IP Library Granted Patent US 7,801,840
Granted Patent B2
US 7,801,840 · App. 11/829,592 · Granted Sep 21, 2010

Threat identification utilizing fuzzy logic analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,801,840
App. No.
11/829,592
Granted
Sep 21, 2010
Kind
B2
Abstract

A method, system, computer program product, and/or computer readable medium of instructions for identifying a malicious entity in a processing system, comprising determining an entity threat value for an entity, the entity threat value being indicative of a level of threat that the entity represents to the processing system, wherein the entity threat value is determined based on one or more characteristics of the entity; and compare the entity threat value to an entity threat threshold to identify if the entity is malicious. In another form, there is provided a method, system, computer program product, and/or computer readable medium of instructions for identifying a malicious entity in a processing system, comprising determining one or more input values indicative of an entity; and performing a fuzzy logic analysis in relation to the one or more input values to identify if the entity is malicious.

Claims (52)

1. A method of identifying a malicious entity in a processing system, wherein the method comprises:

determining, by a processor, an entity threat value for an entity, the entity threat value being indicative of a level of threat that the entity represents to the processing system, wherein the entity threat value is determined based on one or more characteristics of the entity; and

comparing, by a processor, the entity threat value to an entity threat threshold to identify if the entity is malicious.

2. The method according to claim 1 , wherein each of the one or more characteristics of the entity is associated with a respective characteristic threat value, wherein the method comprises calculating the entity threat value using at least some of the characteristic threat values for the one or more characteristics of the entity.

3. The method according to claim 2 , wherein at least one of the one or more characteristics of the entity is associated with a characteristic threat value formula, wherein the method comprises calculating, using the characteristic threat value formula, the characteristic threat value.

4. The method according to claim 3 , wherein at least one characteristic threat value is temporally dependent, wherein the method comprises calculating the at least one characteristic threat value for the entity using the characteristic threat value formula and a temporal value.

5. The method according to claim 3 , wherein the at least one characteristic is a behaviour associated with the entity, wherein the method comprises calculating the at least one characteristic threat value for the entity using the characteristic threat value formula and a frequency of instances the behaviour has been performed.

6. The method according to claim 2 , wherein the one or more characteristics comprises at least one of one or more legitimate characteristics indicative of non-malicious activity and one or more illegitimate characteristics indicative of malicious activity, wherein the method comprises determining the entity threat value using characteristic threat values associated with the one or more legitimate characteristics and the one or more illegitimate characteristics of the entity.

7. The method according to claim 6 , wherein the step of determining the entity threat value for an entity comprises calculating a difference between the characteristic threat values for the one or more legitimate characteristics of the entity, and the characteristic threat values for the one or more illegitimate characteristics of the entity, wherein the difference is indicative of the entity threat value.

8. The method according to claim 1 , wherein the method comprises:

determining one or more related entities to the entity, wherein each related entity has an associated entity threat value; and,

calculating the entity threat value for the entity using the entity threat value for at least some of the one or more related entities.

9. The method according to claim 8 , wherein the method comprises:

determining one or more related entities to the entity, wherein each related entity has an associated entity threat value; and,

calculating a group threat value for the entity and one or more related entities using the entity threat value for at least some of the one or more related entities and the entity.

10. The method according to claim 8 , wherein the method comprises weighting the entity threat value for at least one related entity according to a relatedness of the at least one related entity relative to the entity.

11. The method according to claim 1 , wherein the method comprises weighting the entity threat value for the entity according to permissions of the entity.

12. A system to identify a malicious entity in a processing system, wherein the system comprises:

a processor;

memory in electronic communication with the processor;

the processor configured to:

determine an entity threat value for an entity, the entity threat value being indicative of a level of threat that the entity represents to the processing system, wherein the entity threat value is determined based on one or more characteristics of the entity; and

compare the entity threat value to an entity threat threshold to identify if the entity is malicious.

13. A computer program product comprising a non-transitory computer readable medium having a computer program recorded therein or thereon, the computer program enabling identification of a malicious entity in a processing system, wherein the computer program product configures the processing system to:

determine an entity threat value for an entity, the entity threat value being indicative of a level of threat that the entity represents to the processing system, wherein the entity threat value is determined based on one or more characteristics of the entity; and

compare the entity threat value to an entity threat threshold to identify if the entity is malicious.

14. A method for identifying a malicious entity in a processing system, wherein the method comprises:

determining, by a processor, one or more input values indicative of an entity; and

performing, by a processor, a fuzzy logic analysis in relation to the one or more input values to identify if the entity is malicious.

15. The method according to claim 14 , wherein the method comprises determining an action to perform in regard to whether the entity is determined to be malicious.

16. The method according to claim 14 , wherein the one or more input values can comprise at least one of:

an entity threat value;

a group threat value;

a frequency of an event occurring;

a number of related entities to the entity; and

a number of child processes created by the entity.

17. A system to identify a malicious entity in a processing system, wherein the system

a processor;

memory in electronic communication with the processor;

the processor configured to:

determine one or more input values indicative of one or more characteristics of an entity; and

perform a fuzzy logic analysis in relation to the one or more input values to identify if the entity is malicious.

18. A system according to claim 17 , wherein the system is configured to determine an action to perform in regard to whether the entity is determined to be malicious.

19. The system according to claim 17 , wherein the one or more input values can comprise at least one of:

an entity threat value;

a group threat value;

a frequency of an event occurring;

a number of related entities to the entity; and

a number of child processes created by the entity.

20. A computer program product comprising a non-transitory computer readable medium having a computer program recorded therein or thereon, the computer program enabling identification of a malicious entity in a processing system, wherein the computer program product configures the processing system to:

determine one or more input values indicative of one or more characteristics of an entity; and

perform a fuzzy logic analysis in relation to the one or more input values to identify if the entity is malicious.

Assignments (6)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jan 30, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051759/0845 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2009
From: PC TOOLS TECHNOLOGY PTY LTD.
To: SYMANTEC CORPORATION
Reel/Frame 022960/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2007
From: REPASI, ROLF; CLAUSEN, SIMON; OLIVER, IAN; PEREIRA, RYAN
To: PC TOOLS TECHNOLOGY PTY LTD.
Reel/Frame 019867/0185 →