IP Library Patent Application 11824718
Patent Application
App. No. 11/824,718

Detecting adversaries by correlating detected malware with web access logs

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/824,718
Abstract

An automated arrangement for detecting adversaries is provided by examining a log that contains records of communications into and out of the enterprise network upon the detection of a security incident by which a host computer on an enterprise network becomes compromised. The log is analyzed over a window of time starting before the occurrence of the detected security incident to identify the web site URIs (Uniform Resource Identifiers) and IP (Internet Protocol) addresses (collectively “resources”) that were respectively accessed by the compromised host and/or from which traffic was received by the compromised host. When other host computers in the enterprise are detected as being compromised, a similar analysis is performed and the results of all the analyses are correlated to identify one or more resources that are common to the logged communications of all the compromised machines.

Claims (30)

1 . An automated method for detecting a malicious resource that is accessible by hosts in an enterprise network, the method comprising the steps of:

arranging the enterprise network so that each of a plurality of endpoints in the enterprise network may communicate security assessments over a communication channel;

analyzing, responsively to a security incident detected by an endpoint, a log that is maintained by a traffic monitoring endpoint that is arranged to monitor traffic crossing a boundary of the enterprise network;

analyzing, responsively to the detected security incident, a log that is maintained by an anti-malware endpoint that is arranged to detect malware on the hosts; and

correlating results of the respective analyses of the log maintained by the monitoring endpoint and the log maintained by the anti-malware endpoint to identify the malicious resource.

2 . The automated method of claim 1 in which the traffic monitoring endpoint is one of a firewall, proxy server, gateway or router.

3 . The automated method of claim 1 in which the malicious resource is an IP address or a website URI.

4 . The automated method of claim 1 including a further step of raising an alert.

5 . The automated method of claim 4 in which the alert is communicated via an endpoint in the enterprise network that is arranged for centralized logging of security assessments and auditing.

6 . The automated method of claim 1 in which the analyzing of the log maintained by the traffic monitoring endpoint identifies resources that were commonly accessed by compromised hosts during a time window.

7 . The automated method of claim 6 in which the time window is defined having a predetermined proximity to a time associated with the detected security incident.

8 . The automated method of claim 7 in which the time window is adjustable in response to user input.

9 . The automated method of claim 1 in which the analyzing of the log maintained by the anti-malware endpoint identifies a number of compromised hosts and the resource which caused the hosts to become compromised.

10 . The automated method of claim 9 in which the correlating includes applying a threshold to the number of compromised hosts when identifying the malicious resource.

11 . The automated method of claim 10 in which the threshold is adjustable in response to user input.

12 . The automated method of claim 5 in which the endpoint for centralized logging and auditing is configured with an interface for accepting user input to adjust sensitivity for the correlating.

13 . The automated method of claim 5 in which the endpoint for centralized logging and auditing is configured with an interface for accepting user input to block access to the malicious resource.

14 . A method for detecting an adversary to an enterprise network, the enterprise network supporting host computers, the method comprising the steps of:

generating a security assessment to describe detection of a security incident that results in one or more host computers becoming compromised, in which the generating is based at least in part on locally-available information about a system being monitored by the endpoint, the security assessment being arranged to provide contextual meaning to the incident and being defined with a fidelity to describe a degree of confidence in reliability of the detection, or with a severity to describe a degree of seriousness for the incident;

receiving the security assessment from a communication channel; and

correlating, in response to the receiving, anti-virus logs associated with the host computers with firewall logs to identify an IP address or URI that was commonly accessed by the compromised host computers.

15 . The method of claim 14 including a further step of excluding an IP address or URI as an adversary when the IP address or URI were commonly accessed by non-compromised host computers.

16 . The method of claim 14 in which the compromised host computers are infected by a virus or malware.

17 . The method of claim 14 in which the correlating is performed responsively to the fidelity of the security assessment or the severity of the incident.

18 . A method for managing an enterprise network that includes a plurality of endpoints that are arranged to share security assessments over a common communication channel, the method comprising the steps of:

receiving a security assessment at an endpoint in the enterprise network that is arranged for centralized logging and auditing of security assessments produced by the plurality of endpoints, the security assessment indicating a suspected malicious resource that is identified through correlation of an anti-virus log and a firewall log.

generating an alert that is presented on a user interface and arranged to notify a user of the suspected malicious resource; and

receiving input responsively to the alert that indicates an action to be taken.

19 . The method of claim 18 in which the action is one of blocking access to the suspected malicious resource or quarantining a host computer that accessed the malicious resource.

20 . The method of claim 18 in which the security assessment is arranged for providing an assignment of context by the endpoint to security-related information using a pre-defined taxonomy having a schematized vocabulary comprising object types and assessment categories.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2008
From: NEYSTADT, JOHN; HUDIS, EFIM; HELMAN, YAIR; FAYNBURD, ALEXANDRA
To: MICROSOFT CORPORATION
Reel/Frame 020700/0476 →