IP Library Granted Patent US 8,204,984
Granted Patent B1
US 8,204,984 · App. 11/998,750 · Granted Jun 19, 2012

Systems and methods for detecting encrypted bot command and control communication channels

Assignee: FireEye, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,204,984
App. No.
11/998,750
Granted
Jun 19, 2012
Kind
B1
Abstract

Methods and systems for detecting encrypted bot command and control communication channels are provided. In the exemplary method, the presence of a communication channel between a first network device and a second network device is monitored. Active and inactive periods of the network device are detected and a reverse channel is determined based on the detection. The first network device may then be flagged as potentially infected or suspected based on the reverse channel determination.

Claims (32)

1. A system comprising:

a channel monitoring module configured to monitor a channel between a first network device and a second network device;

an active/inactive detector module configured to detect an active period and an inactive period of the first network device;

a reverse channel detection module comprising instructions stored on a computer readable medium, the reverse channel detection module being configured to detect an establishment of communication by the first network device and a direction for communication over the channel thereafter based on the detected active period and the inactive period of the first network device with respect to the second network device, the reverse channel detection module being further configured to determine the reverse channel based on communications over the channel being substantially in a reverse direction after the detected establishment; and

a flagging module configured to flag the first network device as potentially infected by a bot based on the reverse channel determination.

2. The system of claim 1 , further comprising a whitelist module for determining if the first network device is associated with a white list.

3. The system of claim 1 , wherein the channel monitoring module is further configured to determine if an IRC channel is established by the first network device.

4. The system of claim 1 , further comprising a network scanning module configured to determine if the first network device scans a network.

5. The system of claim 1 , further comprising a controller configured to simulate data flow between the first network device and the second network device.

6. The system of claim 5 , wherein the controller comprises a replayer and a virtual machine, the replayer configured to transmit the data flow to the virtual machine.

7. The system of claim 6 , wherein an infection by the bot is confirmed based on an analysis of a response of the virtual machine.

8. The system of claim 5 , wherein the controller further comprises a signature module configured to generate a signature to identify the bot.

9. The system of claim 8 , wherein the controller is further configured to send the signature to a bot detector.

10. The system of claim 1 , wherein the flagging module is further configured to assign a color category to the first network device for review by an administrator.

11. A method comprising:

monitoring a channel between a first network device and a second network device;

detecting an active period and an inactive period of the first network device;

determining a reverse channel based on the detected active period and the inactive period of the first network device with respect to the second network device, the determining including detecting establishment of communication by the first network and a direction for communication over the channel thereafter, and detecting communications over the channel being substantially in a reverse direction after the detected establishment; and

flagging the first network device as potentially infected by a bot based on the reverse channel determination.

12. The method of claim 11 , further comprising determining if the reverse channel is associated with a white list.

13. The method of claim 11 , further comprising determining if an IRC channel is established by the first network device.

14. The method of claim 11 , further comprising determining if the first network device scans a network.

15. The method of claim 11 , further comprising simulating a data flow between the first network device and the second network device.

16. The method of claim 15 , further comprising transmitting the data flow to a virtual machine.

17. The method of claim 15 , further comprising confirming an infection by the bot based on analysis of a response of the virtual machine.

18. The method of claim 11 , further comprising generating a signature to identify the bot.

19. The method of claim 18 , further comprising sending the signature to a bot detector.

20. A non-transitory computer readable medium having embodied thereon executable instructions, the instructions being executable by a processor for detecting encrypted bot command & control communication channels, the method comprising:

monitoring a channel between a first network device and a second network device;

detecting an active period and an inactive period of the first network device;

determining a reverse channel based on the detected active period and the inactive period of the first network device with respect to the second network device, the determining including detecting establishment of communication by the first network and a direction for communication over the channel thereafter, and detecting communications over the channel being substantially in a reverse direction after the detected establishment; and

flagging the first network device as potentially infected by a bot based on the reverse channel determination.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Feb 2, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 062636/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 061447/0039 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2007
From: AZIZ, ASHAR; LAI, WEI-LUNG; MANNI, JAYARAMAN
To: FIREEYE, INC.
Reel/Frame 020240/0466 →
Continuity (10)
Continuation In Part 11494990 · Jul 28, 2006
Continuation In Part 11471072 · Jun 19, 2006
Continuation In Part 11409355 · Apr 20, 2006
Continuation In Part 11096287 · Mar 31, 2005
Continuation In Part 11151812 · Jun 13, 2005
Continuation In Part 11152286 · Jun 13, 2005
Provisional Application 60868324 · Dec 1, 2006
Provisional Application 60559198 · Apr 1, 2004
Provisional Application 60579953 · Jun 14, 2004
Provisional Application 60579910 · Jun 14, 2004