IP Library Patent Application 11260914
Patent Application
App. No. 11/260,914

Detecting exploit code in network flows

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/260,914
Abstract

Disclosed is a method and apparatus for detecting exploit code in network flows. Network data packets are intercepted by a flow monitor which generates data flows from the intercepted data packets. A content filter filters out legitimate programs from the data flows, and the unfiltered portions are provided to a code recognizer which detects executable code. Any embedded executable code in the unfiltered data flow portions is identified as a suspected exploit in the network flow. The executable code recognizer recognizes executable code by performing convergent binary disassembly on the unfiltered portions of the data flows. The executable code recognizer then constructs a control flow graph and performs control flow analysis, data flow analysis, and constraint enforcement in order to detect executable code. In addition to identifying detected executable code as a potential exploit, the detected executable code may then be used in order to generate a signature of the potential exploit, for use by other systems in detecting the exploit.

Claims (54)

1 . A method for monitoring network traffic comprising the steps of:

intercepting network data packets;

generating data flows from said intercepted data packets;

filtering out at least portions of said data flows; and

detecting executable code in unfiltered portions of said data flows.

2 . The method of claim 1 wherein said filtering is based upon a set of predetermined rules.

3 . The method of claim 1 wherein said step of filtering comprises:

filtering out legitimate program code from said data flows.

4 . The method of claim 3 further comprising the step of:

determining if said legitimate program code contains malicious code.

5 . The method of claim 1 further comprising the step of:

identifying said detected executable code as a potential exploit.

6 . The method of claim 1 wherein said step of detecting executable code comprises:

performing convergent binary disassembly on said unfiltered portions of said data flows.

7 . The method of claim 6 wherein said step of detecting executable code further comprises:

constructing a control flow graph; and

performing control flow analysis using said control flow graph.

8 . The method of claim 7 wherein said step of detecting executable code further comprises:

performing data flow analysis; and

performing constraint enforcement.

9 . The method of claim 1 further comprising the step of:

generating a code signature from said detected executable code.

10 . A system for monitoring network traffic comprising:

a network interface for receiving intercepted network data packets;

a flow monitor for generating data flows from said intercepted network data packets;

a content filter for filtering out at least portions of said data flows; and

an executable code recognizer for detecting executable code in unfiltered portions of said data flows.

11 . The system of claim 10 wherein said content filter stores a set of filtering rules.

12 . The system of claim 10 wherein said content filter filters out legitimate program code from said data flows.

13 . The system of claim 12 further comprising:

a malicious program analyzer for determining whether said legitimate program code contains malicious code.

14 . The system of claim 10 wherein said executable code recognizer performs convergent binary disassembly.

15 . A system for monitoring network traffic comprising:

means for intercepting network data packets;

means for generating data flows from said intercepted data packets;

means for filtering out at least portions of said data flows; and

means for detecting executable code in unfiltered portions of said data flows.

16 . The system of claim 15 wherein said means for filtering comprises a set of predetermined rules.

17 . The system of claim 15 wherein said means for filtering comprises:

means for filtering out legitimate program code from said data flows.

18 . The system of claim 17 further comprising:

means for determining if said legitimate program code contains malicious code.

19 . The system of claim 15 further comprising:

means for identifying said detected executable code as a potential exploit.

20 . The system of claim 15 wherein said means for detecting executable code comprises:

means for performing convergent binary disassembly on said unfiltered portions of said data flows.

21 . The system of claim 20 wherein said means for detecting executable code further comprises:

means for constructing a control flow graph; and

means for performing control flow analysis using said control flow graph.

22 . The system of claim 21 wherein said means for detecting executable code further comprises:

means for performing data flow analysis; and

means for performing constraint enforcement.

23 . The system of claim 15 further comprising:

means for generating a code signature from said detected executable code.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2012
From: TELCORDIA LICENSING COMPANY LLC
To: TTI INVENTIONS C LLC
Reel/Frame 027678/0854 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2009
From: TELCORDIA TECHNOLOGIES, INC.
To: TELCORDIA LICENSING COMPANY, LLC
Reel/Frame 022871/0920 →
RELEASE OF SECURITY INTEREST Recorded Mar 17, 2009
From: WILMINGTON TRUST COMPANY
To: TELCORDIA TECHNOLOGIES, INC.
Reel/Frame 022408/0410 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2006
From: VAN DEN BERG, ERIC; CHINCHANI, RAMKUMAR
To: TELCORDIA TECHNOLOGIES, INC.
Reel/Frame 017209/0389 →