Computer program, method, and system for preventing execution of viruses and malware
Abstract
Preventing execution of viruses or malware on a computing device includes compiling an inventory recordation of legitimate applications while in a training mode and terminating execution of any application not on the inventory recordation while in a protected mode. A user may train the computer program to identify legitimate applications routinely accessed by the user and to be updated to the inventory recordation, such that the inventory recordation is personal to the user. After training, the protected mode is activated. While an Internet browser or e-mail client application is activated while in the protected mode, execution of any accessed application that is not uniquely identified on the inventory recordation is terminated.
Claims
exact text as granted — not AI-modified1 . A non-transitory computer-readable storage medium with an executable program stored thereon for preventing execution of a virus or malware on a computing device, wherein the program instructs a processor to perform the steps of:
compile an inventory recordation personal to a user, wherein the inventory recordation comprises information uniquely identifying a listing of applications approved for execution by the processor during use of the program by the user in a protected mode, wherein said step of compiling an inventory recordation further comprises instructing the processor to perform the steps of—
receive an instruction from the user to selectively activate a training mode, wherein upon activation of the training mode, the program will execute any application instructed by the user and regardless of whether the inventory recordation comprises information uniquely identifying the requested application,
receive information identifying at least one application requested by the user to be executed by the computing device, and
update the inventory recordation to include the information identifying the at least one requested application;
activate the protected mode, such that upon activation of the protected mode, the training mode is automatically deactivated; receive, while the protected mode is activated, information indicative of an instruction by the user to execute an unconfirmed application, wherein the information indicative of an instruction by the user to execute an unconfirmed application includes information identifying the unconfirmed application; compare the information identifying the unconfirmed application with information identifying the listing of applications on the inventory recordation that are approved for execution; identify the unconfirmed application as an application approved for execution if the information identifying the unconfirmed application matches with information identifying an application on the inventory recordation; and identify the unconfirmed application as an application not approved for execution if the information identifying the unconfirmed application does not match with information identifying an application on the inventory recordation.
2 . The computer-readable storage medium of claim 1 , wherein the program instructs the processor to perform the step of instructing an operating system of the computing device executing the program to terminate execution of the application upon the unconfirmed application being identified as an application not approved for execution.
3 . The computer-readable storage medium of claim 2 , wherein the user is not required to respond to a prompt or to affirmatively instruct the operating system executing the program to prevent execution of the unconfirmed application.
4 . The computer-readable storage medium of claim 1 , wherein the program instructs the processor to perform the step of automatically preventing execution of the application by the processor upon the unconfirmed application being identified as an application not approved for execution.
5 . The computer-readable storage medium of claim 1 , wherein during said training mode, the program allows execution of any application for which it receives instructions by the user to execute, regardless of whether the application is identified on the inventory recordation.
6 . The computer-readable storage medium of claim 5 , wherein during said protected mode, the program allows execution of only the applications listed on the inventory recordation.
7 . The computer-readable storage medium of claim 5 , wherein during said protected mode, the program monitors whether an Internet browser or e-mail client application is executed, and if such Internet browser or e-mail client application is executed, the computer program allows execution of only the applications listed on the inventory recordation, and if such Internet browser or e-mail client application is not executed, the computer program allows execution of any application, regardless of whether the application is identified on the inventory recordation.
8 . The computer-readable storage medium of claim 7 , wherein the inventory recordation is only updated to include the application while the training mode is activated or while an Internet browser or e-mail client application is not running when the protected mode is activated.
9 . The computer-readable storage medium of claim 1 , wherein prior to compiling the inventory recordation personal to the user, the program instructs the processor to perform the step of determining an activated program mode, wherein the training mode and the protected mode are both program modes.
10 . The computer-readable storage medium of claim 1 , wherein the program instructs the processor to perform the steps of monitoring an elapsed period of time that the training mode is activated or that the computing device is idle, and upon the elapsed period of time being equal to or greater than a pre-set training time, presenting to the user a prompt to activate the protected mode.
11 . The computer-readable storage medium of claim 1 , wherein the training mode is a first program mode, the protected mode is a second program mode, and further including a third program mode comprising an off mode, wherein when said off mode is activated, the program allows execution of any application, regardless of whether it is identified on the inventory recordation, and the elapsed period of time is not monitored.
12 . The computer-readable storage medium of claim 1 , wherein the inventory recordation further includes an administrator listing that identifies application for which the user did not attempt to execute during activation of the training mode.
13 . The computer-readable storage medium of claim 1 , wherein the computer program is represented on a display of the computing device via an icon, and selection of the icon by left or right-clicking a user interface presents a menu of user-selectable options for instructing the computer program.
14 . A method for preventing execution of a virus or an item of malware on a computing device, wherein the method comprising the steps of:
receiving an instruction from the user to selectively activate a training mode of a computer program; receiving information identifying at least one computer application requested by the user to be executed by the computing device; updating an inventory recordation to include the information identifying the at least one requested application, wherein the inventory recordation comprises information uniquely identifying a listing of applications approved for execution by the computing device during use of the program by the user in a protected mode, wherein upon activation of the training mode, executing any application requested by the user and regardless of whether the inventory recordation comprises information uniquely identifying the requested application; activating the protected mode of the computer program, such that upon activation of the protected mode, the training mode is automatically deactivated; receiving, while the protected mode is activated, information indicative of an instruction by the user to execute an unconfirmed application, wherein the information indicative of an instruction by the user to execute an unconfirmed application includes information identifying the unconfirmed application; comparing the information identifying the unconfirmed application with information identifying the listing of applications on the inventory recordation that are approved for execution; identifying the unconfirmed application as an application approved for execution if the information identifying the unconfirmed application matches with information identifying an application on the inventory recordation; and identifying the unconfirmed application as an application not approved for execution if the information identifying the unconfirmed application does not match with information identifying an application on the inventory recordation.
15 . The method of claim 14 , further including the step of instructing an operating system of the computing device executing the program to terminate execution of the application upon the unconfirmed application being identified as an application not approved for execution.
16 . The method of claim 15 , wherein the user is not required to respond to a prompt or to affirmatively instruct the operating system executing the program to prevent execution of the unconfirmed application.
17 . The method of claim 14 , further including the step of automatically preventing execution of the application by the processor upon the unconfirmed application being identified as an application not approved for execution.
18 . The method of claim 14 , wherein the inventory recordation is only updated to include the application while the training mode is activated.
19 . The method of claim 14 , wherein prior to compiling the inventory recordation personal to the user, determining an activated program mode, wherein the training mode and the protected mode are both program modes.
20 . The method of claim 14 , further including the steps of monitoring an elapsed period of time that the training mode is activated or that the computing device is idle, and upon the elapsed period of time being equal to or greater than a pre-set training time, presenting to the user a prompt to activate the protected mode.Join the waitlist — get patent alerts
Track US2012311710A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.