IP Library Granted Patent US 9,178,907
Granted Patent B2
US 9,178,907 · App. 11/450,110 · Granted Nov 3, 2015

System, method and computer program product for detecting encoded shellcode in network traffic

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,178,907
App. No.
11/450,110
Granted
Nov 3, 2015
Kind
B2
Abstract

A system, method and computer program product are provided for detecting encoded shellcode. In use, network traffic that is encoded is identified. Further, it is determined whether the network traffic that is encoded includes shellcode.

Claims (115)

1. A method, comprising:

identifying network traffic that is encoded, utilizing a processor;

determining a type of encoding associated with the network traffic;

converting the network traffic that is encoded;

determining whether the network traffic that is encoded includes shellcode;

counting predetermined instructions; and

determining whether a number of the predetermined instructions exceeds at least one threshold,

wherein the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text,

wherein the at least one threshold is determined based on an application associated with the network traffic.

2. A method, comprising:

identifying network traffic that is encoded, utilizing a processor;

determining a type of encoding associated with the network traffic;

converting the network traffic that is encoded; and

determining whether the network traffic that is encoded includes shellcode,

wherein the determination whether the network traffic includes the shellcode is

conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the act of determining whether the network traffic that is encoded includes shellcode comprises:

determining whether the network traffic that is encoded includes shellcode without the use of signatures identifying known unwanted data.

3. A method, comprising:

identifying network traffic that is encoded, utilizing a processor;

determining a type of encoding associated with the network traffic;

converting the network traffic that is encoded; and

determining whether the network traffic that is encoded includes shellcode,

wherein the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the act of determining whether the network traffic that is encoded includes shellcode comprises:

detecting a number of predetermined instructions in the network traffic; and

determining whether the number of predetermined instructions exceeds a threshold,

wherein the threshold is based on an application utilizing the network traffic.

4. A method, comprising:

identifying network traffic that is encoded, utilizing a processor;

determining a type of encoding associated with the network traffic;

converting the network traffic that is encoded; and

determining whether the network traffic that is encoded includes shellcode,

wherein the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the act of determining whether the network traffic that is encoded includes shellcode comprises:

detecting a number of predetermined instructions in the network traffic; and

determining whether a number of predetermined instructions exceeds a threshold,

wherein the threshold is based on a type of the network traffic that is encoded.

5. A method, comprising:

identifying network traffic that is encoded, utilizing a processor;

determining a type of encoding associated with the network traffic;

converting the network traffic that is encoded; and

determining whether the network traffic that is encoded includes shellcode,

wherein the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the act of determining whether the network traffic that is encoded includes shellcode comprises:

detecting predetermined instructions within the network traffic, wherein each predetermined instruction is associated with a weight; and

determining whether the predetermined instructions within the network traffic exceed a threshold, wherein the threshold is associated with the weights of the predetermined instructions.

6. A computer program product embodied on a nontransitory computer readable medium, comprising:

computer code for identifying network traffic that is encoded;

computer code for determining a type of encoding associated with the network traffic;

computer code for converting the network traffic that is encoded; and

computer code for determining whether the network traffic that is encoded at least potentially includes shellcode,

wherein the computer program product is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the computer code for determining whether the network traffic that is encoded at least potentially includes shellcode comprises:

computer code for detecting a number of predetermined instructions in the network traffic; and

computer code for determining whether the number of predetermined instructions exceeds a threshold,

wherein the threshold is based on an application utilizing the network traffic.

7. A computer program product embodied on a non-transitory computer readable medium, comprising:

computer code for identifying network traffic that is encoded;

computer code for determining a type of encoding associated with the network traffic;

computer code for converting the network traffic that is encoded; and

computer code for determining whether the network traffic that is encoded at least potentially includes shellcode,

wherein the computer program product is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the computer code for determining whether the network traffic that is encoded at least potentially includes shellcode comprises:

computer code for detecting a number of predetermined instructions in the network traffic; and

computer code for determining whether the number of predetermined instructions exceeds a threshold,

wherein the threshold is based on a type of the network traffic that is encoded.

8. A computer program product embodied on a non-transitory computer readable medium, comprising:

computer code for identifying network traffic that is encoded;

computer code for determining a type of encoding associated with the network traffic;

computer code for converting the network traffic that is encoded; and

computer code for determining whether the network traffic that is encoded at least potentially includes shellcode,

wherein the computer program product is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the computer code for determining whether the network traffic that is encoded at least potentially includes shellcode comprises:

computer code for detecting predetermined instructions within the network traffic, wherein each predetermined instruction is associated with a weight; and

computer code for determining whether the predetermined instructions within the network traffic exceed a threshold, wherein the threshold is associated with the weights of the predetermined instructions.

9. A system, comprising:

a client device for receiving encoded network traffic, comprising a processor; and

a security application installed on the client device, the security application for determining a type of encoding associated with the network traffic, converting the network traffic that is encoded, and determining whether the encoded network traffic includes shellcode,

wherein the security application is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the security application comprises instructions that when executed by the processor, cause the processor to perform actions comprising:

detecting a number of predetermined instructions in the network traffic; and

determining whether the number of predetermined instructions exceeds a threshold,

wherein the threshold is based on an application utilizing the network traffic.

10. A system, comprising:

a client device for receiving encoded network traffic, comprising a processor; and

a security application installed on the client device, the security application for determining a type of encoding associated with the network traffic, converting the network traffic that is encoded, and determining whether the encoded network traffic includes shellcode,

wherein the security application is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the security application comprises instructions that when executed by the processor, cause the processor to perform actions comprising:

detecting a number of predetermined instructions in the network traffic; and

determining whether the number of predetermined instructions exceeds a threshold,

wherein the threshold is based on a type of the network traffic that is encoded.

11. A system, comprising:

a client device for receiving encoded network traffic, comprising a processor; and

a security application installed on the client device, the security application for determining a type of encoding associated with the network traffic, converting the network traffic that is encoded, and determining whether the encoded network traffic includes shellcode,

wherein the security application is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the security application comprises instructions that when executed by the processor, cause the processor to perform actions comprising:

detecting predetermined instructions within the network traffic, wherein each predetermined instruction is associated with a weight; and

determining whether the predetermined instructions within the network traffic exceed a threshold, wherein the threshold is associated with the weights of the predetermined instructions.

12. A system, comprising:

a client device for receiving encoded network traffic, comprising a processor; and

a security application installed on the client device, the security application for determining a type of encoding associated with the network traffic, converting the network traffic that is encoded, and determining whether the encoded network traffic includes shellcode,

wherein the security application is operable such that the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text, and

wherein the security application comprises:

a detection routine, selected based on characteristics of the client device.

13. A method, comprising:

identifying network traffic that is encoded, utilizing a processor;

determining a type of encoding associated with the network traffic;

converting the network traffic that is encoded;

determining whether the network traffic that is encoded includes shellcode; and

selecting a detection routine,

wherein the determination whether the network traffic includes the shellcode is conditionally performed based on a determination whether the network traffic comprises machine language instructions encoded as text,

wherein the act of determining whether the network traffic that is encoded includes shellcode is performed by the detection routine, and

wherein the act of selecting a detection routine comprises:

selecting a detection routine based on characteristics of a system from which the network traffic is received.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →