Patents Assigned to Trusteer Ltd.
-
Publication number: 20150235026Abstract: A process for finding potentially harmful malware dropper on an infected computer system includes the steps of a) identifying an executable file that is about to run, and b) providing a storage agent that stores a copy of said executable file for a later inspection.Type: ApplicationFiled: February 17, 2014Publication date: August 20, 2015Applicant: Trusteer Ltd.Inventor: Amit Klein
-
Patent number: 9081956Abstract: A method for protecting a browser from malicious processes, comprises providing at least one process-proxy object and at least a browser-proxy object, interposed between the browser and a process, such that when the process invokes one of the DOM entry points, the process-proxy object isolates it from the real browser implementation and executes the process-proxy object's code instead.Type: GrantFiled: May 22, 2009Date of Patent: July 14, 2015Assignee: Trusteer Ltd.Inventors: Amit Klein, Eldan Ben-Haim, Oleg Izmerly, Shmuel Regev, Michael Boodaei
-
Publication number: 20150178374Abstract: The present disclosure relates to a method of providing user categorization from computer pointer interaction, comprising the steps of: creating a plurality of different pointer data profiles based on initial user sessions and storing said created pointer data profiles in the form of pointer data profile entries in a pointer data profile database, wherein said pointer data profile is obtained from collected user activity data generated by a pointing device; and categorizing each user using the stored pointer data profiles at an onset of subsequent user sessions.Type: ApplicationFiled: December 23, 2013Publication date: June 25, 2015Applicant: TRUSTEER LTD.Inventors: Ofer Rahat, Ron Peleg, Ayman Jarrous, Shmuel Regev
-
Publication number: 20150128206Abstract: A method for providing early filtering of events using a kernel-based filter, comprising the steps of: a) providing a driver for the kernel level that acts as a kernel filtering process, wherein said driver is configured to match events that occur at the kernel level according to predefined rules; and b) upon finding a match, acting according to the definition of the matched rule in order to allow the event, disallow said event or forward the content of said event for further processing.Type: ApplicationFiled: November 4, 2013Publication date: May 7, 2015Applicant: TRUSTEER LTD.Inventors: Eldan Ben Haim, Ilan Fraiman, Arkady Dubovsky
-
Patent number: 8863281Abstract: A method for protecting a browser from malicious processes, comprises providing at least one process-proxy object and at least a browser-proxy object, interposed between the browser and a process, such that when the process invokes one of the DOM entry points, the process-proxy object isolates it from the real browser implementation and executes the process-proxy object's code instead.Type: GrantFiled: May 22, 2009Date of Patent: October 14, 2014Assignee: Trusteer Ltd.Inventors: Amit Klein, Eldan Ben-Haim, Oleg Izmerly, Shmuel Regev, Michael Boodaei
-
Publication number: 20140289851Abstract: A process for identifying potentially harmful malware, comprises the steps of: a) identifying an executable that is about to run; b) providing a monitoring agent that monitors all threads that are descendent of a thread initiated by the process of said executable; and c) configuring said monitoring agent to conclude that a high probability of malware presence exists, if one of said descendent threads reaches a target process in which suspicious patches are created.Type: ApplicationFiled: March 19, 2013Publication date: September 25, 2014Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Yaron DYCIAN, Gal FRISHMAN, Avner GIDEONI
-
Patent number: 8813224Abstract: A method for protecting a browser from malicious processes, comprises providing at least one process-proxy object and at least a browser-proxy object, interposed between the browser and a process, such that when the process invokes one of the DOM entry points, the process-proxy object isolates it from the real browser implementation and executes the process-proxy object's code instead.Type: GrantFiled: May 22, 2009Date of Patent: August 19, 2014Assignee: Trusteer Ltd.Inventors: Amit Klein, Eldan Ben-Haim, Oleg Izmerly, Shmuel Regev, Michael Boodaei
-
Patent number: 8732794Abstract: A browser plug-in firewall manages data exchanged between a browser and a plug-in according to a pre-defined list of rights.Type: GrantFiled: August 11, 2008Date of Patent: May 20, 2014Assignee: Trusteer Ltd.Inventors: Michael Boodaei, Amit Klein, Oleg Izmerly
-
Patent number: 8725636Abstract: A method detects fraudulent transaction of money transfer to a mule account, according to which a detection software module is injected into a browser or a website to be protected. The detection module traces the content and the activities performed on a webpage of the website and detects any exceptional activity/condition which may be fraudulent online activity performed by malware and waits until all sensitive data to perform a fraud transaction is entered. Then the detection module stores and/or forwards the details of the mule account that has been used for the fraudulent transaction.Type: GrantFiled: October 22, 2012Date of Patent: May 13, 2014Assignee: Trusteer Ltd.Inventors: Amit Klein, Michael Boodaei
-
Publication number: 20140130152Abstract: A method for defending a computer system comprising a DNS server against a DoS or a DDoS attack directed at said DNS server comprises replacing the address of said system provided by a user to a client software with an alternative address, wherein said address is replaced by a software agent associated with said user, such that said client software is capable of connecting with said system.Type: ApplicationFiled: November 7, 2012Publication date: May 8, 2014Applicant: TRUSTEER LTD.Inventor: Michael Boodaei
-
Publication number: 20140114843Abstract: A method detects fraudulent transaction of money transfer to a mule account, according to which a detection software module is injected into a browser or a website to be protected. The detection module traces the content and the activities performed on a webpage of the website and detects any exceptional activity/condition which may be fraudulent online activity performed by malware and waits until all sensitive data to perform a fraud transaction is entered. Then the detection module stores and/or forwards the details of the mule account that has been used for the fraudulent transaction.Type: ApplicationFiled: October 22, 2012Publication date: April 24, 2014Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Michael BOODAEI
-
Publication number: 20140053267Abstract: In a computer system, a method detects a suspected malware behavior. Activities on a computer system conducted within a given time frame are monitored during the installation of a suspected file. The monitored activities are recorded and the monitored/recorded activities are compared with patterns of malware behavior, stored in a database. Upon detecting a suspicious program, the recorded monitored activities are provided for further analysis to be performed by appropriate software removal tools.Type: ApplicationFiled: August 20, 2012Publication date: February 20, 2014Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Mickey Boodaei
-
Patent number: 8595836Abstract: A method for preventing malicious attacks on software, using the patching method, includes providing a database of malicious known patches (malware). The database contains characteristic signatures of the malware. The method also includes detecting whether a patch is malicious by comparing it with a signature in the database and performing one or more activities needed to prevent the malicious patch from performing undesired activities.Type: GrantFiled: August 3, 2011Date of Patent: November 26, 2013Assignee: Trusteer Ltd.Inventors: Amit Klein, Oleg Izmerly, Shmuel Regev, Eldan Ben-Haim
-
Publication number: 20130263264Abstract: A method for alerting a service provider and/or a user of a web browser of a phishing attempt comprises providing on a page that it is desired to protect against phishing, a Javascript that when caused by a phishing page to run not in the context of the original page generates an indication that a phishing attempt may exist.Type: ApplicationFiled: April 2, 2012Publication date: October 3, 2013Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Michael BOODAEI
-
Publication number: 20130239214Abstract: A method for detecting and removing a suspicious software code in a computer system, according to which the installation process of the suspicious software code is monitored by a client agent residing within the computer system where predetermined operations of the suspicious software code are identified and registered during the installation process. The predetermined operations are compared with a known software code in order to define whether the software code is similar to the known software code. It is then determined if the suspicious software code is malware and if it is, the client agent is instructed to uninstall the suspicious software code from the OS, or to remove its entry from the boot registry.Type: ApplicationFiled: March 6, 2012Publication date: September 12, 2013Applicant: TRUSTEER LTD.Inventors: Amit Klein, Mickey Boodaei
-
Publication number: 20130198842Abstract: System and method for determining, by a security application, whether an examined software code is a malware, according to which the system detects whenever the examined process code performs system calls and further detects a call site. Pieces of code in the surrounding area of the site and/or in branches related to the site are analyzed and the properties of the analyzed pieces of code are compared with a predefined software code patterns, for determining whether the examined process code corresponds to one of the predefined software code patterns. Then the examined process code is classified according to the comparison results.Type: ApplicationFiled: January 31, 2012Publication date: August 1, 2013Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Eldan BEN-HAIM, Gal FRISHMAN
-
Patent number: 8239940Abstract: A method for preventing malicious attacks on software, using the patching method, includes providing a database of legitimate and known patches, the database contains characteristic code paths of said legitimate patches. The method also includes detecting whether a patch is malicious by inspecting one or more characteristic paths of the patch and matching one or more code paths against the database of legitimate and known patches. An activity needed to prevent the malicious patch from performing undesired activities is then performed.Type: GrantFiled: August 7, 2009Date of Patent: August 7, 2012Assignee: Trusteer Ltd.Inventors: Amit Klein, Oleg Izmerly, Shmuel Regev, Eldan Ben-Haim
-
Publication number: 20120030762Abstract: A method for preventing malicious attacks on software, using the patching method, includes providing a database of malicious known patches (malware). The database contains characteristic signatures of the malware. The method also includes detecting whether a patch is malicious by comparing it with a signature in the database and performing one or more activities needed to prevent the malicious patch from performing undesired activities.Type: ApplicationFiled: August 3, 2011Publication date: February 2, 2012Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Oleg Izmerly, Shmuel Regev, Eldan Ben-Haim
-
Publication number: 20110239300Abstract: A method for detecting HTML-modifying malware present in a computer includes providing a server which serves a web page (HTML) to a browser. A determination is made whether a modified string exists in the page received by said browser and if a modifying element is found, determining the malware is present in the computer.Type: ApplicationFiled: November 1, 2010Publication date: September 29, 2011Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Michael Boodaei
-
Publication number: 20100169969Abstract: A method for preventing malicious attacks on software, using the patching method, includes providing a database of legitimate and known patches, the database contains characteristic code paths of said legitimate patches. The method also includes detecting whether a patch is malicious by inspecting one or more characteristic paths of the patch and matching one or more code paths against the database of legitimate and known patches. An activity needed to prevent the malicious patch from performing undesired activities is then performed.Type: ApplicationFiled: August 7, 2009Publication date: July 1, 2010Applicant: TRUSTEER LTD.Inventors: Amit KLEIN, Oleg Izmerly, Shmuel Regev, Eldan Ben-Haim