IP Library Granted Patent US 8,468,604
Granted Patent B2
US 8,468,604 · App. 11/541,413 · Granted Jun 18, 2013

Method and system for detecting malware

Inventors: Christopher Hercules Claudatos (San Jose, CA); Jason A Baim (Providence, RI); Daniel S Cobb (Shrewsbury, MA)
Assignee: EMC Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,468,604
App. No.
11/541,413
Filed
Sep 29, 2006
Granted
Jun 18, 2013
Kind
B2
Art Unit
2433
USPC
726/24
Abstract

A method for protecting objects in a computer system against malware is disclosed. An object is analyzed to determine whether it is infected by malware, and if it is determined to be infected, a backup copy of the object is located in a backup of the objects. The infected object is replaced with the backup copy.

Claims (28)

1. A method for protecting objects in a system comprising a backup including backup copies of the objects, the method comprising:

determining a pattern associated with an object by performing a size-based analysis, using at least one backup copy from the backup copies of the object, wherein performing the size-based analysis includes determining a first size of the object selected from a group comprising a current size of the object and a size of a backup copy of the object and, determining a second size of another backup copy of the object, wherein determining the pattern includes determining modification times of the backup copies of the object and, deriving a frequency of modification based on the modification times of the backup copies of the object;

detecting a deviation from the pattern to identify an anomaly indicating that the object is infected by malware, wherein detecting the deviation from the pattern includes comparing the first size to the second size based on a size change threshold for the object and, analyzing a binary pattern of the object if the first size is same as the second size, wherein detecting the deviation from the pattern includes identifying a change to a first portion of the object that is expected to remain the same, wherein detecting the deviation from the pattern includes identifying an absence of a change to a second portion of the object that is expected to change, wherein the first and second portions of the object are located at respective first and second offsets within the object;

determining a magnitude of the deviation from the pattern; and

comparing the magnitude of the deviation to a threshold, wherein the threshold is determined according to known object profiles.

2. The method as recited in claim 1 , wherein detecting the deviation from the pattern to identify an anomaly includes returning a positive result if the first size is larger than the second size.

3. The method as recited in claim 1 , further comprising determining a size change threshold for the object, and wherein detecting the deviation from the pattern to identify an anomaly includes returning a positive result if the first size is larger than the second size by at least the size change threshold.

4. The method as recited in claim 1 , further comprising determining size change thresholds for a plurality of objects.

5. The method as recited in claim 1 , wherein determining the pattern includes determining sizes of backup copies of the object, and performing statistical analysis on the sizes of backup copies.

6. The method as recited in claim 5 , wherein detecting a deviation from the pattern to identify an anomaly includes analyzing a size of the object or a size of a backup copy of the object with respect to the sizes of the backup copies.

7. The method as recited in claim 6 , wherein detecting a deviation from the pattern to identify an anomaly further includes returning a positive result if the size of the object or a size of a backup copy of the object is larger than a size predicted by the statistical analysis.

8. The method as recited in claim 1 , wherein detecting a deviation from the pattern to identify an anomaly includes returning a positive result if a modification time of the object or a modification time of a backup copy of the object is inconsistent with the derived frequency.

9. The method as recited in claim 1 , wherein detecting a deviation from the pattern to identify an anomaly includes returning a positive result if a modification time of the object occurs earlier than a modification time predicted from the derived frequency.

10. The method as recited in claim 1 , wherein detecting a deviation from the pattern to identify an anomaly includes returning a positive result if a modification time of the object occurs later than a modification time predicted from the derived frequency.

11. The method as recited in claim 1 , further comprising determining an infection point in time when the object became infected by malware.

12. The method as recited in claim 11 , wherein the infection point is determined from a time of occurrence of the identified anomaly.

13. The method as recited in claim 12 , further comprising retrieving a backup copy made prior to the infection point.

14. The method as recited in claim 13 , further comprising replacing the object with the retrieved backup copy.

15. A computer program product for protecting objects in a system comprising a backup including backup copies of the objects, the computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining a pattern associated with an object by performing a size-based analysis, using at least one backup copy from the backup copies of the object, wherein performing the size-based analysis includes determining a first size of the object selected from a group comprising a current size of the object and a size of a backup copy of the object and, determining a second size of another backup copy of the object, wherein determining the pattern includes determining modification times of the backup copies of the object and, deriving a frequency of modification based on the modification times of the backup copies of the object;

detecting a deviation from the pattern to identify an anomaly indicating that the object is infected by malware, wherein detecting the deviation from the pattern includes comparing the first size to the second size based on a size change threshold for the object and, analyzing a binary pattern of the object if the first size is same as the second size, wherein detecting the deviation from the pattern includes identifying a change to a first portion of the object that is expected to remain the same, wherein detecting the deviation from the pattern includes identifying an absence of a change to a second portion of the object that is expected to change, wherein the first and second portions of the object are located at respective first and second offsets within the object;

determining a magnitude of the deviation from the pattern; and

comparing the magnitude of the deviation to a threshold, wherein the threshold is determined according to known object profiles.

16. A system for protecting objects, comprising a backup including copies of the objects, and a processor configured to:

determine a pattern associated with an object by performing a size-based analysis, using at least one backup copy from the backup copies of the object, wherein performing the size-based analysis includes determining a first size of the object selected from a group comprising a current size of the object and a size of a backup copy of the object and, determining a second size of another backup copy of the object, wherein determining the pattern includes determining modification times of the backup copies of the object and, deriving a frequency of modification based on the modification times of the backup copies of the object;

detect a deviation from the pattern to identify an anomaly indicating that the object is infected by malware, wherein detecting the deviation from the pattern includes comparing the first size to the second size based on a size change threshold for the object and, analyzing a binary pattern of the object if the first size is same as the second size, wherein detecting the deviation from the pattern includes identifying a change to a first portion of the object that is expected to remain the same, wherein detecting the deviation from the pattern includes identifying an absence of a change to a second portion of the object that is expected to change, wherein the first and second portions of the object are located at respective first and second offsets within the object;

determine a magnitude of the deviation from the pattern; and

compare the magnitude of the deviation to a threshold, wherein the threshold is determined according to known object profiles.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2006
From: CLAUDATOS, CHRISTOPHER HERCULES; BAIM, JASON A.; COBB, DANIEL S.
To: EMC CORPORATION
Reel/Frame 018493/0564 →
Continuity (3)
Continuation In Part 11505559 · Aug 16, 2006
Provisional Application 60708969 · Aug 16, 2005
Related Publication 20080047013A1 · Feb 21, 2008