US2014020104A1PendingUtilityA1

System and Method of Opportunistically Protecting a Computer from Malware

Assignee: MICROSOFT CORPPriority: May 16, 2005Filed: Sep 13, 2013Published: Jan 16, 2014
Est. expiryMay 16, 2025(expired)· nominal 20-yr term from priority
H04L 63/1433H04L 63/1416G06F 2221/2115G06F 21/568G06F 21/577G06F 21/56
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention provides a system, method, and computer-readable medium that opportunistically install a software update on a computer that closes a vulnerability that existed on the computer. In accordance with one aspect of the present invention, when antivirus software on a computer identifies malware, a method causes a software update that closes the vulnerability exploited by the malware to be installed on the computer. The method includes identifying the vulnerability exploited by the malware, using a software update system to obtain a software update that is configured to close the vulnerability; and causing the software update to be installed on the computer where the vulnerability exists.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . A method performed on a computing device, the method comprising:
 detecting malware infecting the computing device;   identifying, in response to the detecting, a vulnerability exploited to infect the computing device with the detected malware;   obtaining, in response to the detecting and the identifying, a patch that corresponds to the detected malware and to the identified vulnerability; and   installing the obtained patch on the computing device.   
     
     
         2 . The method of  claim 1  further comprising sending data that corresponds to the detected malware and the computing device to a service that is a trusted entity. 
     
     
         3 . The method of  claim 2  further comprising receiving, in response to the sending, information corresponding to the vulnerability exploited to infect the computing device with the detected malware. 
     
     
         4 . The method of  claim 3  where the identifying is further in response to the receiving. 
     
     
         5 . The method of  claim 1  where the obtaining the patch is from a service that is a trusted entity. 
     
     
         6 . The method of  claim 1  where the patch is configured for closing the identified vulnerability. 
     
     
         7 . The method of  claim 1  where the identifying comprises mapping, by the computing device, the vulnerability to the detected malware. 
     
     
         8 . At least one computer-readable storage device storing computer-executable instructions that, when executed by a computing device, cause the computing device to perform actions comprising:
 detecting malware infecting the computing device;   identifying, in response to the detecting, a vulnerability exploited to infect the computing device with the detected malware;   obtaining, in response to the detecting and the identifying, a patch that corresponds to the detected malware and to the identified vulnerability; and   installing the obtained patch on the computing device.   
     
     
         9 . The at least one computer-readable storage device of  claim 8 , the actions further comprising sending data that corresponds to the detected malware and the computing device to a service that is a trusted entity. 
     
     
         10 . The at least one computer-readable storage device of  claim 9 , the actions further comprising receiving, in response to the sending, information corresponding to the vulnerability exploited to infect the computing device with the detected malware. 
     
     
         11 . The at least one computer-readable storage device of  claim 10  where the identifying is further in response to the receiving. 
     
     
         12 . The at least one computer-readable storage device of  claim 8  where the obtaining the patch is from a service that is a trusted entity. 
     
     
         13 . The at least one computer-readable storage device of  claim 8  where the patch is configured for closing the identified vulnerability. 
     
     
         14 . The at least one computer-readable storage device of  claim 1  where the identifying comprises mapping, by the computing device, the vulnerability to the detected malware. 
     
     
         15 . A system comprising a first computing device and at least one program module together configured for performing actions comprising:
 detecting malware infecting the computing device;   identifying, in response to the detecting, a vulnerability exploited to infect the computing device with the detected malware;   obtaining, in response to the detecting and the identifying, a patch that corresponds to the detected malware and to the identified vulnerability; and   installing the obtained patch on the computing device.   
     
     
         16 . The system of  claim 15  further comprising sending data that corresponds to the detected malware and the computing device to a service that is a trusted entity. 
     
     
         17 . The system of  claim 16  further comprising receiving, in response to the sending, information corresponding to the vulnerability exploited to infect the computing device with the detected malware, and where the identifying is further in response to the receiving. 
     
     
         18 . The system of  claim 15  where the obtaining the patch is from a service that is a trusted entity. 
     
     
         19 . The system of  claim 15  where the patch is configured for closing the identified vulnerability. 
     
     
         20 . The system of  claim 15  where the identifying comprises mapping, by the computing device, the vulnerability to the detected malware.

Join the waitlist — get patent alerts

Track US2014020104A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.