Patents by Inventor Mark Obrecht

Mark Obrecht has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8931097
    Abstract: Techniques for categorizing programs running on an information handling system. One method includes, while a program is running on an information handling system in a manner that permits the program to infect the information handling system, calculating a first score and a second score. The first score is indicative of the likelihood that the program is malicious; the second score is indicative of the likelihood that the program is valid. This method further includes categorizing the program with respect to the likelihood of the program infecting the information handling system, including by categorizing the program as valid code based on the second score being above a threshold value, regardless of the first score.
    Type: Grant
    Filed: April 9, 2012
    Date of Patent: January 6, 2015
    Assignee: Symantec Corporation
    Inventors: Michael Tony Alagna, Mark Obrecht, Andy Payne, Peter Norwood
  • Patent number: 8615805
    Abstract: A method for classifying a process that modifies a registry attribute is described. At least one attribute associated with a registry is monitored. A determination is made that the at least one attribute has been modified. The process that modified the at least one attribute is identified. One or more characteristics of the identified process is evaluated. The identified process is classified based on the evaluation of the one or more characteristics of the identified process.
    Type: Grant
    Filed: September 3, 2008
    Date of Patent: December 24, 2013
    Assignee: Symantec Corporation
    Inventors: Mark Obrecht, Shane Pereira
  • Patent number: 8341744
    Abstract: Behavioral blocking of overlay-type identity stealers is achieved by detecting a transactional web page session, evaluating a property of a window corresponding to a process running on the computer system, and then, based on a result of the evaluation, blocking a behavior of the process for a duration of the transactional web page session. The evaluation of the property window involves determining whether the window exhibits one or more characteristics representing activity of an overlay-type identity stealer.
    Type: Grant
    Filed: December 29, 2006
    Date of Patent: December 25, 2012
    Assignee: Symantec Corporation
    Inventors: Mark Obrecht, Zhixiong Wu
  • Publication number: 20120198552
    Abstract: Techniques for categorizing programs running on an information handling system. One method includes, while a program is running on an information handling system in a manner that permits the program to infect the information handling system, calculating a first score and a second score. The first score is indicative of the likelihood that the program is malicious; the second score is indicative of the likelihood that the program is valid. This method further includes categorizing the program with respect to the likelihood of the program infecting the information handling system, including by categorizing the program as valid code based on the second score being above a threshold value, regardless of the first score.
    Type: Application
    Filed: April 9, 2012
    Publication date: August 2, 2012
    Applicant: SYMANTEC CORPORATION
    Inventors: Michael Tony Alagna, Mark Obrecht, Andy Payne, Peter Norwood
  • Patent number: 8205217
    Abstract: Systems and methods for configuring a specific-use computing system are disclosed. A computing system may comprise a first set of predetermined application programs and a processor limited to executing the first set of predetermined application programs and pre-approved application programs received from a pre-approved computing device. The computing system may also include a communication interface configured to enable communication between the first computing system and the pre-approved computing device. Exemplary methods and computer-readable media are also enclosed.
    Type: Grant
    Filed: September 29, 2007
    Date of Patent: June 19, 2012
    Assignee: Symantec Corporation
    Inventors: Mark Kennedy, Mark Obrecht
  • Patent number: 8156552
    Abstract: A method for implementing an online transaction security product includes downloading an online transaction security product program from a web site to an information handling system. The security product program includes an anti-malicious code program configured to detect malicious code on the information handling system. Lastly, the security product program is executed, wherein the anti-malicious code program of the security product program operates to detect malicious code on the information handling system.
    Type: Grant
    Filed: February 11, 2008
    Date of Patent: April 10, 2012
    Assignee: Symantec Corporation
    Inventors: Michael Tony Alagna, Mark Obrecht, Andy Payne, Peter Norwood
  • Patent number: 7930751
    Abstract: A method for detecting malicious code on an information handling system includes executing malicious code detection code (MCDC) on the information handling system. The malicious code detection code includes detection routines. The detection routines are applied to executable code under investigation running on the information handling system during the execution of the MCDC. The detection routines associate weights to respective executable code under investigation in response to detections of a valid program or malicious code as a function of respective detection routines. Lastly, executable code under investigation is determined a valid program or malicious code as a function of the weights associated by the detection routines. Computer-readable media and an information handling system are also disclosed.
    Type: Grant
    Filed: February 27, 2009
    Date of Patent: April 19, 2011
    Assignee: Symantec Corporation
    Inventors: Mark Obrecht, Michael Tony Alagna, Andy Payne
  • Patent number: 7748039
    Abstract: A method for detecting malicious code on an information handling system includes executing malicious code detection code (MCDC) on the information handling system. The malicious code detection code includes detection routines. The detection routines are applied to executable code under investigation running on the information handling system during the execution of the MCDC. The detection routines associate weights to respective executable code under investigation in response to detections of a valid program or malicious code as a function of respective detection routines. Lastly, executable code under investigation is determined a valid program or malicious code as a function of the weights associated by the detection routines. Computer-readable media and an information handling system are also disclosed.
    Type: Grant
    Filed: August 30, 2002
    Date of Patent: June 29, 2010
    Assignee: Symantec Corporation
    Inventors: Mark Obrecht, Michael Tony Alagna, Andy Payne
  • Publication number: 20100095379
    Abstract: A method for detecting malicious code on an information handling system includes executing malicious code detection code (MCDC) on the information handling system. The malicious code detection code includes detection routines. The detection routines are applied to executable code under investigation running on the information handling system during the execution of the MCDC. The detection routines associate weights to respective executable code under investigation in response to detections of a valid program or malicious code as a function of respective detection routines. Lastly, executable code under investigation is determined a valid program or malicious code as a function of the weights associated by the detection routines. Computer-readable media and an information handling system are also disclosed.
    Type: Application
    Filed: February 27, 2009
    Publication date: April 15, 2010
    Inventors: Mark Obrecht, Michael Tony Alagna, Andy Payne
  • Publication number: 20090089814
    Abstract: Systems and methods for configuring a specific-use computing system are disclosed. A computing system may comprise a first set of predetermined application programs and a processor limited to executing the first set of predetermined application programs and pre-approved application programs received from a pre-approved computing device. The computing system may also include a communication interface configured to enable communication between the first computing system and the pre-approved computing device. Exemplary methods and computer-readable media are also enclosed.
    Type: Application
    Filed: September 29, 2007
    Publication date: April 2, 2009
    Inventors: Mark Kennedy, Mark Obrecht
  • Publication number: 20080209561
    Abstract: A method for implementing an online transaction security product includes downloading an online transaction security product program from a web site to an information handling system. The security product program includes an anti-malicious code program configured to detect malicious code on the information handling system. Lastly, the security product program is executed, wherein the anti-malicious code program of the security product program operates to detect malicious code on the information handling system.
    Type: Application
    Filed: February 11, 2008
    Publication date: August 28, 2008
    Inventors: Michael Tony Alagna, Mark Obrecht, Andy Payne, Peter Norwood
  • Patent number: 7331062
    Abstract: A method for implementing an online transaction security product includes downloading an online transaction security product program from a web site to an information handling system. The security product program includes an anti-malicious code program configured to detect malicious code on the information handling system. Lastly, the security product program is executed, wherein the anti-malicious code program of the security product program operates to detect malicious code on the information handling system.
    Type: Grant
    Filed: February 4, 2003
    Date of Patent: February 12, 2008
    Assignee: Symantec Corporation
    Inventors: Michael Tony Alagna, Mark Obrecht, Andy Payne, Peter Norwood
  • Publication number: 20040098607
    Abstract: A method for implementing an online transaction security product includes downloading an online transaction security product program from a web site to an information handling system. The security product program includes an anti-malicious code program configured to detect malicious code on the information handling system. Lastly, the security product program is executed, wherein the anti-malicious code program of the security product program operates to detect malicious code on the information handling system.
    Type: Application
    Filed: February 4, 2003
    Publication date: May 20, 2004
    Applicant: WholeSecurity, Inc.
    Inventors: Michael Tony Alagna, Mark Obrecht, Andy Payne, Peter Norwood
  • Publication number: 20040054917
    Abstract: A method for detecting malicious code on an information handling system includes executing malicious code detection code (MCDC) on the information handling system. The malicious code detection code includes detection routines. The detection routines are applied to executable code under investigation running on the information handling system during the execution of the MCDC. The detection routines associate weights to respective executable code under investigation in response to detections of a valid program or malicious code as a function of respective detection routines. Lastly, executable code under investigation is determined a valid program or malicious code as a function of the weights associated by the detection routines. Computer-readable media and an information handling system are also disclosed.
    Type: Application
    Filed: August 30, 2002
    Publication date: March 18, 2004
    Applicant: WholeSecurity, Inc.
    Inventors: Mark Obrecht, Michael Tony Alagna, Andy Payne