IP Library Granted Patent US 6,973,577
Granted Patent B1
US 6,973,577 · App. 09/579,810 · Granted Dec 6, 2005

System and method for dynamically detecting computer viruses through associative behavioral analysis of runtime state

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,973,577
App. No.
09/579,810
Granted
Dec 6, 2005
Kind
B1
Abstract

A system and a method for dynamically detecting computer viruses through associative behavioral analysis of runtime state are described. A group of monitored events is defined. Each monitored event includes a set of one or more actions defined within an object. Each action is performed by one or more applications executing within a defined computing environment. The runtime state within the defined computing environment is continuously monitored for an occurrence of any one of the monitored events in the group. The sequence of the execution of the monitored events is tracked for each of the applications. Each occurrence of a specific event sequence characteristic of computer virus behavior and the application that performed the specific event sequence, are identified. A histogram describing the specific event sequence occurrence for each of the applications is created. Repetitions of the histogram associated with at least one object are identified.

Claims (45)

1. A system for dynamically detecting computer viruses through associative behavioral analysis of runtime state, comprising:

a parameter set stored on a client system defining a group of monitored events, each monitored event comprising a set of one or more actions defined within an object, each action being performed by one or more applications executing within a defined computing environment;

a monitor executing on the client system, comprising:

a collector continuously monitoring runtime state within the defined computing environment for an occurrence of any one of the monitored events in the group and tracking a sequence of execution of the monitored events for each of the applications;

an analyzer identifying each occurrence of a specific event sequence characteristic of behavior of a computer virus and the application which performed the specific event sequence, creating a histogram describing the specific event sequence occurrence for each of the applications, and identifying repetitions of the histogram associated with at least one object;

a storage manager organizing the histograms into plurality of records ordered by object, application, and monitored event; and

a structured database in which the plurality of records is stored;

wherein the storage manager stores each histogram for each such specific event sequence occurrence in one such database record identified by the application by which the specific event sequence was performed;

wherein the storage manager configures the structured database as an event log organized by each event in the group of monitored events and updates the database record storing each specific event sequence occurrence with a revised histogram as each such occurrence is identified.

2. A system according to claim 1 , further comprising:

the analyzer detecting suspect activities within each histogram, each suspect activity comprising a set of known actions comprising a computer virus signature.

3. A system according to claim 2 , wherein each such suspect activity is selected from a class of actions comprising file accesses, program executions, message transmissions, configuration area accesses, security setting accesses, and impersonations.

4. A system according to claim 2 , wherein each such suspect activity is selected from a group comprising files accesses, program executions, direct disk accesses, media formatting operations, sending of electronic mail, system configuration area accesses, changes to security settings, impersonations, and system calls having the ability to monitor system input/output activities.

5. A system according to claim 1 , wherein the computer virus comprises at least one form of unauthorized content selected from a group comprising a computer virus application, a Trojan horse application, and a hoax application.

6. A method for dynamically detecting computer viruses through associative behavioral analysis of runtime state, comprising:

defining a group of monitored events, each monitored event comprising a set of one or more actions defined within an object, each action being performed by one or more applications executing within a defined computing environment;

continuously monitoring runtime state within the defined computing environment for an occurrence of any one of the monitored events in the group;

tracking a sequence of execution of the monitored events for each of the applications;

identifying each occurrence of a specific event sequence characteristic of behavior of a computer virus and the application which performed the specific event sequence;

creating a histogram describing the specific event sequence occurrence for each of the applications;

identifying repetitions of the histogram associated with at least one object;

organizing the histograms into plurality of records ordered by object, application, and monitored event;

maintaining a structured database in which the plurality of records is stored;

storing each histogram for each such specific event sequence occurrence in one such database record identified by the application by which the specific event sequence was performed;

configuring the structured database as an event log organized by each event in the group of monitored events; and

updating the database record storing each specific event sequence occurrence with a revised histogram as each such occurrence is identified.

7. A method according to claim 6 , further comprising:

detecting suspect activities within each histogram, each suspect activity comprising a set of known actions comprising a computer virus signature.

8. A method according to claim 7 , wherein each such suspect activity is selected from a class of actions comprising file accesses, program executions, message transmissions, configuration area accesses, security setting accesses, and impersonations.

9. A method according to claim 7 , wherein each such suspect activity is selected from a group comprising files accesses, program executions, direct disk accesses, media formatting operations, sending of electronic mail, system configuration area accesses, changes to security settings, impersonations, and system calls having the ability to monitor system input/output activities.

10. A method according to claim 6 , wherein the computer virus comprises at least one form of unauthorized content selected from a group comprising a computer virus application, a Trojan horse application, and a hoax application.

11. A computer-readable storage medium holding code for dynamically detecting computer viruses through associative behavioral analysis of runtime state, comprising:

defining a group of monitored events, each monitored event comprising a set of one or more actions defined within an object, each action being performed by one or more applications executing within a defined computing environment;

continuously monitoring runtime state within the defined computing environment for an occurrence of any one of the monitored events in the group;

tracking a sequence of execution of the monitored events for each of the applications;

identifying each occurrence of a specific event sequence characteristic of behavior of a computer virus and the application which performed the specific event sequence;

creating a histogram describing the specific event sequence occurrence for each of the applications;

identifying repetitions of the histogram associated with at least one object;

organizing the histograms into plurality of records ordered by object, application, and monitored event;

maintaining a structured database in which the plurality of records is stored;

storing each histogram for each such specific event sequence occurrence in one such database record identified by the application by which the specific event sequence was performed;

configuring the structured database as an event log organized by each event in the group of monitored events; and

updating the database record storing each specific event sequence occurrence with a revised histogram as each such occurrence is identified.

12. A storage medium according to claim 11 , further comprising:

detecting suspect activities within each histogram, each suspect activity comprising a set of known actions comprising a computer virus signature.

Assignments (7)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →