previously mentioned, preferably an image stored on M<b>1</b><b>110</b> (step <b>450</b>). The <b>130</b>-<b>140</b> may now be rebooted and/or reinitialized from the clean critical system files. In an extreme case where the malware resists deletion by the operating system, the user may elect to do a low level format on the M<b>1</b><b>110</b> memory in order to ensure that the malware infection has been cleaned.
0062In accordance with a preferred embodiment of the present invention, a user <b>160</b> may consider it advantageous for the <b>130</b>-<b>140</b> system to be automatically reinitialized from clean critical system files when a protected process window is opened. In this way, the new protected process is much less likely to be affected by an infection from a previous protected process session. Of course, a user may have a plurality of protected processes open and running during a protected process session. It may only be necessary to automatically reinitialize from clean critical system files when the first protected process is opened during a session. Subsequent protected processes may not require automatic re-initialization from clean critical system files. An exemplary automatic re-initialization from clean critical system files is illustrated by steps <b>510</b>, <b>520</b> and <b>530</b> in <figref idref="DRAWINGS">FIG. 5a</figref>. Additionally, processes running on P<b>2</b><b>140</b> may be automatically scanned and compared with an allowed process list, particularly as a protected process is started up. If any process is detected which is not on the allowed list, the user may be alerted that a possible malware infection has occurred. A user may then choose to scan or clean the system, or inspect the unknown process to determine if the process will be allowed to continue to execute. A user may also update the list of allowed processes from time to time as new, legitimate processes are added, for example, by a browser software update.
0063In accordance with a preferred embodiment of the present invention, a user <b>160</b> may consider it advantageous for the <b>130</b>-<b>140</b> system to be automatically cleaned when a protected process window is closed. In this way, any detected or undetected malware infections are much less likely to affect a future protected process session. It may only be necessary to automatically clean the <b>130</b>-<b>140</b> system when the last protected process is closed during a session. An exemplary automatic cleaning process is illustrated by steps <b>540</b>, <b>550</b>, <b>560</b>, <b>570</b> and <b>580</b> in <figref idref="DRAWINGS">FIG. 5b</figref>. The memory M<b>2</b><b>130</b> and processor P<b>2</b><b>140</b> may be automatically scanned for malware infections as the protected process session closes. Infected files may be deleted or quarantined automatically. Additionally, there may be a variety of files that a user may wish to have automatically cleaned or deleted upon closing a protected process session. For example, temporary internet files, cookies, browser plugins, etc., may be deleted or scanned for malware automatically. A user may also wish to have websites that contributed to a malware infection noted, and may wish to place the offending websites in a block list, such that the offending websites cannot be accessed in the future without the user specifically authorizing access. As part of the malware scan, the malware scanner may automatically log the offending website(s), and block future access. Also, the P<b>2</b><b>140</b> processor and any associated non-volatile memory may be reset and/or erased as the protected process session is closed. The exemplary automatic cleaning process illustrated in <figref idref="DRAWINGS">FIG. 5b</figref> may therefore reduce the risk of a malware infection being carried over to a future protected process session.
0064Interactive network processes such as interactive gaming have become very popular in recent years. In current interactive gaming processes, a user may log onto a game host located on network <b>195</b>, or connect to other computers whose users wish to participate in the game. Computer games, such as Quake 3. Arena, by Id Software Incorporated, or Call of Duty, by Activision Incorporated, are just two examples of the plethora of games available that may be played interactively over a network. The user's computer system typically provides the bulk of the processing power and video graphics generation required to display the often fast moving and richly detailed three dimensional game environments. Information about the current and new state of the game is exchanged between various users' computer systems, often in real time. With this type of process, a relatively modest amount of data is required to be exchanged between users, or a user and the host, with the bulk of the processing, data manipulation, and graphics generation being handled by the user's local machine. However, this open network connection may become a conduit for malware practitioners to exploit, allowing malware to be downloaded onto a user's computer during a gaming session, often without the user being aware of the malware transfer. It would be advantageous, therefore, for a computer system to be much less susceptible to malware attacks during gaming sessions.
0065In accordance with a preferred embodiment of the present invention, an exemplary process flow <b>600</b>, illustrated in <figref idref="DRAWINGS">FIG. 6</figref>, allows an interactive network process, such as online gaming, to be carried out on computer system <b>100</b>. A user initiates an interactive network process via 2<sup>nd </sup>processor P<b>2</b><b>140</b> (step <b>610</b>). P<b>2</b><b>140</b> receives interactive network process status data from network connection (step <b>620</b>). P<b>2</b><b>140</b> informs 1st processor P<b>1</b><b>120</b> that interactive network process status data is available (step <b>630</b>). P<b>1</b><b>120</b> retrieves interactive network process status data from P<b>2</b><b>140</b> and uses the status data to update the interactive network process and update video display (step <b>640</b>). P<b>1</b><b>120</b> then passes the updated interactive network process status data to P<b>2</b><b>140</b> (step <b>650</b>). P<b>2</b><b>140</b> then sends the updated interactive network process status data to the network via network connection <b>195</b> (step <b>660</b>). The exemplary process <b>600</b>, or a process functionally equivalent, is carried out continuously as long as the interactive process is running.
0066By using exemplary process <b>600</b> (or an equivalent), computer system <b>100</b> is capable of actively deciding what data to download and use, and what data to discard or scan for malware. The game status data is buffered prior to loading it onto the <b>110</b>-<b>120</b> system. The <b>110</b>-<b>120</b> system may be advantageously configured to only accept game status information in the proper format, thereby minimizing the chance that a malware practitioner could deceptively load malware onto the <b>110</b>-<b>120</b> system.
0067Additionally, computer system <b>100</b> could be configured such that system <b>130</b>-<b>140</b> is powerful enough to process the interactive network process without exchanging information with the <b>110</b>-<b>120</b> system. Such a configuration may be more secure, as a conduit between the <b>110</b>-<b>120</b> system and the <b>130</b>-<b>140</b> system may not be necessarily opened. The <b>130</b>-<b>140</b> system may contain all the necessary files to facilitate the interactive network process. Higher end computers, workstations, and servers often contain dual (or more) processors, such as the Mac G5, manufactured by the Apple Computer Corporation, or a single physical processor with a multiple processor core. Often, the processors in these multi-processor machines are of equal or comparable processing power. In such a configuration, one processor may be dedicated to performing functions equivalent to those described for P<b>1</b><b>120</b>, with a second processor performing the functions equivalent to those described for P<b>2</b><b>140</b>. A computer system <b>100</b> employing multiple processors may be advantageously configured such that one of the processors is dedicated to protected processes only when a network process is active. When a user is not accessing a network, the multiple processors in a computer system may be dedicated to other processes, such as performing complex calculations or simulations, or running complex non-network interactive gaming processes, for example. Alternatively, the computer system <b>100</b> may be configured such that the <b>110</b>-<b>120</b> system simply transfers required files to the video processor <b>170</b> or the <b>130</b>-<b>140</b> system at the appropriate time to facilitate the interactive network process. The <b>110</b>-<b>120</b> system could be commanded to retrieve and transfer the files at the command of the video processor, or at the command of the <b>130</b>-<b>140</b> system, or a combination of both.
0068In accordance with embodiments of the present invention, computer system <b>100</b> may be configured in a variety of ways, while still remaining within the spirit and scope of the present teachings. One such exemplary embodiment is illustrated in <figref idref="DRAWINGS">FIG. 7</figref>. Subsystem <b>700</b> of computer system <b>100</b> comprises a video processor <b>770</b>, a second processor <b>740</b>, and a second memory data storage area <b>730</b>. The demarcation line illustrated by subsystem <b>700</b> may be either physical or logical. For example, subsystem <b>700</b> may comprise an add-on card, such as a high end video card, or a video/network card. If configured in this exemplary manner, a user could upgrade an existing computer system to take advantage of the teachings of the present invention. Subsystem <b>700</b> may be plugged into the main motherboard of an existing computer, for example. The motherboard connector may be already communicatively coupled to the <b>110</b>-<b>120</b> system, thereby facilitating the system upgrade. The network interface device <b>190</b> may be connected directly to subsystem <b>700</b>, or network interface device <b>190</b> could be integrated as part of subsystem <b>700</b>. Memory data storage area <b>730</b> may comprise any of the volatile and/or non-volatile memory types previously described, or any combination thereof, or any suitable memory storage medium, for example. Alternatively, subsystem <b>700</b> may be located on the motherboard, as opposed to an add-on card. Further still, portions of subsystem <b>700</b>, such as video processor <b>770</b>, and/or second processor <b>740</b>, for example, may be integrated together with P<b>1</b><b>120</b>. It is understood that functions described herein may be configured in a wide variety of ways, without departing from the spirit and scope of the present teachings.
0069In accordance with a preferred embodiment of the present invention, an alternate configuration for computer system <b>100</b> is illustrated in <figref idref="DRAWINGS">FIG. 8</figref>. Subsystem <b>800</b> of computer system <b>100</b> comprises a video processor <b>870</b>, a second processor <b>840</b>, and a second memory data storage area <b>830</b>. The demarcation line illustrated by subsystem <b>800</b> may be either physical or logical. For example, subsystem <b>800</b> may comprise an add-on card, such as a high end video card, or a video/network card. If configured in this exemplary manner, a user could upgrade an existing computer system to take advantage of features of the present invention. In the exemplary embodiment of <figref idref="DRAWINGS">FIG. 8</figref>, second processor <b>840</b> and video processor <b>870</b> are integrated together, perhaps on a common integrated circuit. Such a configuration may help to reduce the cost of subsystem <b>800</b>, and/or improve the performance. Additionally, a circuit designer may find it advantageous to integrate <b>840</b> and <b>870</b> together to facilitate communication between the functions. It is understood that such an integration of functions may create a device in which an external user may find it difficult to distinguish where the function of <b>870</b> ends and the function of <b>840</b> begins, and vice versa. Such a device, however, would remain within the spirit and scope of the present teachings.
0070In accordance with a preferred embodiment of the present invention, an alternate configuration for computer system <b>100</b> is illustrated in <figref idref="DRAWINGS">FIG. 9</figref>. Computer system <b>100</b> comprises a video processor <b>970</b>, processor <b>960</b>, and a memory data storage area <b>950</b>. Processor <b>960</b> may further comprise multiple processor cores, illustrated by 1<sup>st </sup>processor <b>920</b> and 2<sup>nd </sup>processor <b>940</b>. It is understood that processor <b>960</b> may contain more than 2 processor cores. Microprocessors manufactured with multiple processor cores are becoming common in the industry, and such multi-core processors may be particularly advantageous when used in accordance with the present teachings. Memory data storage area <b>950</b> may further comprise 1<sup>st </sup>memory data storage area <b>910</b> and 2<sup>nd </sup>memory data storage area <b>930</b>. Memory areas <b>910</b> and <b>930</b> may comprise, for example, different partitions on a single hard drive, and/or different address ranges in a RAM bank.
0071Referring again to <figref idref="DRAWINGS">FIG. 9</figref>, the functions carried out by processors <b>920</b> and <b>940</b> may comprise separate, secure logical processes executing on the same physical processor. For example, a first logical process may comprise executing instructions necessary to carry out the functions of an operating system, or the first logical process may comprise executing instructions necessary to carry out the functions of a first computer program, including but not limited to a word processor. A second logical process may comprise executing instructions necessary to carry out the functions of a web browser program, or may comprise executing instructions necessary to carry out the functions of an instant messenger program, for example. A computer system <b>100</b> constructed in accordance with the principles of the present invention would be capable of disallowing a secure logical process, such as the second logical process described above, access to certain memory spaces, and/or disallowing a secure logical process from initiating access to another logical process. For example, the functions carried out by P<b>2</b><b>140</b> (<figref idref="DRAWINGS">FIG. 1</figref>) may comprise a secure logical process, which may be configured to be unable to automatically initiate access to either M<b>1</b><b>110</b> or another logical process performing the functions of P<b>1</b><b>120</b>. Additionally, memory areas <b>910</b> and <b>930</b> may comprise separate, isolated memory zones within a common physical memory space, such as separate partitions within the same hard drive, for example.
0072Some malware programs are designed to secretly record user input commands (such as keystrokes, for example), then send the information back to a host computer. This type of malware is capable of stealing important user information, such as passwords, bank account numbers, social security numbers, driver's license numbers, credit account numbers, etc. Theft of such personal information could result in the theft of actual assets (money or securities, etc.) or perhaps used for identity theft, among other malicious intents. Clearly, a computer system capable of ensuring the protection of such sensitive information would be desirable.
0073In accordance with an embodiment of the present invention, a computer system is configured such that attempts by malware to record and report data entry by the computer user via input devices such as keyboards, mouse clicks, microphones, or any other data input devices are effectively blocked. Encryption of user input data, such as keystrokes, is an effective means of protecting such data from theft by malware. Specific techniques used for data encryption and decryption are well known in the art, and need not be discussed further here. There are many examples in the art that may be examined to better understand various encryption/decryption techniques and the use of encryption/decryption in computer systems. Among these are U.S. Pat. No. 6,581,162 entitled “Method for securely creating, storing and using encryption keys in a computer system.” issued to Angelo, et al., and U.S. Pat. No. 6,134,661 entitled “Computer network security device and method.” Issued to Topp. The aforementioned patents have been previously incorporated by reference.
0074In accordance with the present teachings, a method of operating a computer system involving data encryption is described. In step <b>1010</b>, a user opens a protected process where some level of data encryption is desired, for example, the encryption of sensitive user interface data or user files. Other data may be encrypted as desired. At step <b>1020</b>, processor P<b>1</b><b>120</b> instructs processor P<b>2</b><b>140</b> to initiate a protected process and open a process window. P<b>1</b><b>120</b> encrypts the sensitive data and passes the user interface data to P<b>2</b><b>140</b> when a P<b>2</b><b>140</b> window is selected or active (step <b>1030</b>). P<b>2</b><b>140</b> generates video data for the P<b>2</b><b>140</b> process window(s) and passes the video data to video processor <b>170</b> (step <b>1040</b>). Video processor <b>170</b> decrypts the sensitive data and interleaves the video data from all P<b>1</b> and P<b>2</b> processes (step <b>1050</b>). P<b>2</b><b>140</b> passes the encrypted sensitive data to network interface device <b>190</b> (step <b>1060</b>). Network interface device <b>190</b> decrypts the sensitive data and passes the decrypted sensitive data to network <b>195</b>. Of course, other methods of operating a computer system in which data is encrypted prior to being passed to P<b>2</b><b>140</b>, and decrypted after leaving the control of P<b>2</b><b>140</b>, are within the spirit and scope of the present teachings.
0075In accordance with a preferred embodiment of the present invention, data desired to be protected is encrypted prior to sending the data to processor P<b>2</b><b>140</b>, which may be running one or more malware processes. Processor P<b>2</b><b>140</b> does not have visibility to the decryption keys, and is therefore unable to decrypt the data. Data may be decrypted by network interface device <b>190</b> prior to forwarding the data on to network <b>195</b>. Conversely, encrypted data may be sent directly over the network for decryption by another computer system, including, for example, an interne banking host computer. Decryption keys may be passed between P<b>1</b><b>120</b> and network interface device <b>190</b> via a communication link <b>191</b>. Video processor <b>170</b> may decrypt the data prior to displaying the data on video display <b>180</b>, with decryption keys possibly passed between P<b>1</b><b>120</b> and video processor <b>170</b> via a communication link <b>171</b>. Conversely, data may be passed directly to video processor <b>170</b> via a communication link <b>151</b>.
0076A user <b>160</b> may wish to encrypt just a portion of the data destined for the network, such as passwords, credit card numbers, etc. Conversely, a user may wish to encrypt large blocks of data, such as e-mails or large application files containing sensitive text and/or graphics. Instructions may be passed to network interface device <b>190</b> directing <b>190</b> to decrypt one or more specific data blocks prior to sending the data blocks to network <b>195</b>. Conversely, instructions may be passed to network interface device <b>190</b> directing <b>190</b> to pass one or more specific data blocks to network <b>195</b> without decryption.
0077While this invention has been described with reference to illustrative embodiments, this description is not intended to be construed in a limiting sense. Various modifications and combinations of the illustrative embodiments, as well as other embodiments of the invention, will be apparent to persons skilled in the art upon reference to the description. It is therefore intended that the appended claims encompass any such modifications or embodiments.
Contents7
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
Every citation, both waysCites: the store holds 113 of 114
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10061922B2 | Cited by | United States of America | Search report |
| US2013347114A1 | Cited by | United States of America | Pre-grant |
| US11188652B2 | Cited by | United States of America | Applicant |
| US9614839B2 | Cited by | United States of America | Applicant |
| US10592063B1 | Cited by | United States of America | Applicant |
| US11223634B2 | Cited by | United States of America | Applicant |
| US9781141B2 | Cited by | United States of America | Applicant |
| US9870116B1 | Cited by | United States of America | Applicant |
| US9672360B2 | Cited by | United States of America | Applicant |
| US9342695B2 | Cited by | United States of America | Applicant |
| US2002002673A1 | Cites | United States of America | Search report |
| US2002052809A1 | Cites | United States of America | Search report |
| US2002066016A1 | Cites | United States of America | Applicant |
| US2002174349A1 | Cites | United States of America | Applicant |
| US2003023857A1 | Cites | United States of America | Applicant |
| US2003097591A1 | Cites | United States of America | Applicant |
| US2003131152A1 | Cites | United States of America | Applicant |
| US2003177397A1 | Cites | United States of America | Applicant |
| US2003221114A1 | Cites | United States of America | Search report |
| US2004006706A1 | Cites | United States of America | Applicant |
| US2004006715A1 | Cites | United States of America | Applicant |
| US2004034794A1 | Cites | United States of America | Applicant |
| US2004039944A1 | Cites | United States of America | Search report |
| US2004054588A1 | Cites | United States of America | Applicant |
| US2004199763A1 | Cites | United States of America | Applicant |
| US2004230794A1 | Cites | United States of America | Search report |
| US2004267929A1 | Cites | United States of America | Search report |
| US2005005153A1 | Cites | United States of America | Search report |
| US2005091661A1 | Cites | United States of America | Search report |
| US2005149726A1 | Cites | United States of America | Search report |
| US2005198692A1 | Cites | United States of America | Search report |
| US2005240810A1 | Cites | United States of America | Applicant |
| US2006004667A1 | Cites | United States of America | Applicant |
| US4890098A | Cites | United States of America | Applicant |
| US5280579A | Cites | United States of America | Applicant |
| US5502808A | Cites | United States of America | Applicant |
| US5555364A | Cites | United States of America | Applicant |
| US5564051A | Cites | United States of America | Search report |
| US5666030A | Cites | United States of America | Applicant |
| US5673403A | Cites | United States of America | Search report |
| US5751979A | Cites | United States of America | Search report |
| US5826013A | Cites | United States of America | Applicant |
| US5918039A | Cites | United States of America | Applicant |
| US5974549A | Cites | United States of America | Search report |
| US5978917A | Cites | United States of America | Applicant |
| US5995103A | Cites | United States of America | Applicant |
| US6091412A | Cites | United States of America | Applicant |
| US6108715A | Cites | United States of America | Applicant |
| US6134661A | Cites | United States of America | Applicant |
| US6167522A | Cites | United States of America | Applicant |
| US6183366B1 | Cites | United States of America | Applicant |
| US6192477B1 | Cites | United States of America | Search report |
| US6199181B1 | Cites | United States of America | Search report |
| US6216112B1 | Cites | United States of America | Applicant |
| US6275938B1 | Cites | United States of America | Applicant |
| US6285987B1 | Cites | United States of America | Applicant |
| US6321337B1 | Cites | United States of America | Applicant |
| US6351816B1 | Cites | United States of America | Applicant |
| US6385721B1 | Cites | United States of America | Search report |
| US6397242B1 | Cites | United States of America | Applicant |
| US6401134B1 | Cites | United States of America | Applicant |
| US6433794B1 | Cites | United States of America | Applicant |
| US6438600B1 | Cites | United States of America | Applicant |
| US6480198B2 | Cites | United States of America | Applicant |
| US6492995B1 | Cites | United States of America | Applicant |
| US6505300B2 | Cites | United States of America | Applicant |
| US6507904B1 | Cites | United States of America | Applicant |
| US6507948B1 | Cites | United States of America | Applicant |
| US6546554B1 | Cites | United States of America | Applicant |
| US6553377B1 | Cites | United States of America | Applicant |
| US6578140B1 | Cites | United States of America | Search report |
| US6581162B1 | Cites | United States of America | Applicant |
| US6633963B1 | Cites | United States of America | Applicant |
| US6658573B1 | Cites | United States of America | Applicant |
| US6663000B1 | Cites | United States of America | Applicant |
| US6678712B1 | Cites | United States of America | Search report |
| US6678825B1 | Cites | United States of America | Applicant |
| US6691230B1 | Cites | United States of America | Applicant |
| US6735700B1 | Cites | United States of America | Applicant |
| US6754815B1 | Cites | United States of America | Search report |
| US6756236B2 | Cites | United States of America | Applicant |
| US6757685B2 | Cites | United States of America | Applicant |
| US6772345B1 | Cites | United States of America | Applicant |
| US6804780B1 | Cites | United States of America | Applicant |
| US6836885B1 | Cites | United States of America | Applicant |
| US6871348B1 | Cites | United States of America | Search report |
| US6873988B2 | Cites | United States of America | Applicant |
| US6880110B2 | Cites | United States of America | Applicant |
| US6990630B2 | Cites | United States of America | Applicant |
| US6996828B1 | Cites | United States of America | Search report |
| US7013484B1 | Cites | United States of America | Search report |
| US7024555B2 | Cites | United States of America | Search report |
| US7024581B1 | Cites | United States of America | Search report |
| US7039801B2 | Cites | United States of America | Search report |
| US7062672B2 | Cites | United States of America | Applicant |
| US7082615B1 | Cites | United States of America | Search report |
| US7085928B1 | Cites | United States of America | Applicant |
| US7096381B2 | Cites | United States of America | Applicant |
| US7139890B2 | Cites | United States of America | Applicant |
| US7146305B2 | Cites | United States of America | Search report |
7 members in 1 office
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 91360904 | United States of America | A | |
| 91360904 | United States of America | A | |
| 72020710 | United States of America | A | |
| 10913609 | – | – | – |
| US20040913609 | – | – | – |
| US20100720207 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| US2006031940A1 | United States of America | A1 | |
| US7484247B2 | United States of America | B2 | |
| USRE43103E | United States of America | E | |
| USRE43500EThis record | United States of America | E | |
| USRE43528E | United States of America | E | |
| USRE43529E | United States of America | E | |
| USRE43987E | United States of America | E |
72 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | |
|---|---|
| 11.5 yr surcharge- late pmt w/in 6 mo, Small Entity | |
| Payment of Maintenance Fee, 12th Yr, Small Entity | |
| Request for Trial Denied | |
| Request for Trial Denied | |
| Email Notification | |
| Change in Power of Attorney (May Include Associate POA) | |
| Correspondence Address Change | |
| Petition Requesting Trial | |
| Petition Requesting Trial | |
| Recordation of Patent Grant Mailed | |
| Email Notification | |
| Issue Notification MailedAllowed | |
| Dispatch to FDC | |
| Application Is Considered Ready for Issue | |
| Issue Fee Payment Verified | |
| Issue Fee Payment Received | |
| Electronic Review | |
| Email Notification | |
| Mail Notice of AllowanceAllowed | |
| Notice of Allowance Data Verification CompletedAllowed | |
| Oath or Declaration Filed (Including Supplemental) | |
| Date Forwarded to Examiner | |
| Disposal for a RCE / CPA / R129 | |
| Information Disclosure Statement considered | |
| Information Disclosure Statement (IDS) Filed | |
| Reference capture on IDS | |
| Information Disclosure Statement (IDS) Filed | |
| Request for Continued Examination (RCE) | |
| Workflow - Request for RCE - Begin | |
| Electronic Review | |
| Email Notification | |
| Mail Final Rejection (PTOL - 326)Final rejection | |
| Final RejectionFinal rejection | |
| Paralegal or electronic terminal disclaimer approved | |
| Terminal Disclaimer Filed | |
| Date Forwarded to Examiner | |
| Information Disclosure Statement considered | |
| Response after Non-Final Action | |
| Request for Extension of Time - Granted | |
| Reference capture on IDS | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Email Notification | |
| Change in Power of Attorney (May Include Associate POA) | |
| Correspondence Address Change | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Paralegal TD Not accepted | |
| Date Forwarded to Examiner | |
| Response after Non-Final Action | |
| Mail Examiner Interview Summary (PTOL - 413) | |
| Interview Summary Record | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Date Forwarded to Examiner | |
| Supplemental Response | |
| Information Disclosure Statement considered | |
| Electronic Information Disclosure Statement | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement considered | |
| Information Disclosure Statement considered | |
| Electronic Information Disclosure Statement | |
| Electronic Information Disclosure Statement | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Notice of Reissue Published in Official Gazette | |
| Case Docketed to Examiner in GAU | |
| Cleared by OIPE CSR | |
| Application Dispatched from OIPE | |
| Filing Receipt | |
| IFW Scan & PACR Auto Security Review | |
| Initial Exam Team nn |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Reexamination decision: claims changed and/or cancelledREEXAMINATION CERTIFICATE; THE PATENTABILITY OF CLAIMS 22-24, 31-33, 42-45 AND 66-71 IS CONFIRMED. CLAIMS 1-20 WERE PREVIOUSLY CANCELLED. CLAIMS 21, 25-30, 34-41 AND 46-65 ARE CANCELLED.LIMR | LIMR | |
| Fee payment procedure11.5 YR SURCHARGE- LATE PMT W/IN 6 MO, SMALL ENTITY (ORIGINAL EVENT CODE: M2556); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Request for reexamination filedRR | RR | |
| Aia trial proceeding filed before patent trial and appeal board: covered business methodsAppealCBM | CBM | |
| Aia trial proceeding filed before patent trial and appeal board: covered business methodsAppealCBM | CBM | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- RE043500
- Publication, DOCDB
- RE43500
- Publication, EPODOC
- USRE43500E
- Application
- 12720207
- Application, DOCDB
- 72020710
- Application, EPODOC
- US20100720207
Titles
- English
- System and method for protecting a computer system from malicious software
Classification
- CPC, 5
- H04L63/02
- G06F21/53
- G06F21/568
- G06F21/57
- H04L63/1408
- IPC, 5
- H04L29 06
- G06F11 00
- G06F12 14
- G06F12 16
- G08B23 00
- USPC, 6
- 713152000
- 713151000
- 713188000
- 726022000
- 726023000
- 726024000