Processing

Please wait...

Settings

Settings

Goto Application

Offices all Languages en Stemming true Single Family Member false Include NPL true
RSS feed can only be generated if you have a WIPO account

Save query

A private query is only visible to you when you are logged-in and can not be used in RSS feeds

Query Tree

Refine Options

Offices
All
Specify the language of your search keywords
Stemming reduces inflected words to their stem or root form.
For example the words fishing, fished,fish, and fisher are reduced to the root word,fish,
so a search for fisher returns all the different variations
Returns only one member of a family of patents
Include Non-Patent literature in results

Full Query

Marc Seinfeld AND Microsoft

Side-by-side view shortcuts

General
Go to Search input
CTRL + SHIFT +
Go to Results (selected record)
CTRL + SHIFT +
Go to Detail (selected tab)
CTRL + SHIFT +
Go to Next page
CTRL +
Go to Previous page
CTRL +
Results (First, do 'Go to Results')
Go to Next record / image
/
Go to Previous record / image
/
Scroll Up
Page Up
Scroll Down
Page Down
Scroll to Top
CTRL + Home
Scroll to Bottom
CTRL + End
Detail (First, do 'Go to Detail')
Go to Next tab
Go to Previous tab

Analysis

1.20120324578Mobile device operations with battery optimization
US 20.12.2012
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No 13162133 Applicant Marc Seinfeld Inventor Marc Seinfeld

Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.

2.20160285900Scanning files for inappropriate content during synchronization
US 29.09.2016
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 15173580 Applicant Microsoft Technology Licensing, LLC Inventor Marc E. Seinfeld

The present invention extends to methods, systems, and computer program products for scanning files for inappropriate content during file synchronization. Embodiments of the invention are mindful of the order of operations when scanning files for inappropriate content and in subsequent file processing. In some embodiments, during synchronization, an intermediary server scans a file for inappropriate content. The file is not permitted to be fully downloaded to a client device until the scan determines that the file does not contain inappropriate content. In other embodiments, during synchronization, a client device scans a newer version of a file for inappropriate content. An older version of the file is not deleted until the scan determines that the newer version of the file does not contain inappropriate content. In further embodiments, server side scanning and client side scanning are both used to enhance capabilities for detecting inappropriate content.

3.20060259974System and method of opportunistically protecting a computer from malware
US 16.11.2006
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 11130570 Applicant Marinescu Adrian M Inventor Marinescu Adrian M

The present invention provides a system, method, and computer-readable medium that opportunistically install a software update on a computer that closes a vulnerability that existed on the computer. In accordance with one aspect of the present invention, when antivirus software on a computer identifies malware, a method causes a software update that closes the vulnerability exploited by the malware to be installed on the computer. The method includes identifying the vulnerability exploited by the malware, using a software update system to obtain a software update that is configured to close the vulnerability; and causing the software update to be installed on the computer where the vulnerability exists.

4.20170091219Reverse replication to rollback corrupted files
US 30.03.2017
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No 15376681 Applicant Microsoft Technology Licensing, LLC Inventor Marc E. Seinfeld

The present invention extends to methods, systems, and computer program products for reverse replication to rollback corrupted files. When a computer system detects that a copy of a file includes inappropriate content, the computer system can coordinate with other computer systems (e.g., in replicated storage system) to determine that a viable (e.g., clean) copy of the file exists. The computer system can access the viable copy and replace the copy that includes the inappropriate content with the viable copy. As such, a computer system can “reverse replicate” a file rather than break a synchronization relationship. Reverse replication can be used to rollback a copy of an infected file to another (possibly earlier) copy of the file that is not infected. Embodiments of the invention can be used to rollback data files, such as, for example, pictures, videos, documents, etc.

5.20100077481Collecting and analyzing malware data
US 25.03.2010
Int.Class G06F 11/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
Appl.No 12234717 Applicant Polyakov Alexey Inventor Polyakov Alexey

A malware analysis system is described that provides information about malware execution history on a client computer and allows automated back-end analysis for faster creation of identification signatures and removal instructions. The malware analysis system collects threat information on client computers and sends the threat information to a back-end analysis component for automated analysis. The back-end analysis component analyzes the threat information by comparing the threat information to information about known threats. The system builds a signature for identifying the threat family and a mitigation script for neutralizing the threat. The system sends the signature and mitigation data to client computers, which use the information to mitigate the threat. Thus, the malware analysis system detects and mitigates threats more quickly than previous systems by reducing the burden on technicians to manually create environments for reproducing the threats and manually analyze the threat behavior.

6.20130152201Adjunct Computing Machine for Remediating Malware on Compromised Computing Machine
US 13.06.2013
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 13316709 Applicant Gullotto Vincent P. Inventor Gullotto Vincent P.

Described is a technology by which a malware-compromised machine, such as a personal computer is cleaned through the use of a functional adjunct machine, such as a mobile device (or vice-versa). The functional adjunct machine performs actions on behalf of the malware-compromised machine and/or to assist the remediation. This may include downloading antimalware-related data (e.g., an application, antimalware code, signature updates and/or the like) via a marketplace/application store, and transferring at least some of the data and/or programs to the compromised machine. Other actions may include using the functional adjunct machine to boot the malware-compromised machine into a non-compromised state and providing the data or programs to allow remediation of the malware while in this state.

7.20110225128Clean store for operating system and software recovery
US 15.09.2011
Int.Class G06F 17/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
Appl.No 12722426 Applicant Jarrett Michael S. Inventor Jarrett Michael S.

Systems, methods and apparatus for automatically identifying a version of a file that is expected to be present on a computer system and for automatically replacing a potentially corrupted copy of the file with a clean (or undamaged) copy of the expected version. Upon identifying a file on the computer system as being potentially corrupted, a clean file agent may perform an analysis based on the identity of the file and one or more other properties of the system to determine the version of the file that is expected to be present on the system. Once the expected version is identified, a clean replacement copy of the file may be obtained from a clean file repository by submitting a version identifier of the expected version. The version identifier may be a hash value, which may additionally be used to verify integrity of the clean copy.

8.20110314543System state based diagnostic scan
US 22.12.2011
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 12816567 Applicant Treit Randal P. Inventor Treit Randal P.

In some embodiments, a local agent on a target system may evaluate current and/or historical system state information from a store (either local or remote) and dynamically adjust the level of diagnosis performed during the scan based on the evaluated state information. Individual diagnostic scans may, for example, be enabled and disabled based on the context in the store, and each scan may update the context for further evaluation. By employing such an approach, systems with a low risk profile and lacking symptoms of a problem may be scanned quickly while systems that show signs of a problem or have a high risk profile may receive a more thorough evaluation.

9.20100169972SHARED REPOSITORY OF MALWARE DATA
US 01.07.2010
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 12347103 Applicant Microsoft Corporation Inventor Kuo Chengi Jimmy

Various principles for maintaining a shared repository of authorization scanning results, which may be populated with results of authorization scans of particular files (and other content units) as well as a signature for those particular files. When a particular file is to be scanned by a client computing device to determine whether it contains unauthorized software, a signature for the file may be calculated and provided to the shared repository. If the repository has a result for that file—as indicated by a signature for the file being present in the repository—the result in the repository may be provided to the client computing device that issued the query, and the client computing device may accept the answer in the shared repository. If the result is not in the repository (i.e., the file has not been scanned), then the file may be scanned, and a result may be placed in the repository.

10.2838397MOBILE DEVICE OPERATIONS WITH BATTERY OPTIMIZATION
CA 20.12.2012
Int.Class G06F 1/3206
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
3203Power management, i.e. event-based initiation of a power-saving mode
3206Monitoring of events, devices or parameters that trigger a change in power modality
Appl.No 2838397 Applicant MICROSOFT CORPORATION Inventor MARC SEINFELD
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.
11.20070179903Identity theft mitigation
US 02.08.2007
Int.Class H04L 9/00
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
9Arrangements for secret or secure communications; Network security protocols
Appl.No 11342447 Applicant Microsoft Corporation Inventor Seinfeld Marc

Public-key authentication, based on public key cryptographic techniques, is utilized to authenticate a person opening an account. The person provides a declaration to use only public-key authentication and a copy of his/her public key to an authorized agent, such as a credit bureau. The person provides a signed request to open an account with a merchant based on public-key authentication. This merchant requests a credit report from the credit bureau, providing the credit bureau the applicant's public key. The credit bureau uses the public key to locate a credit report. Barring theft of the user's private key, the credit report will be that of the requesting user with a high probability. The credit bureau can then provide the requested information to the merchant, and the merchant can provide notification to the person that the account is authorized or not, based on what the merchant reads in the credit report.

12.20120297488Discovering malicious input files and performing automatic and distributed remediation
US 22.11.2012
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 13161950 Applicant Vishal Kapoor Inventor Vishal Kapoor

The subject disclosure is directed towards detecting malware or possible malware in an input file by allowing the input file to be opened, and by monitoring for one or more behaviors corresponding to the open file that likely indicate malware. Only certain executable files and/or file types opened thereby may be monitored, with various collected event data used for antimalware purposes when improper behavior is observed. Example behaviors include writing of a file to storage, generation of network traffic, injection of a process, running of script, and/or writing system registry data. Telemetry data and/or a sample of the file may be sent to an antimalware service, and malware remediation may be performed. Data (e.g., the collected events) may be distributed to other nodes for use in antimalware detection, e.g., to block execution of a similar file.

13.20130160126MALWARE REMEDIATION SYSTEM AND METHOD FOR MODERN APPLICATIONS
US 20.06.2013
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 13327223 Applicant Kapoor Vishal Inventor Kapoor Vishal

A system is described for remediating a malicious modern application installed on an end user device. In an embodiment, the system includes an antimalware program executing on the end user device that can detect and attempt to remediate the malicious modern application, an operating system executing on the end user device that is configured to interact with the antimalware program for the purpose of facilitating the establishment of a connection between the end user device and an application support system in response to determining that the antimalware program has detected and attempted to remediate the malicious modern application, and the application support system that can perform remediation operations beyond those that can be performed by the antimalware program.

14.1091536Methods and systems for conversion of data format
EP 11.04.2001
Int.Class H04L 12/66
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
Appl.No 00308746 Applicant MICROSOFT CORP Inventor KADYK DONALD
The dynamic conversion of a data structure from an origin data format into a destination data format is described. Instead of using a single data conversion module to accomplish this data conversion, a gateway computer system identifies a sequence of format conversion modules that, when executed in sequence, converts the data structure from the origin to the destination data format. The conversion occurs dynamically during run time and reduces the amount of needed data conversion modules significantly, particularly when there is a large amount of possible origin data formats and destination data formats. This conversion is particularly useful when communicating over wireless networks since there is little standardization in wireless devices resulting in wireless devices having many different proprietary data formats.
15.WO/1998/031149SYSTEM AND METHOD FOR SYNCHRONIZING ENHANCING CONTENT WITH A VIDEO PROGRAM USING CLOSED CAPTIONING
WO 16.07.1998
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No PCT/US1998/000082 Applicant MICROSOFT CORPORATION Inventor FEINLEIB, David
A system and method uses the closed captioning script to synchronize supplemental data with specified junctures in a video program. A parser parses the closed captioning script to identify a set of unique phrases, with each phrase having the same number of words. A program producer decides what points in the video program to introduce enhancing content. The producer associates supplemental data used to activate the enhancing content with specific key phrases of the closed captioning script that correspond to the desired points in the program. The parser creates a key phrase data file which contains a listing of the key phrases and their association to the supplemental data. The key phrase data file is delivered to viewer computing units at user's homes. When the program is played, the viewer computing unit monitors the closed captioning script to detect the key phrases listed in the key phrase data file.
16.6637032System and method for synchronizing enhancing content with a video program using closed captioning
US 21.10.2003
Int.Class H04N 5/445
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
NPICTORIAL COMMUNICATION, e.g. TELEVISION
5Details of television systems
44Receiver circuitry
445for displaying additional information
Appl.No 08779270 Applicant Microsoft Corporation Inventor Feinleib, David

A system and method uses the closed captioning script to synchronize supplemental data with specified junctures in a video program. A parser parses the closed captioning script to identify a set of unique phrases, with each phrase having the same number of words. A program producer decides what points in the video program to introduce enhancing content. The producer associates supplemental data used to activate the enhancing content with specific key phrases of the closed captioning script that correspond to the desired points in the program. The parser creates a key phrase data file which contains a listing of the key phrases and their association to the supplemental data. The key phrase data file is delivered to viewer computing units at users' homes. When the program is played, the viewer computing unit monitors the closed captioning script to detect the key phrases listed in the key phrase data file. Upon detection of a particular key phrase, the viewer computing unit accesses the key phrase data file to retrieve the supplemental data associated with the particular key phrase. The viewer computing unit executes an enhancement action according to the supplemental data to synchronize the enhancement action with the video program. According to one implementation, the key phrase detector multicasts the enhancement action to a multicast address. A listener in the form of an ActiveX™ control listens to the multicast address to receive and handle any enhancement action supported by the supplemental data. The listener can be embedded in a container, such as an HTML page or other hypermedia document.

17.20120317644Applying antimalware logic without revealing the antimalware logic to adversaries
US 13.12.2012
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 13156726 Applicant Kumar Ajith Inventor Kumar Ajith

The subject disclosure is directed towards a technology by which antimalware detection logic is maintained and operated at a backend service, with which a customer frontend machine communicates (queries) for purposes of malware detection. In this way, some antimalware techniques are maintained at the backend service rather than revealed to antimalware authors. The backend antimalware detection logic may be based upon feature selection, and may be updated rapidly, in a manner that is faster than malware authors can track. Noise may be added to the results to make it difficult for malware authors to deduce the logic behind the results. The backend may return results indicating malware or not malware, or return inconclusive results. The backend service may also detect probing-related queries that are part of an attempt to deduce the unrevealed antimalware detection logic, with noisy results returned in response and/or other actions taken to foil the attempt.

18.7046691Methods and systems for dynamic conversion of objects from one format type to another format type by selectively using an intermediary format type
US 16.05.2006
Int.Class H04J 3/22
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
JMULTIPLEX COMMUNICATION
3Time-division multiplex systems
22in which the sources have different rates or codes
Appl.No 09609269 Applicant Microsoft Corporation Inventor Kadyk Donald

The dynamic conversion of a data structure from an origin data format into a destination data format is described. Instead of using a single data conversion module to accomplish this data conversion, a gateway computer system identifies a sequence of format conversion modules that, when executed in sequence, converts the data structure from the origin to the destination data format. The conversion occurs dynamically during run time and reduces the amount of needed data conversion modules significantly, particularly when there is a large amount of possible origin data formats and destination data formats. This conversion is particularly useful when communicating over wireless networks since there is little standardization in wireless devices resulting in wireless devices having many different proprietary data formats.

19.WO/2010/033326COLLECTING AND ANALYZING MALWARE DATA
WO 25.03.2010
Int.Class G06F 15/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
Appl.No PCT/US2009/053774 Applicant MICROSOFT CORPORATION Inventor POLYAKOV, Alexey
A malware analysis system is described that provides information about malware execution history on a client computer and allows automated back-end analysis for faster creation of identification signatures and removal instructions. The malware analysis system collects threat information on client computers and sends the threat information to a back-end analysis component for automated analysis. The back-end analysis component analyzes the threat information by comparing the threat information to information about known threats. The system builds a signature for identifying the threat family and a mitigation script for neutralizing the threat. The system sends the signature and mitigation data to client computers, which use the information to mitigate the threat. Thus, the malware analysis system detects and mitigates threats more quickly than previous systems by reducing the burden on technicians to manually create environments for reproducing the threats and manually analyze the threat behavior.
20.112013031986método em um dispositivo e agendador de tarefas em um dispositivo móvel
BR 20.12.2016
Int.Class G06F 9
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
Appl.No 112013031986 Applicant MICROSOFT CORPORATION Inventor AARON PUTNAM
método em um dispositivo e agendador de tarefas em um dispositivo móvel.a presente invenção refere-se a técnicas para conservar energia de bateria (118) em dispositivos. uma ou mais tarefas postergáveis são enfileiradas para execução posterior. uma iniciação de um evento de carregamento subsequente para uma bateria (118) do dispositivo é detectada. a(s) tarefa(s) postergável(eis) enfileirada(s) tem(têm) permissão para ser(em) executada(s) durante o evento de carregamento. por exemplo, a(s) tarefa(s) postergável(eis) enfileirada(s) pode(m) ter permissão para ser(em) executada(s), se o evento de carregamento for predito para ser um evento de carregamento de longa duração, tal como através de referência a um perfil decarregamento do dispositivo móvel (102). dessa maneira, a energia de bateria (118) é conservada enquanto o dispositivo está em uso e não conectado a um carregador de bateria (106).
21.2013014794MOBILE DEVICE OPERATIONS WITH BATTERY OPTIMIZATION.
MX 24.01.2014
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No 2013014794 Applicant MICROSOFT CORPORATION Inventor Marc SEINFELD
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.
22.WO/2010/077792SHARED REPOSITORY OF MALWARE DATA
WO 08.07.2010
Int.Class G06F 21/24
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
24by protecting data directly, e.g. by labelling
Appl.No PCT/US2009/067787 Applicant MICROSOFT CORPORATION Inventor KUO, Chengi Jimmy
Various principles for maintaining a shared repository of authorization scanning results, which may be populated with results of authorization scans of particular files (and other content units) as well as a signature for those particular files. When a particular file is to be scanned by a client computing device to determine whether it contains unauthorized software, a signature for the file may be calculated and provided to the shared repository. If the repository has a result for that file-as indicated by a signature for the file being present in the repository-the result in the repository may be provided to the client computing device that issued the query, and the client computing device may accept the answer in the shared repository. If the result is not in the repository (i.e., the file has not been scanned), then the file may be scanned, and a result may be placed in the repository.
23.2721460MOBILE DEVICE OPERATIONS WITH BATTERY OPTIMIZATION
EP 23.04.2014
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No 12800604 Applicant MICROSOFT TECHNOLOGY LICENSING LLC Inventor SEINFELD MARC
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.
24.9401/CHENP/2013MOBILE DEVICE OPERATIONS WITH BATTERY OPTIMIZATION
IN 24.06.2016
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No 9401/CHENP/2013 Applicant MICROSOFT TECHNOLOGY LICENSING, LLC Inventor SEINFELD Marc
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event such as by referring to a charging profile of the mobile device. In this manner battery power is conserved while the device is in use and not connected to a battery charger.
25.2012271103Mobile device operations with battery optimization
AU 05.12.2013
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No 2012271103 Applicant Microsoft Technology Licensing, LLC Inventor Kuo, Chengi Jimmy
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.
26.0117/DEL/2005ARCHITECTURE FOR CONTROLLING ACCESS TO A SERVICE BY CONCURRENT CLIENTS"
IN 01.12.2006
Int.Class G06F 17/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
10Complex mathematical operations
16Matrix or vector computation
Appl.No 0117/DEL/2005 Applicant MICROSOFT CORPORATION Inventor MARC E. SEINFELD
Architecture (100) for controlling access to a service (102). The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients (104) associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules (108) the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.
27.1020080096757IDENTITY THEFT MITIGATION
KR 03.11.2008
Int.Class G06Q 20/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
QINFORMATION AND COMMUNICATION TECHNOLOGY SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
20Payment architectures, schemes or protocols
Appl.No 1020087018284 Applicant MICROSOFT CORP. Inventor SEINFELD MARC
Public-key authentication, based on public key cryptographic techniques, is utilized to authenticate a person opening an account. The person provides a declaration to use only public-key authentication and a copy of his/her public key to an authorized agent, such as a credit bureau. The person provides a signed request to open an account with a merchant based on public-key authentication. This merchant requests a credit report from the credit bureau, providing the credit bureau the applicant's public key. The credit bureau uses the public key to locate a credit report. Barring theft of the user's private key, the credit report will be that of the requesting user with a high probability. The credit bureau can then provide the requested information to the merchant, and the merchant can provide notification to the person that the account is authorized or not, based on what the merchant reads in the credit report. ©KIPO&WIPO 2009
28.6674767Flexible system and method for communicating between a broad range of networks and devices
US 06.01.2004
Int.Class H04L 12/00
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
Appl.No 09411594 Applicant Microsoft Corporation Inventor Kadyk, Donald J.

A flexible gateway accommodates data transfer from a data origination device over a wide variety of networks to a wide variety of destination devices, even if those networks use different protocols, and even if the devices recognize different data formats. Thus, the gateway can perform work previously requiring numerous gateways. After the gateway receives information from a data source, the gateway identifies the specific device type and the specific network type to which the information is to be routed. The gateway then calls device and network drivers associated with the specific device and network identified with the destination device. These drivers then manipulate the data using the device driver into the format recognized by the destination device, and then provide the manipulated data to the destination device over the identified network using the compatible protocol. Thus, the destination device properly receives and interprets the information provided by the data source. If, in the very next moment, data arrives at the gateway that is to be routed over a different network using a different protocol to a different device recognizing a different device, the gateway will call different device and network drivers to enable the communication.

29.1091532A flexible system and method for communicating between a broad range of networks and devices
EP 11.04.2001
Int.Class H04L 12/66
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
Appl.No 00308747 Applicant MICROSOFT CORP Inventor KADYK DONALD J
A flexible gateway accommodates data transfer from a data origination device over a wide variety of networks to a wide variety of destination devices, even if those networks use different protocols, and even if the devices recognize different data formats. Thus, the gateway can perform work previously requiring numerous gateways. After the gateway receives information from a data source, the gateway identifies the specific device type and the specific network type to which the information is to be routed. The gateway then calls device and network drivers associated with the specific device and network identified with the destination device. These drivers then manipulate the data using the device driver into the format recognized by the destination device, and then provide the manipulated data to the destination device over the identified network using the compatible protocol. Thus, the destination device properly receives and interprets the information provided by the data source. If, in the very next moment, data arrives at the gateway that is to be routed over a different network using a different protocol to a different device recognizing a different device, the gateway will call different device and network drivers to enable the communication.
30.20050187957Architecture for controlling access to a service by concurrent clients
US 25.08.2005
Int.Class G06F 15/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
Appl.No 10783911 Applicant Microsoft Corporation Inventor Kramer Michael

Architecture for controlling access to a service. The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes rules the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.

31.175537Netflix
NPL 28.01.2003
Int.Class H04L 29/08
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
08Transmission control procedure, e.g. data link level control procedure
Publisher wikipedia Journal wikipedia
Netflix, Inc. is an American over-the-top content platform and production company headquartered in Los Gatos, California.,Netflix was founded in 1997 by Reed Hastings and Marc Randolph in Scotts Valley, California.,The company's primary business is a subscription-based streaming service offering online streaming from a library of films and television series, including those produced in-house.,As of October 2020, Netflix had over 195 million paid subscriptions worldwide, including 73 million in the United States.,It is available worldwide except in the following: mainland China (due to local restrictions), Syria, North Korea, and Crimea (due to US sanctions).,It was reported in 2020 that Netflix's operating income is $1.2 billion.,The company has offices in France, the United Kingdom, Brazil, the Netherlands, India, Japan, and South Korea.,Netflix is one of the "Big Six", as well as a member of the Motion Picture Association (MPA), producing and distributing content from countries all over the globe. Netflix's initial business model included DVD sales and rental by mail, but Hastings abandoned the sales about a year after the company's founding to focus on the initial DVD rental business.,Netflix expanded its business in 2007 with the introduction of streaming media while retaining the DVD and Blu-ray rental business.,The company expanded internationally in 2010 with streaming available in Canada, followed by Latin America and the Caribbean.,Netflix entered the content-production industry in 2013, debuting its first series House of Cards. Since 2012, Netflix has taken more of an active role as producer and distributor for both film and television series, and to that end, offers a variety of "Netflix Original" content through its online library.,By January 2016, Netflix services operated in more than 190 countries.,Netflix released an estimated 126 original series and films in 2016, more than any other network or cable channel.,Their efforts to produce new content, secure the rights for additional content, and diversify through 190 countries have resulted in the company racking up billions in debt: $21.9 billion as of September 2017, up from $16.8 billion from the previous year.,$6.5 billion of this is long-term debt, with the remainder in long-term obligations.,In October 2018, Netflix announced it would raise another $2 billion in debt to help fund new content.,On July 10, 2020, Netflix became the largest entertainment/media company by market capitalization.
32.000060027247Verfahren und Systeme zur Konvertierung von Datenformaten
DE 04.01.2007
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 60027247 Applicant MICROSOFT CORP Inventor KADYK DONALD
33.323368VERFAHREN UND SYSTEME ZUR KONVERTIERUNG VON DATENFORMATEN
AT 15.04.2006
Int.Class H04L 12/66
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
Appl.No 00308746 Applicant MICROSOFT CORP Inventor KADYK DONALD
34.PI0405968Arquitetura para controlar acesso a um serviço por clientes simultâneos
BR 18.10.2005
Int.Class G06F 15/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
Appl.No 405968-9 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
35.PA/a/2005/000847ARCHITECTURE FOR CONTROLLING ACCESS TO A SERVICE BY CONCURRENT CLIENTS
MX 12.10.2005
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No PA/a/2005/000847 Applicant MICROSOFT CORPORATION Inventor SEINFELD, Marc, E.
Architecture for controlling access to a service. The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.
36.1566942System and method for controlling access to a service by concurrent clients associated with a subscriber
EP 24.08.2005
Int.Class G06F 1/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
Appl.No 05000624 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
Architecture (100) for controlling access to a service (102). The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients (104) associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules (108) the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.
37.2492742ARCHITECTURE FOR CONTROLLING ACCESS TO A SERVICE BY CONCURRENT CLIENTS
CA 20.08.2005
Int.Class H04L 12/00
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
Appl.No 2492742 Applicant MICROSOFT CORPORATION Inventor SEINFELD, MARC E.
Architecture for controlling access to a service. The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.
38.397245SYSTEM UND VERFAHREN ZUR KONTROLLE DES GLEICHZEITIGEN DIENSTZUGANGS VON ENDGERÄTEN, DIE MIT EINEM TEILNEHMER ASSOZIIERT SIND
AT 15.06.2008
Int.Class G06F 1/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
Appl.No 05000624 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
39.WO/2012/173843MOBILE DEVICE OPERATIONS WITH BATTERY OPTIMIZATION
WO 20.12.2012
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No PCT/US2012/041035 Applicant MICROSOFT CORPORATION Inventor SEINFELD, Marc
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.
40.20040040042System and method for synchronizing enhancing content with a video program using closed captioning
US 26.02.2004
Int.Class H04N 5/445
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
NPICTORIAL COMMUNICATION, e.g. TELEVISION
5Details of television systems
44Receiver circuitry
445for displaying additional information
Appl.No 10647549 Applicant Inventor Feinleib David

A system and method uses a closed captioning script to synchronize supplemental data with specified junctures in a video program. A parser parses the closed captioning script to identify a set of unique key phrases. A producer associates the supplemental data with the key phrases of the closed captioning script that correspond to the desired points in the program. When the program is played, a viewer computing unit monitors the closed captioning script to detect the key phrases. Upon detection of a particular key phrase, the viewer computing unit retrieves the supplemental data associated with the particular key phrase. The supplemental data is multicast to a multicast address. A listener listens to the multicast address to receive and handle any enhancement action supported by the supplemental data. The listener can be embedded in a container, such as an HTML page or other hypermedia document.

41.2004242455Architecture for controlling access to a service by concurrent clients
AU 13.01.2005
Int.Class G06F 15/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
Appl.No 2004242455 Applicant Microsoft Technology Licensing, LLC Inventor Kramer, Michael
Architecture for controlling access to a service. The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled. 110 04
42.WO/2007/089439IDENTITY THEFT MITIGATION
WO 09.08.2007
Int.Class G06Q 20/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
QINFORMATION AND COMMUNICATION TECHNOLOGY SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
20Payment architectures, schemes or protocols
Appl.No PCT/US2007/001322 Applicant MICROSOFT CORPORATION Inventor SEINFELD, Marc
Public-key authentication, based on public key cryptographic techniques, is utilized to authenticate a person opening an account. The person provides a declaration to use only public-key authentication and a copy of his/her public key to an authorized agent, such as a credit bureau. The person provides a signed request to open an account with a merchant based on public-key authentication. This merchant requests a credit report from the credit bureau, providing the credit bureau the applicant's public key. The credit bureau uses the public key to locate a credit report. Barring theft of the user's private key, the credit report will be that of the requesting user with a high probability. The credit bureau can then provide the requested information to the merchant, and the merchant can provide notification to the person that the account is authorized or not, based on what the merchant reads in the credit report.
43.2004237916Detection of code-free files
AU 06.01.2005
Int.Class G06F 9/44
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
44Arrangements for executing specific programs
Appl.No 2004237916 Applicant Microsoft Corporation Inventor Costea, Mihai
S[0046] Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.
44.20060236393System and method for protecting a limited resource computer from malware
US 19.10.2006
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No 11096491 Applicant Microsoft Corporation Inventor Kramer Michael

The present invention is directed to a system and methods for protecting a limited resource computer from malware. Aspects of the present invention use antivirus software on a general purpose computer to prevent malware from infecting a limited resource computer. Typically, antivirus software on the general purpose computer is kept “up-to-date” with the most recent software updates. When a connection is established between the limited resource computer and the general purpose computer, a signature of each application installed on the limited resource computer is transmitted to the general purpose computer. Then antivirus software on the general purpose computer compares the received signatures to known malware. Finally, the results of the scan are reported to the limited resource computer.

45.20140373147Scanning files for inappropriate content during synchronization
US 18.12.2014
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 13920015 Applicant Microsoft Corporation Inventor Marc E. Seinfeld

The present invention extends to methods, systems, and computer program products for scanning files for inappropriate content during file synchronization. Embodiments of the invention are mindful of the order of operations when scanning files for inappropriate content and in subsequent file processing. In some embodiments, during synchronization, an intermediary server scans a file for inappropriate content. The file is not permitted to be fully downloaded to a client device until the scan determines that the file does not contain inappropriate content. In other embodiments, during synchronization, a client device scans a newer version of a file for inappropriate content. An older version of the file is not deleted until the scan determines that the newer version of the file does not contain inappropriate content. In further embodiments, server side scanning and client side scanning are both used to enhance capabilities for detecting inappropriate content.

46.1195949Using an expert proxy server as an agent for wireless devices
EP 10.04.2002
Int.Class H04L 12/28
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
28characterised by path configuration, e.g. LAN or WAN
Appl.No 01123665 Applicant MICROSOFT CORP Inventor KADYK DONALD J
An expert proxy server (130) is described that is coupled to a number of wireless devices (110) through a wireless network (120), and to a number of server computer systems (150) through an external network (140) such as, for example, the Internet. The expert proxy server acts as an agent for a wireless device by providing a service for the wireless device. Specifically, the expert proxy server determines that a service is to be provided to the wireless device. Next, the expert proxy server identifies an application that provides the service and then communicates with the identified application that provides the service. The expert proxy server compiles the results of the communication with the application and then transmits the compilation to the wireless device over the wireless network. Thus, the relatively smaller bandwidth of the wireless network is preserved by transmitting a minimal amount of information over the wireless network while leaving more extensive communications to occur over higher bandwidth external networks. Also, since the extensive processing occurs at the expert proxy server rather than at the wireless device, the application on the wireless device may be simplified and smaller as compared to the supporting applications on the expert proxy server thereby preserving the limited memory and processing capability of the wireless device.
47.20070006304Optimizing malware recovery
US 04.01.2007
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No 11172373 Applicant Microsoft Corporation Inventor Kramer Michael

Malware recovery optimization is provided in which malware detection processes and protocol processes on a device are monitored for events indicating a breach of security of the device, such as the presence of an infection or other evidence of a malware attack. The devices report the events for collection on a centralized event collector that issues alerts of the events to other devices that may have been compromised as a result of the breach of security. Upon receipt of the alert, the receiving devices may initiate malware recovery optimization, including activating anti-virus software to initiate a targeted scan of those resources that may have been compromised. In this manner, malware recovery processes are optimized to recover the receiving device and/or resources when indicated.

48.6895425Using an expert proxy server as an agent for wireless devices
US 17.05.2005
Int.Class G06F 15/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
Appl.No 09684053 Applicant Microsoft Corporation Inventor Kadyk Donald J.

An expert proxy server is described that is coupled to a number of wireless devices through a wireless network, and to a number of server computer systems through an external network such as, for example, the Internet. The expert proxy server acts as an agent for a wireless device by providing a service for the wireless device. Specifically, the expert proxy server determines that a service is to be provided to the wireless device. Next, the expert proxy server identifies an application that provides the service and then communicates with the identified application that provides the service. The expert proxy server compiles the results of the communication with the application and then transmits the compilation to the wireless device over the wireless network. Thus, the relatively smaller bandwidth of the wireless network is preserved by transmitting a minimal amount of information over the wireless network while leaving more extensive communications to occur over higher bandwidth external networks. Also, since the extensive processing occurs at the expert proxy server rather than at the wireless device, the application on the wireless device may be simplified and smaller as compared to the supporting applications on the expert proxy server thereby preserving the limited memory and processing capability of the wireless device.

49.20050160140Using an expert proxy server as an agent for wireless devices
US 21.07.2005
Int.Class G06F 15/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
Appl.No 11059860 Applicant Microsoft Corporation Inventor Kadyk Donald J.

An expert proxy server is described that is coupled to a number of wireless devices through a wireless network, and to a number of server computer systems through an external network such as, for example, the Internet. The expert proxy server acts as an agent for a wireless device by providing a service for the wireless device. Specifically, the expert proxy server determines that a service is to be provided to the wireless device. Next, the expert proxy server identifies an application that provides the service and then communicates with the identified application that provides the service. The expert proxy server compiles the results of the communication with the application and then transmits the compilation to the wireless device over the wireless network. Thus, the relatively smaller bandwidth of the wireless network is preserved by transmitting a minimal amount of information over the wireless network while leaving more extensive communications to occur over higher bandwidth external networks. Also, since the extensive processing occurs at the expert proxy server rather than at the wireless device, the application on the wireless device may be simplified and smaller as compared to the supporting applications on the expert proxy server thereby preserving the limited memory and processing capability of the wireless device.

50.20140020104System and Method of Opportunistically Protecting a Computer from Malware
US 16.01.2014
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 14026226 Applicant Microsoft Corporation Inventor Marinescu Adrian M.

The present invention provides a system, method, and computer-readable medium that opportunistically install a software update on a computer that closes a vulnerability that existed on the computer. In accordance with one aspect of the present invention, when antivirus software on a computer identifies malware, a method causes a software update that closes the vulnerability exploited by the malware to be installed on the computer. The method includes identifying the vulnerability exploited by the malware, using a software update system to obtain a software update that is configured to close the vulnerability; and causing the software update to be installed on the computer where the vulnerability exists.

51.20140020103System and Method of Opportunistically Protecting a Computer from Malware
US 16.01.2014
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 14025799 Applicant Microsoft Corporation Inventor Marinescu Adrian M.

The present invention provides a system, method, and computer-readable medium that opportunistically install a software update on a computer that closes a vulnerability that existed on the computer. In accordance with one aspect of the present invention, when antivirus software on a computer identifies malware, a method causes a software update that closes the vulnerability exploited by the malware to be installed on the computer. The method includes identifying the vulnerability exploited by the malware, using a software update system to obtain a software update that is configured to close the vulnerability; and causing the software update to be installed on the computer where the vulnerability exists.

52.7640583Method and system for protecting anti-malware programs
US 29.12.2009
Int.Class G06F 11/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
30Monitoring
Appl.No 11097984 Applicant Microsoft Corporation Inventor Marinescu Adrian M.

In general, embodiments of the present invention provide protection for anti-malware software programs (also referred to herein as anti-malware) that is in addition to the protection that currently exists. In particular, instead of only protecting anti-malware programs from malware attacks by attempting to detect the malware software programs (also referred to herein as malware) before they can accomplish their malicious task, embodiments of the present invention obfuscate, or hide, the anti-malware and/or files associated with the anti-malware. Obfuscating files makes it difficult for malware to locate the information needed to accomplish its malware tasks. Additionally, because obfuscation makes file location difficult, malware that attempts to overcome this protection technique will likely include or use a detection engine.

53.103597423Mobile device operations with battery optimization
CN 19.02.2014
Int.Class G06F 1/32
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
26Power supply means, e.g. regulation thereof
32Means for saving power
Appl.No 201280029334.0 Applicant MICROSOFT CORPORATION Inventor SEINFELD MARC
Techniques for conserving battery power in devices are provided. One or more deferrable tasks are queued for later execution. An initiation of a subsequent charging event for a battery of the device is detected. The queued deferrable task(s) are enabled to be executed during the charging event. For instance, the queued deferrable task(s) may be enabled to be executed if the charging event is predicted to be a long duration charging event, such as by referring to a charging profile of the mobile device. In this manner, battery power is conserved while the device is in use and not connected to a battery charger.
54.20020099727Accounting for update notifications in synchronizing data that may be represented by different data structures
US 25.07.2002
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No 09768747 Applicant Microsoft Corporation Inventor Kadyk Donald J.

Methods, systems, and computer program products for synchronizing data stored at one or more message clients with data stored at a message server where the message clients may receive update notifications and may represent the data using different data structures than the message server uses to represent the same data. A token is associated with each data change that occurs at the message server. The message server sends each change and associated token to the message clients. When the message clients request a synchronization, the tokens they received are returned to the message server for comparison with the tokens the message server sent to the message clients. If the message clients do not return a particular token, the message server determines that the clients did not receive the corresponding change and resends the change to the message clients. Tokens may also be used to divide a change into one or more portions, with only one portion being provided initially. Then, in response to receiving the token associated with the portion, the message server may provide the remaining portion of the message to the message clients.

55.20050050104Accounting for update notifications in synchronizing data that may be represented by different data structures
US 03.03.2005
Int.Class G06F 13/20
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
13Interconnection of, or transfer of information or other signals between, memories, input/output devices or central processing units
14Handling requests for interconnection or transfer
20for access to input/output bus
Appl.No 10961003 Applicant Microsoft Corporation Inventor Kadyk Donald J.

Methods, systems, and computer program products for synchronizing data stored at one or more message clients with data stored at a message server where the message clients may receive update notifications and may represent the data using different data structures than the message server uses to represent the same data. A token is associated with each data change that occurs at the message server. The message server sends each change and associated token to the message clients. When the message clients request a synchronization, the tokens they received are returned to the message server for comparison with the tokens the message server sent to the message clients. If the message clients do not return a particular token, the message server determines that the clients did not receive the corresponding change and resends the change to the message clients. Tokens may also be used to divide a change into one or more portions, with only one portion being provided initially. Then, in response to receiving the token associated with the portion, the message server may provide the remaining portion of the message to the message clients.

56.20050144312Accounting for update notifications in synchronizing data that may be represented by different data structures
US 30.06.2005
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No 11021537 Applicant Microsoft Corporation Inventor Kadyk Donald J.

Methods, systems, and computer program products for synchronizing data stored at one or more message clients with data stored at a message server where the message clients may receive update notifications and may represent the data using different data structures than the message server uses to represent the same data. A token is associated with each data change that occurs at the message server. The message server sends each change and associated token to the message clients. When the message clients request a synchronization, the tokens they received are returned to the message server for comparison with the tokens the message server sent to the message clients. If the message clients do not return a particular token, the message server determines that the clients did not receive the corresponding change and resends the change to the message clients. Tokens may also be used to divide a change into one or more portions, with only one portion being provided initially. Then, in response to receiving the token associated with the portion, the message server may provide the remaining portion of the message to the message clients.

57.20050060355Accounting for update notification in synchronizing data that may be represented by different data structures
US 17.03.2005
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No 10958723 Applicant Microsoft Corporation Inventor Kadyk Donald J.

Methods, systems, and computer program products for synchronizing data stored at one or more message clients with data stored at a message server where the message clients may receive update notifications and may represent the data using different data structures than the message server uses to represent the same data. A token is associated with each data change that occurs at the message server. The message server sends each change and associated token to the message clients. When the message clients request a synchronization, the tokens they received are returned to the message server for comparison with the tokens the message server sent to the message clients. If the message clients do not return a particular token, the message server determines that the clients did not receive the corresponding change and resends the change to the message clients. Tokens may also be used to divide a change into one or more portions, with only one portion being provided initially. Then, in response to receiving the token associated with the portion, the message server may provide the remaining portion of the message to the message clients.

58.2005235177ARCHITECTURE FOR CONTROLLING ACCESS TO SERVICE BY CONCURRENTLY EXISTING CLIENTS
JP 02.09.2005
Int.Class G06F 15/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
Appl.No 2005001957 Applicant MICROSOFT CORP Inventor MARC E SEINFELD

PROBLEM TO BE SOLVED: To provide an architecture for controlling access to a service.

SOLUTION: This architecture allows denial of regular and periodic service to all but a selected number of concurrent clients associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules of the enforcement which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.

COPYRIGHT: (C)2005,JPO&NCIPI

59.1227637Caching transformed content in a mobile gateway
EP 31.07.2002
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 02001452 Applicant MICROSOFT CORP Inventor FISHMAN NEIL
A mobile gateway receives content from a content source and customizes the content using transforms assigned to each mobile client. Transforms account for differences between mobile clients without imposing significant processing burdens on the content server. Copies of the content, the transformed content, and a transform identifier are cached at the mobile gateway so that subsequent requests for the content may be satisfied without requiring access to the content source. Processing that is common among several transforms may be shared. Mobile clients may be any type of computer.
60.20020103934Caching transformed content in a mobile gateway
US 01.08.2002
Int.Class G06F 15/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
Appl.No 09771184 Applicant Microsoft Corporation Inventor Fishman Neil

Methods, systems, and computer program products for caching content that has been customized based on one or more operating characteristics of a mobile client. A mobile gateway receives content from a content source and customizes the content using transforms assigned to each mobile client. Transforms account for differences between mobile clients without imposing significant processing burdens on the content server. Copies of the content, the transformed content, and a transform identifier are cached at the mobile gateway so that subsequent requests for the content may be satisfied without requiring access to the content source. Processing that is common among several transforms may be shared. Mobile clients may be any type of computer.

61.20050172339Detection of code-free files
US 04.08.2005
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No 10769106 Applicant Microsoft Corporation Inventor Costea Mihai

Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.

62.20070016690Pushing rich content information to mobile devices
US 18.01.2007
Int.Class G06F 15/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
Appl.No 11532768 Applicant Microsoft Corporation Inventor Fishman Neil

Methods, systems, and computer program products for customizing content based on at least one operating characteristic of a mobile client. A mobile gateway receives content from a content source, such as an email server, a Web server, or some other content server. For example, content may include email, calendar, contact, task, Web, notification, financial, sports data, configuration information, etc. The mobile gateway customizes the content based on transforms assigned to each mobile client. Transforms account for differences in the software, display, processor, memory, communication channel, and the like, of each mobile client, without imposing additional processing burdens on the content server. Processing that is common among several transforms may be shared. Mobile clients may be any type of computer, including telephones, pagers, PDAs, laptops, and other mobile gateways.

63.PI 20045231DETECTION OF CODE-FREE FILES
MY 30.07.2005
Int.Class Appl.No PI 20045231 Applicant MICROSOFT CORPORATION Inventor MARC E. SEINFELD
64.000060035467Flexibles System und Verfahren zur Kommunikation zwischen verschiedenen Netzwerken und Vorrichtungen
DE 08.11.2007
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 60035467 Applicant MICROSOFT CORP Inventor KADYK DONALD J
65.367040FLEXIBLES SYSTEM UND VERFAHREN ZUR KOMMUNIKATION ZWISCHEN VERSCHIEDENEN NETZWERKEN UND VORRICHTUNGEN
AT 15.08.2007
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 00308747 Applicant MICROSOFT CORP Inventor KADYK DONALD J
66.1251670Negotiating secure connections through a proxy server
EP 23.10.2002
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 02007078 Applicant MICROSOFT CORP Inventor KADYK DONALD J
Methods, systems, and computer program products for negotiating a secure end-to-end connection using a proxy server as an intermediary. The client first negotiates a secure connection between the client and the proxy so that any credentials exchanged will be encrypted. After the exchange of authentication credentials, the secure client-proxy connection is altered so that no further encryption takes place. The client and server then negotiate a secure end-to-end connection through the proxy, with the secure end-to-end connection being encapsulated within the insecure client-proxy connection. In this way, the overhead of creating a separate client-proxy connection for the secure end-to-end connection may be avoided, but the insecure client-proxy connection introduces only minimal overhead because it no longer encrypts any data that it carries.
67.20060101510Negotiating secure connections through a proxy server
US 11.05.2006
Int.Class H04L 9/00
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
9Arrangements for secret or secure communications; Network security protocols
Appl.No 11305600 Applicant Microsoft Corporation Inventor Kadyk Donald J.

Methods, systems, and computer program products for negotiating a secure end-to-end connection using a proxy server as an intermediary. The client first negotiates a secure connection between the client and the proxy so that any credentials exchanged will be encrypted. After the exchange of authentication credentials, the secure client-proxy connection is altered so that no further encryption takes place. The client and server then negotiate a secure end-to-end connection through the proxy, with the secure end-to-end connection being encapsulated within the insecure client-proxy connection. In this way, the overhead of creating a separate client-proxy connection for the secure end-to-end connection may be avoided, but the insecure client-proxy connection introduces only minimal overhead because it no longer encrypts any data that it carries.

68.20020157019Negotiating secure connections through a proxy server
US 24.10.2002
Int.Class H04L 9/00
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
9Arrangements for secret or secure communications; Network security protocols
Appl.No 09838745 Applicant Microsoft Corporation Inventor Kadyk Donald J.

Methods, systems, and computer program products for negotiating a secure end-to-end connection using a proxy server as an intermediary. The client first negotiates a secure connection between the client and the proxy so that any credentials exchanged will be encrypted. After the exchange of authentication credentials, the secure client-proxy connection is altered so that no further encryption takes place. The client and server then negotiate a secure end-to-end connection through the proxy, with the secure end-to-end connection being encapsulated within the insecure client-proxy connection. In this way, the overhead of creating a separate client-proxy connection for the secure end-to-end connection may be avoided, but the insecure client-proxy connection introduces only minimal overhead because it no longer encrypts any data that it carries.

69.000060201854Verhandlung von sicheren Verbindungen durch einen Proxy-Server
DE 31.03.2005
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 60201854 Applicant MICROSOFT CORP Inventor FISHMAN NEIL S
70.282273VERHANDLUNG VON SICHEREN VERBINDUNGEN DURCH EINEN PROXY-SERVER
AT 15.11.2004
Int.Class H04L 29/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
29Arrangements, apparatus, circuits or systems, not covered by a single one of groups H04L1/-H04L27/136
02Communication control; Communication processing
06characterised by a protocol
Appl.No 02007078 Applicant MICROSOFT CORP Inventor KADYK DONALD J
71.PA/a/2004/012866DETECTION OF CODE-FREE FILES
MX 12.10.2005
Int.Class G06F 17/27
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
20Handling natural language data
27Automatic analysis, e.g. parsing, orthograph correction
Appl.No PA/a/2004/012866 Applicant MICROSOFT CORPORATION Inventor ZEKE B. ODINS-LUCAS
Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.
72.2004/10384DETECTION OF CODE-FREE FILES
ZA 27.09.2006
Int.Class G06F
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
Appl.No 2004/10384 Applicant MICROSOFT CORPORATION Inventor Marc E SEINFELD
[0046] Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.

73.0020/DEL/2005DETECTION OF CODE-FREE FILES
IN 22.12.2006
Int.Class G06F 11/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
30Monitoring
Appl.No 0020/DEL/2005 Applicant MICROSOFT CORPORATION Inventor MARC E. SEINFELD
Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.
74.20060224724Latency free scanning of malware at a network transit point
US 05.10.2006
Int.Class G06F 15/173
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
163Interprocessor communication
173using an interconnection network, e.g. matrix, shuffle, pyramid, star or snowflake
Appl.No 11097060 Applicant Microsoft Corporation Inventor Marinescu Adrian M

In accordance with the present invention, a system, method, and computer-readable medium for identifying malware at a network transit point such as a computer that serves as a gateway to an internal or private network is provided. A network transmission is scanned for malware at a network transit point without introducing additional latency to the transmission of data over the network. In accordance with one aspect of the present invention, a computer-implemented method for identifying malware at a network transit point is provided. More specifically, when a packet in a transmission is received at the network transit point, the packet is immediately forwarded to the target computer. Simultaneously, the packet and other data in the transmission are scanned for malware by an antivirus engine. If malware is identified in the transmission, the target computer is notified that the transmission contains malware.

75.MX/a/2007/011685PROTECTING A COMPUTER THAT PROVIDES A WEB SERVICE FROM MALWARE
MX 22.02.2008
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No MX/a/2007/011685 Applicant MICROSOFT CORPORATION.* Inventor Marc E. Seinfeld
In accordance with the present invention, a system, method, and computer-readable medium for identifying malware in a request to a Web service is provided. One aspect of the present invention is a computer-implemented method for protecting a computer that provides a Web service from malware made in a Web request. When a request is received, an on-demand compilation system compiles high-level code associated with the request into binary code that may be executed. However, before the code is executed, antivirus software designed to identify malware scans the binary code for malware. If malware is identified, the antivirus software prevents the binary code associated with the request from being executed.
76.PI0608845PROTEÇÃO DE COMPUTADOR PROVENDO UM SERVIÇO EM REDE A PARTIR DE SOFTWARE MAL INTENCIONADO
BR 02.02.2010
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No PI0608845-7 Applicant MICROSOFT CORPORATION Inventor Marc E. Seinfeld, Adrian M. Marinescu, Charles W. Kaufman, Jeffrey M. Cooperstein, Michael Kramer
PROTEÇÃO DE COMPUTADOR PROVENDO UM SERVIÇO EM REDE A PARTIR DE SOFTWARE MAL INTENCIONADO. De acordo com a presente invenção, é provido um sistema, um método e um meio para leitura por computador para a identificação de software mal intencionado, ou "malware", em uma requisição para um serviço em rede. Um aspecto da presente invenção consiste de um método implementado por computador para proteger um computador que provê um serviço de rede a partir de um malware efetuado em uma requisição à rede. Quando uma requisição é recebida, um sistema de compilação sob demanda compila um código de alto nível associado à requisição para um código binário que pode ser executado. No entanto, antes que o código seja executado, um software antivírus projetado para identificar malware escaneia o cádigo binário quanto a malware. Caso seja identificado um malware, o software antivírus impede a execução do código binário associado à requisição.
77.2006200384System and method for identifying and removing potentially unwanted software
AU 16.02.2006
Int.Class G06F 9/44
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
44Arrangements for executing specific programs
Appl.No 2006200384 Applicant Microsoft Corporation Inventor Azad, Kalid M.
ct DISCLOSURE 0 A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one 0 5 embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. SSimilarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.
78.1020050083018SERVER ARCHITECTURE FOR CONTROLLING ACCESS TO SERVICE BY CONCURRENT CLIENTS
KR 24.08.2005
Int.Class G06F 15/16
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
Appl.No 1020050000045 Applicant MICROSOFT CORP. Inventor SEINFELD MARC E.

PURPOSE: A server architecture for controlling access to a service by concurrent clients is provided to disallow a periodical and cyclic service to all clients, not concurrent clients of a selected number related to a subscriber, without any manual management in a server of a computer list.

CONSTITUTION: A rule component(108) processes more than one rule according to a subscribed service of a subscriber client(104). A service component(102) automatically constrains the subscribed service partially according to the concurrent client number of the subscriber client by using more than one rule. The rule automatically constrains the subscribed service according to at least one of a churn parameter or a frequency parameter. Each concurrent client includes a cookie facilitating constraint of the subscribed service.

© KIPO 2006

79.20/DEL/2005"DETECTION OF CODE-FREE FILES"
IN 08.12.2006
Int.Class G06F 11/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
30Monitoring
Appl.No 20/DEL/2005 Applicant MICROSOFT TECHNOLOGY LICENSING, LLC Inventor MARC E. SEINFELD
A processor-readable medium comprising processor-executable instructions for: parsing an input file to recognize a file format of the input file; checking contents of the input file, according to the recognized file format ifavailable, to determine whether executable code exists within the input file;and sending a status in response to results of said checking.
80.WO/2011/112474CLEAN STORE FOR OPERATING SYSTEM AND SOFTWARE RECOVERY
WO 15.09.2011
Int.Class G06F 9/06
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
Appl.No PCT/US2011/027308 Applicant MICROSOFT CORPORATION Inventor JARRETT, Michael S.
Systems, methods and apparatus for automatically identifying a version of a file that is expected to be present on a computer system and for automatically replacing a potentially corrupted copy of the file with a clean (or undamaged) copy of the expected version. Upon identifying a file on the computer system as being potentially corrupted, a clean file agent may perform an analysis based on the identity of the file and one or more other properties of the system to determine the version of the file that is expected to be present on the system. Once the expected version is identified, a clean replacement copy of the file may be obtained from a clean file repository by submitting a version identifier of the expected version. The version identifier may be a hash value, which may additionally be used to verify integrity of the clean copy.
81.10.1109/TVCG.2017.2657239Paint with Me: Stimulating Creativity and Empathy While Painting with a Painter in Virtual Reality
NPL 15.03.2017
Int.Class B44D 2/00
BPERFORMING OPERATIONS; TRANSPORTING
44DECORATIVE ARTS
DPAINTING OR ARTISTIC DRAWING, NOT OTHERWISE PROVIDED FOR; PRESERVING PAINTINGS; SURFACE TREATMENT TO OBTAIN SPECIAL ARTISTIC SURFACE EFFECTS OR FINISHES
2Special techniques in artistic painting or drawing, e.g. oil painting, water painting, pastel painting, relief painting
Publisher IEEE Journal Transactions on Visualization and Computer Graphics
While nothing can be more vivid, immediate and real than our own sensorial experiences, emerging virtual reality technologies are playing with the possibility of being able to share someone else's sensory reality. The Painter Project is a virtual environment where users see a video from a painter's point of view in tandem with a tracked rendering of their own hand while they paint on a physical canvas. The end result is an experiment in superimposition of one experiential reality on top of another, hopefully opening a new window into an artist's creative process. This explorative study tested this virtual environment on stimulating empathy and creativity. The findings indicate potential for this technology as a new expert-novice mentorship simulation.
82.3011437SCANNING FILES FOR INAPPROPRIATE CONTENT DURING SYNCHRONIZATION
EP 27.04.2016
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 14737423 Applicant MICROSOFT TECHNOLOGY LICENSING LLC Inventor SEINFELD MARC E
The present invention extends to methods, systems, and computer program products for scanning files for inappropriate content during file synchronization. Embodiments of the invention are mindful of the order of operations when scanning files for inappropriate content and in subsequent file processing. In some embodiments, during synchronization, an intermediary server scans a file for inappropriate content. The file is not permitted to be fully downloaded to a client device until the scan determines that the file does not contain inappropriate content. In other embodiments, during synchronization, a client device scans a newer version of a file for inappropriate content. An older version of the file is not deleted until the scan determines that the newer version of the file does not contain inappropriate content. In further embodiments, server side scanning and client side scanning are both used to enhance capabilities for detecting inappropriate content.
83.20140379637REVERSE REPLICATION TO ROLLBACK CORRUPTED FILES
US 25.12.2014
Int.Class G06F 17/30
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
30Information retrieval; Database structures therefor
Appl.No 13926674 Applicant Microsoft Corporation Inventor Seinfeld Marc E.

The present invention extends to methods, systems, and computer program products for reverse replication to rollback corrupted files. When a computer system detects that a copy of a file includes inappropriate content, the computer system can coordinate with other computer systems (e.g., in replicated storage system) to determine that a viable (e.g., clean) copy of the file exists. The computer system can access the viable copy and replace the copy that includes the inappropriate content with the viable copy. As such, a computer system can “reverse replicate” a file rather than break a synchronization relationship. Reverse replication can be used to rollback a copy of an infected file to another (possibly earlier) copy of the file that is not infected. Embodiments of the invention can be used to rollback data files, such as, for example, pictures, videos, documents, etc.

84.105518694Reverse replication to rollback corrupted files
CN 20.04.2016
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 112014000036268 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
The present invention extends to methods, systems, and computer program products for reverse replication to rollback corrupted files. When a computer system detects that a copy of a file includes inappropriate content, the computer system can coordinate with other computer systems (e.g., in replicated storage system) to determine that a viable (e.g., clean) copy of the file exists. The computer system can access the viable copy and replace the copy that includes the inappropriate content with the viable copy. As such, a computer system can ''reverse replicate'' a file rather than break a synchronization relationship. Reverse replication can be used to rollback a copy of an infected file to another (possibly earlier) copy of the file that is not infected. Embodiments of the invention can be used to rollback data files, such as, for example, pictures, videos, documents, etc.
85.PI0405400Detecção de arquivos livres de código
BR 20.09.2005
Int.Class G06F 21/22
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
22by restricting access to, or manipulation of, programmes or processes
Appl.No 405400-8 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
86.1560112Detection of files that do not contain executable code
EP 03.08.2005
Int.Class G06F 9/445
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
44Arrangements for executing specific programs
445Program loading or initiating
Appl.No 04028765 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.
87.2491114DETECTION OF CODE-FREE FILES
CA 30.07.2005
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 2491114 Applicant MICROSOFT CORPORATION Inventor SEINFELD, MARC E.
Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.
88.3014512REVERSE REPLICATION TO ROLLBACK CORRUPTED FILES
EP 04.05.2016
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 14740059 Applicant MICROSOFT TECHNOLOGY LICENSING LLC Inventor SEINFELD MARC E
The present invention extends to methods, systems, and computer program products for reverse replication to rollback corrupted files. When a computer system detects that a copy of a file includes inappropriate content, the computer system can coordinate with other computer systems (e.g., in replicated storage system) to determine that a viable (e.g., clean) copy of the file exists. The computer system can access the viable copy and replace the copy that includes the inappropriate content with the viable copy. As such, a computer system can "reverse replicate" a file rather than break a synchronization relationship. Reverse replication can be used to rollback a copy of an infected file to another (possibly earlier) copy of the file that is not infected. Embodiments of the invention can be used to rollback data files, such as, for example, pictures, videos, documents, etc.
89.20060242709Protecting a computer that provides a Web service from malware
US 26.10.2006
Int.Class G08B 23/00
GPHYSICS
08SIGNALLING
BSIGNALLING OR CALLING SYSTEMS; ORDER TELEGRAPHS; ALARM SYSTEMS
23Alarms responsive to unspecified undesired or abnormal conditions
Appl.No 11112507 Applicant Microsoft Corporation Inventor Seinfeld Marc E

In accordance with the present invention, a system, method, and computer-readable medium for identifying malware in a request to a Web service is provided. One aspect of the present invention is a computer-implemented method for protecting a computer that provides a Web service from malware made in a Web request. When a request is received, an on-demand compilation system compiles high-level code associated with the request into binary code that may be executed. However, before the code is executed, antivirus software designed to identify malware scans the binary code for malware. If malware is identified, the antivirus software prevents the binary code associated with the request from being executed.

90.1872232PROTECTING A COMPUTER THAT PROVIDES A WEB SERVICE FROM MALWARE
EP 02.01.2008
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 06750717 Applicant MICROSOFT TECHNOLOGY LICENSING LLC Inventor SEINFELD MARC E
In accordance with the present invention, a system, method, and computer-readable medium for identifying malware in a request to a Web service is provided. One aspect of the present invention is a computer-implemented method for protecting a computer that provides a Web service from malware made in a Web request. When a request is received, an on-demand compilation system compiles high-level code associated with the request into binary code that may be executed. However, before the code is executed, antivirus software designed to identify malware scans the binary code for malware. If malware is identified, the antivirus software prevents the binary code associated with the request from being executed.
91.WO/2006/107320LATENCY FREE SCANNING OF MALWARE AT A NETWORK TRANSIT POINT
WO 12.10.2006
Int.Class G06F 11/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
Appl.No PCT/US2005/027205 Applicant MICROSOFT CORPORATION Inventor MARINESCU, Adrian, M.
In accordance with the present invention, a system, method, and computer-readable medium for identifying malware at a network transit point such as a computer that serves as a gateway to an internal or private network is provided. A network transmission is scanned for malware at a network transit point without introducing additional latency to the transmission of data over the network. In accordance with one aspect of the present invention, a computer-implemented method for identifying malware at a network transit point is provided. More specifically, when a packet in a transmission is received at the network transit point, the packet is immediately forwarded to the target computer. Simultaneously, the packet and other data in the transmission is scanned for malware by an antivirus engine. If malware is identified in the transmission, the target computer is notified that the transmission contains malware.
92.WO/2014/204786SCANNING FILES FOR INAPPROPRIATE CONTENT DURING SYNCHRONIZATION
WO 24.12.2014
Int.Class G06F 9/44
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
44Arrangements for executing specific programs
Appl.No PCT/US2014/042212 Applicant MICROSOFT TECHNOLOGY LICENSING, LLC Inventor SEINFELD, Marc E.
The present invention extends to methods, systems, and computer program products for scanning files for inappropriate content during file synchronization. Embodiments of the invention are mindful of the order of operations when scanning files for inappropriate content and in subsequent file processing. In some embodiments, during synchronization, an intermediary server scans a file for inappropriate content. The file is not permitted to be fully downloaded to a client device until the scan determines that the file does not contain inappropriate content. In other embodiments, during synchronization, a client device scans a newer version of a file for inappropriate content. An older version of the file is not deleted until the scan determines that the newer version of the file does not contain inappropriate content. In further embodiments, server side scanning and client side scanning are both used to enhance capabilities for detecting inappropriate content.
93.PA/a/2005/012549METHOD AND SYSTEM FOR A SELF-HEALING DEVICE
MX 24.07.2006
Int.Class G06F 11/07
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
07Responding to the occurrence of a fault, e.g. fault tolerance
Appl.No PA/a/2005/012549 Applicant MICROSOFT CORPORATION.* Inventor Adrian M. Marinescu
A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.
94.3018/DEL/2005A METHOD AND SYSTEM FOR A SELF-HEALING DEVICE
IN 31.07.2009
Int.Class H04J 1/16
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
JMULTIPLEX COMMUNICATION
1Frequency-division multiplex systems
02Details
16Monitoring arrangements
Appl.No 3018/DEL/2005 Applicant MICROSOFT CORPORATION Inventor ADRIAN M. MARINESCU
A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.
95.101395625Identity theft mitigation
CN 25.03.2009
Int.Class G06Q 20/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
QINFORMATION AND COMMUNICATION TECHNOLOGY SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
20Payment architectures, schemes or protocols
Appl.No 200780008007.6 Applicant Microsoft Corp. Inventor Seinfeld Marc
Public-key authentication, based on public key cryptographic techniques, is utilized to authenticate a person opening an account. The person provides a declaration to use only public-key authentication and a copy of his/her public key to an authorized agent, such as a credit bureau. The person provides a signed request to open an account with a merchant based on public-key authentication. This merchant requests a credit report from the credit bureau, providing the credit bureau the applicant's public key. The credit bureau uses the public key to locate a credit report. Barring theft of the user's private key, the credit report will be that of the requesting user with a high probability. The credit bureau can then provide the requested information to the merchant, and the merchant can provide notification to the person that the account is authorized or not, based on what the merchant reads in the credit report.
96.PA/a/2006/002337SYSTEM AND METHOD FOR IDENTIFYING AND REMOVING POTENTIALLY UNWANTED SOFTWARE
MX 23.10.2006
Int.Class G06F 9/315
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
30Arrangements for executing machine instructions, e.g. instruction decode
315Controlling moving, shifting or rotation operations
Appl.No PA/a/2006/002337 Applicant MICROSOFT CORPORATION.* Inventor Jason Garms
A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.
97.345/DEL/2006"SYSTEM AND METHOD FOR IDENTIFYING AND REMOVING POTENTIALLY UNWANTED SOFTWARE"
IN 17.08.2007
Int.Class G06F 9/46
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
46Multiprogramming arrangements
Appl.No 345/DEL/2006 Applicant MICROSOFT CORPORATION Inventor ALVIN LOH
A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.
98.WO/2014/209825REVERSE REPLICATION TO ROLLBACK CORRUPTED FILES
WO 31.12.2014
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No PCT/US2014/043555 Applicant MICROSOFT TECHNOLOGY LICENSING, LLC Inventor SEINFELD, Marc E.
The present invention extends to methods, systems, and computer program products for reverse replication to rollback corrupted files. When a computer system detects that a copy of a file includes inappropriate content, the computer system can coordinate with other computer systems (e.g., in replicated storage system) to determine that a viable (e.g., clean) copy of the file exists. The computer system can access the viable copy and replace the copy that includes the inappropriate content with the viable copy. As such, a computer system can "reverse replicate" a file rather than break a synchronization relationship. Reverse replication can be used to rollback a copy of an infected file to another (possibly earlier) copy of the file that is not infected. Embodiments of the invention can be used to rollback data files, such as, for example, pictures, videos, documents, etc.
99.1679631Method and system for a self-healing device
EP 12.07.2006
Int.Class G06F 21/56
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
55Detecting local intrusion or implementing counter-measures
56Computer malware detection or handling, e.g. anti-virus arrangements
Appl.No 05111725 Applicant MICROSOFT CORP Inventor MARINESCU ADRIAN M
A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.
100.PI0505778método e sistema para um dispositivo de auto-cura
BR 19.09.2006
Int.Class Appl.No PI 0505778-7 Applicant MICROSOFT CORP Inventor MARINESCU ADRIAN M
101.20060137010Method and system for a self-heating device
US 22.06.2006
Int.Class G06F 11/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
Appl.No 11018412 Applicant Microsoft Corporation Inventor Kramer Michael

A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.

102.2527475A METHOD AND SYSTEM FOR A SELF-HEALING DEVICE
CA 21.06.2006
Int.Class G06F 11/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
Appl.No 2527475 Applicant MICROSOFT CORPORATION Inventor MARINESCU, ADRIAN M.
A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.
103.2005237166A method and system for a self-healing device
AU 15.12.2005
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No 2005237166 Applicant Microsoft Corporation Inventor Carter-Schwendler, Carl
104.WO/2006/115935PROTECTING A COMPUTER THAT PROVIDES A WEB SERVICE FROM MALWARE
WO 02.11.2006
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No PCT/US2006/014743 Applicant MICROSOFT CORPORATION Inventor SEINFELD, Marc E.
In accordance with the present invention, a system, method, and computer-readable medium for identifying malware in a request to a Web service is provided. One aspect of the present invention is a computer-implemented method for protecting a computer that provides a Web service from malware made in a Web request. When a request is received, an on-demand compilation system compiles high-level code associated with the request into binary code that may be executed. However, before the code is executed, antivirus software designed to identify malware scans the binary code for malware. If malware is identified, the antivirus software prevents the binary code associated with the request from being executed.
105.1658557Architecture for controlling access to a service by concurrent clients
CN 24.08.2005
Int.Class H04L 12/00
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
12Data switching networks
Appl.No 200510004163.8 Applicant Microsoft Corp. Inventor Seinfeld Marc E.
Architecture for controlling access to a service. The architecture allows denial of regular and periodic service to all but a selected number of concurrent clients associated with a subscriber, and without any manual administration at the server of a list of specific computers. Rather than require an administered list, the system discovers which clients are active, places the active clients on an active list, and excludes all client not on the active list. The system includes one or more rules the enforcement of which provide a mechanism for ensuring that the subscriber is not adding an unlimited number of clients or rotating clients in and out of the pool to effectively maintain service on a larger number of computers to which the subscriber is entitled.
106.20060130141System and method of efficiently identifying and removing active malware from a computer
US 15.06.2006
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No 11012892 Applicant Microsoft Corporation Inventor Kramer Michael

The present invention provides a system, method, and computer-readable medium for identifying and removing active malware from a computer. Aspects of the present invention are included in a cleaner tool that may be obtained automatically with an update service or may be downloaded manually from a Web site or similar distribution system. The cleaner tool includes a specialized scanning engine that searches a computer for active malware. Since the scanning engine only searches for active malware, the amount of data downloaded and resource requirements of the cleaner tool are less than traditional antivirus software. The scanning engine searches specific locations on a computer, such as data mapped in memory, configuration files, and file metadata for data characteristic of malware. If malware is detected, the cleaner tool removes the malware from the computer.

107.PI0600631sistema e processo para identificar e remover software potencialmente indesejado
BR 28.11.2006
Int.Class Appl.No PI 0600631-0 Applicant MICROSOFT CORP Inventor LOH ALVIN
108.1708115System and method for identifying and removing potentially unwanted software
EP 04.10.2006
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 06111545 Applicant MICROSOFT CORP Inventor LOH ALVIN
A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.
109.20060218145Identifying and removing potentially unwanted software
US 28.09.2006
Int.Class G06F 17/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
17Digital computing or data processing equipment or methods, specially adapted for specific functions
Appl.No 11092995 Applicant Microsoft Corporation Inventor Butcher Angela K.

A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.

110.2534728SYSTEM AND METHOD FOR IDENTIFYING AND REMOVING POTENTIALLY UNWANTED SOFTWARE
CA 28.09.2006
Int.Class G06F 11/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
Appl.No 2534728 Applicant MICROSOFT CORPORATION Inventor LOH, ALVIN
A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.
111.102272771Shared repository of malware data
CN 07.12.2011
Int.Class G06F 21/24
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
24by protecting data directly, e.g. by labelling
Appl.No 200980153819.9 Applicant Microsoft Corp. Inventor Kuo Chengi Jimmy
Various principles for maintaining a shared repository of authorization scanning results, which may be populated with results of authorization scans of particular files (and other content units) as well as a signature for those particular files. When a particular file is to be scanned by a client computing device to determine whether it contains unauthorized software, a signature for the file may be calculated and provided to the shared repository. If the repository has a result for that file-as indicated by a signature for the file being present in the repository-the result in the repository may be provided to the client computing device that issued the query, and the client computing device may accept the answer in the shared repository. If the result is not in the repository (i.e., the file has not been scanned), then the file may be scanned, and a result may be placed in the repository.
112.1020050078192DETECTION OF EXECUTABLE CODE-FREE COMPUTER FILES
KR 04.08.2005
Int.Class G06F 9/44
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
44Arrangements for executing specific programs
Appl.No 1020040104254 Applicant MICROSOFT CORP. Inventor SEINFELD MARC E.

PURPOSE: Detection of executable code-free computer files is provided to protect a computer system from infection of a new software virus by detecting the executable code-free computer files.

CONSTITUTION: An input file is parsed to recognize a file format of the input file(702). It is checked whether the executable code is present in the input file and contents of the input file are confirmed according to the recognized file format(706). When the file format of the input file is recognized and the executable code is not found, a file-has-no-code status is transmitted(710). When the executable code is found, a file-has-code status is transmitted(712).

© KIPO 2006

113.2005216286DETECTION OF CORD-FREE FILE
JP 11.08.2005
Int.Class G06F 11/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
Appl.No 2004368217 Applicant MICROSOFT CORP Inventor SEINFELD MARC E

PROBLEM TO BE SOLVED: To detect executable code-free computer files.

SOLUTION: In one embodiment, input files are parsed to recognize their file formats (102). If the file formats recognized in order to determine whether executable codes exist within the input files are usable, the contents of the input files are inspected according to the file formats recognized (104). Next, a status is sent according to this inspection (106).

COPYRIGHT: (C)2005,JPO&NCIPI

114.1020080002755PROTECTING A COMPUTER THAT PROVIDES A WEB SERVICE FROM MALWARE
KR 04.01.2008
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No 1020077019923 Applicant MICROSOFT CORP. Inventor SEINFELD MARC E.
In accordance with the present invention, a system, method, and computer-readable medium for identifying malware in a request to a Web service is provided. One aspect of the present invention is a computer-implemented method for protecting a computer that provides a Web service from malware made in a Web request. When a request is received, an on-demand compilation system compiles high-level code associated with the request into binary code that may be executed. However, before the code is executed, antivirus software designed to identify malware scans the binary code for malware. If malware is identified, the antivirus software prevents the binary code associated with the request from being executed. ©KIPO&WIPO 2008
115.2006277747SYSTEM AND METHOD FOR IDENTIFYING AND REMOVING POTENTIALLY UNWANTED SOFTWARE
JP 12.10.2006
Int.Class G06F 21/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
Appl.No 2006088388 Applicant MICROSOFT CORP Inventor LOU ALVIN

PROBLEM TO BE SOLVED: To provide a system and a method for identifying and removing potentially unwanted software.

SOLUTION: A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying a potentially unwanted program is displayed in a GUI that allows the user to inhibit continued operation of the program. For example, any software not on a list of well-known, harmless applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.

COPYRIGHT: (C)2007,JPO&INPIT

116.1020060071306METHOD AND SYSTEM FOR RECOVERING/RESTORING COMPUTING DEVICE INFECTED WITH MALWARE
KR 26.06.2006
Int.Class G06F 15/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
15Digital computers in general; Data processing equipment in general
Appl.No 1020050103655 Applicant MICROSOFT CORP. Inventor MARINESCU ADRIAN M.

PURPOSE: A method and a system for a self-healing device are provided to recover and restore a computing device infected with malware by analyzing whether there is any change between infected time and a restorable time earlier than the infected time.

CONSTITUTION: The system includes a malware information repository, a system inspection information repository, and a processor. Clearing up evidence of infection caused from malware attack and identifying the changes generated after the evidence for the infection, the processor recovers the malware attack by removing the changes based on at least one of malware information and system inspection information.

© KIPO 2006

117.2006178934METHOD AND SYSTEM FOR SELF-HEALING DEVICE
JP 06.07.2006
Int.Class G06F 21/22
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
21Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
22by restricting access to, or manipulation of, programmes or processes
Appl.No 2005332030 Applicant MICROSOFT CORP Inventor MARINESCU ADRIAN M

PROBLEM TO BE SOLVED: To provide a device that can self-heal from malicious software attacks such as viruses and worms.

SOLUTION: Changes made between the time that an infection resulting from an attack on the device is detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes are made, whether the changes are bona fide or malware-induced, whether the changes are made after the time that the infection likely occurred, and whether new software is installed.

COPYRIGHT: (C)2006,JPO&NCIPI

118.1648812Detection of code-free files
CN 03.08.2005
Int.Class G06F 1/00
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
1Details not covered by groups G06F3/-G06F13/82
Appl.No 200410061564.2 Applicant Microsoft Corp. Inventor Seinfeld Marc E.
Detection of code-free files is described. According to one implementation, an input file is parsed to recognize a file format. Contents of the input file are checked according to the recognized file format, if available, in an effort to determine whether executable code might exist within the input file. A status is then sent in response to the checking.
119.101542451Protecting a computer that provides a web service from malware
CN 23.09.2009
Int.Class G06F 12/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
12Accessing, addressing or allocating within memory systems or architectures
14Protection against unauthorised use of memory
Appl.No 200680009408.9 Applicant Microsoft Corp. Inventor Seinfeld Marc E.
In accordance with the present invention, a system, method, and computer-readable medium for identifying malware in a request to a Web service is provided. One aspect of the present invention is a computer-implemented method for protecting a computer that provides a Web service from malware made in a Web request. When a request is received, an on-demand compilation system compiles high-level code associated with the request into binary code that may be executed. However, before the code is executed, antivirus software designed to identify malware scans the binary code for malware. If malware is identified, the antivirus software prevents the binary code associated with the request from being executed.
120.1020060103826SYSTEM AND METHOD FOR IDENTIFYING/REMOVING POTENTIALLY UNNEEDED SOFTWARE BY OFFERING SCANNER DATA INTO GENERAL APPLICATION MANAGEMENT GUI
KR 04.10.2006
Int.Class G06F 9/06
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
Appl.No 1020060011043 Applicant MICROSOFT CORP. Inventor LOH ALVIN

PURPOSE: A system and a method for identifying and removing potentially unneeded software are provided to enable a user to identify which software is potentially unneeded by offering scanner data into a general application management GUI(Graphic User Interface).

CONSTITUTION: A list of needed programs is generated. The programs not present in the list are identified as the potentially unneeded program by comparing the list with other programs(110). The potentially unneeded program is presented to the user on the list(120). The user selects interruption of the potentially unneeded program(130). A function for isolating and recovering the potentially unneeded programs instead of the user is provided to the user.

© KIPO 2006

121.105518619Scanning files for inappropriate content during synchronization
CN 20.04.2016
Int.Class G06F 8/658
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
8Arrangements for software engineering
60Software deployment
65Updates
658Incremental updates; Differential updates
Appl.No 201480034638.5 Applicant MICROSOFT CORP Inventor SEINFELD MARC E
The present invention extends to methods, systems, and computer program products for scanning files for inappropriate content during file synchronization. Embodiments of the invention are mindful of the order of operations when scanning files for inappropriate content and in subsequent file processing. In some embodiments, during synchronization, an intermediary server scans a file for inappropriate content. The file is not permitted to be fully downloaded to a client device until the scan determines that the file does not contain inappropriate content. In other embodiments, during synchronization, a client device scans a newer version of a file for inappropriate content. An older version of the file is not deleted until the scan determines that the newer version of the file does not contain inappropriate content. In further embodiments, server side scanning and client side scanning are both used to enhance capabilities for detecting inappropriate content.
122.1841319System and method for identifying and removing potentially unwanted software
CN 04.10.2006
Int.Class G06F 9/44
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
9Arrangements for program control, e.g. control units
06using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
44Arrangements for executing specific programs
Appl.No 200610051556.9 Applicant Microsoft Corp. Inventor Loh Alvin
A system and method for identifying and removing potentially unwanted software. A mechanism is provided that identifies suspect programs to a user and allows the user to prevent the suspect programs from running without actually deleting them. In one embodiment, scanner data identifying potentially unwanted software is displayed in a GUI that allows the user to inhibit its continued execution. For example, any software not on a list of known, benign applications/processes may be identified as potentially unwanted. Similarly, software that displays one or more suspect behaviors may be so identified, allowing the user to distinguish between normal and suspect software without irreversibly altering the user's system.
123.1794193A method and system for a self-healing device
CN 28.06.2006
Int.Class G06F 11/14
GPHYSICS
06COMPUTING; CALCULATING OR COUNTING
FELECTRIC DIGITAL DATA PROCESSING
11Error detection; Error correction; Monitoring
07Responding to the occurrence of a fault, e.g. fault tolerance
14Error detection or correction of the data by redundancy in operation, e.g. by using different operation sequences leading to the same result
Appl.No 200510126800.9 Applicant Microsoft Corp. Inventor Marinescu Adrian M.
A self-healing device is provided in which changes made between the time that an infection resulting from an attack on the device was detected and an earlier point in time to which the device is capable of being restored may be recovered based, at least in part, on what kinds of changes were made, whether the changes were bona fide or malware induced, whether the changes were made after the time that the infection likely occurred, and whether new software was installed.