US 12,450,334 B2
Malware deterrence using computer environment indicators
Nera Pershing Schwartz, Singapore (SG); Harish Tammaji Kulkarni, Singapore (SG); Kumudini Choyal, Tung Chung (HK); Mahesh Ramesh Bane, Mumbai (IN); and Vaibhav Shankar Tambe, Dombiwali (IN)
Assigned to Bank of America Corporation, Charlotte, NC (US)
Filed by Bank of America Corporation, Charlotte, NC (US)
Filed on Feb. 2, 2024, as Appl. No. 18/431,016.
Application 18/431,016 is a continuation of application No. 17/540,778, filed on Dec. 2, 2021, granted, now 11,934,515.
Prior Publication US 2024/0202317 A1, Jun. 20, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/00 (2013.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01); H04L 9/40 (2022.01)
CPC G06F 21/53 (2013.01) [G06F 21/566 (2013.01); H04L 63/1416 (2013.01); H04L 63/145 (2013.01)] 18 Claims
OG exemplary drawing
 
1. An apparatus comprising at least one hardware processor and a memory storing computer-readable instructions that, when executed by the at least one hardware processor, cause the apparatus to:
determine an environmental indicator used by a target filtering mechanism associated with a malware program to prevent execution in a sandbox environment, wherein the environmental indicator comprises an indication of a file system structure of the sandbox environment;
determine whether the environmental indicator is within a predetermined percentile of environmental indicators, in a malware database, arranged in a priority order from lowest priority to highest priority, wherein the priority order of the environmental indicators is based on respective quantities of malware programs using the environmental indicators; and
based on determining that the environmental indicator is within the predetermined percentile of the environmental indicators:
generate, based on the environmental indicator, an inoculation message for transmission to one or more computing devices in a computing network, wherein the inoculation message comprises the indication of the file system structure; and
send, to the one or more computing devices, the inoculation message, wherein the inoculation message causes the one or more computing devices to integrate the indication of the file system structure into corresponding computing environments of the one or more computing devices.