IP Library Granted Patent US 8,402,529
Granted Patent B1
US 8,402,529 · App. 12/130,609 · Granted Mar 19, 2013

Preventing propagation of malicious software during execution in a virtual machine

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,402,529
App. No.
12/130,609
Granted
Mar 19, 2013
Kind
B1
Abstract

A system and method for preventing propagation of malicious content associated with an electronic message are disclosed. An electronic message and content associated with the electronic message is simulated in a virtual machine which emulates the destination computing device of the electronic message. A virtual firewall receives one or more commands as the electronic message or content associated with an electronic message is executed. Initially, the virtual firewall establishes a network connection and determines the type of action associated with the commands. If the type of action comprises a connection maintenance or configuration command, the network connection is maintained. If the type of action comprises a data transmission command, the network connection is terminated. This allows the virtual machine to simulate performance of a networked computer by transmitting a subset of the data through a network connection.

Claims (22)

1. An apparatus for preventing propagation of malicious content specifying a destination computing device during simulation of execution of content, comprising: a plurality of virtual machines for executing the content in a simulation environment simulating an environment associated with the destination computing device; a simulation manager for receiving the content and associating a destination virtual machine from the plurality of virtual machines with the content; a virtual firewall adapted to communicate with the simulation manager and the plurality of virtual machines, the virtual firewall establishing a connection to a network, communicating the content to the destination virtual machine and applying one or more access rules to identify a network access command that includes a type of a network action received from the destination virtual machine during execution of the content, wherein the one or more access rules modify the connection to the network, the virtual firewall also preventing the network access command from propagating to a second virtual machine, and wherein the one or more access rules comprise responsive to determining the network access command is non-malicious, determining to allow the network access command to access the connection to the network; responsive to determining the network access command is malicious, terminating the connection to the network before the network access command transmits data using the connection to the network; and responsive to failing to determine whether the network access command is malicious or non-malicious, determining to allow the network access command to access the connection to the network, monitoring data including one or more data types transmitted by the network access command via the connection to the network, and responsive to detecting transmission of the one or more data types via the connection to the network, terminating the connection to the network, wherein the one or more data types include one or more of configuration data, user data, and registry data.

2. The apparatus of claim 1 , wherein determining the network access command is non-malicious comprises:

determining the network access command comprises a command to maintain the connection to the network.

3. The apparatus of claim 2 , wherein the command to maintain the connection to the network comprises a status request, a domain name server (DNS) lookup request, a hypertext transfer protocol (HTTP) request or a packet internet grouper (PING) command.

4. The apparatus of claim 1 , wherein determining the network access command is malicious comprises:

determining the network access command is a command to transmit data via the connection to the network.

5. The apparatus of claim 4 , wherein the command to transmit data via the connection to the network comprises: a file transfer protocol (FTP) request, a simple mail transfer protocol (SMTP) session request, a server message block (SMB) file transfer request, a Distributed File System (DFS) request or a Network Basic Input/Output (NetBIOS) session service request.

6. The apparatus of claim 1 , wherein determining the network access command is malicious comprises:

determining the network access command comprises a command to transmit a subset of data via the connection to the network.

7. The apparatus of claim 6 , wherein the subset of data comprises: configuration data, user identification data, registry data or contact data.

8. A computer-implemented method for preventing propagation of malicious content during execution of content, comprising: associating the content with a virtual machine; establishing a network connection; receiving a network access command generated by execution of the content in the virtual machine using an environment similar to an environment of a destination computing device; applying one or more access rules to identify the network access command that includes a type of network action, the one or more access rules specifying whether the network connection is maintained; modifying the network connection responsive to the one or more access rules; and wherein the one or more access rules comprise responsive to determining the network access command is non-malicious, determining to allow the network access command to access the connection to the network; responsive to determining the network access command is malicious, terminating the connection to the network before the network access command transmits data using the connection to the network; and responsive to failing to determine whether the network access command is malicious or non-malicious, determining to allow the network access command to access the connection to the network, monitoring data including one or more data types transmitted by the network access command via the connection to the network, and responsive to detecting transmission of the one or more data types via the connection to the network, terminating the connection to the network, wherein the one or more data types include one or more of configuration data, user data, and registry data.

9. The computer-implemented method of claim 8 , wherein determining the network access command is non-malicious comprises:

determining the network access command comprises a command to maintain the network connection.

10. The computer-implemented method of claim 9 , wherein the command to maintain the network connection comprises a status request, a domain name server (DNS) lookup request, a hypertext transfer protocol (HTTP) request or a packet internet grouper (PING) command.

11. The computer-implemented method of claim 8 , wherein determining the network access command is malicious comprises:

determining the network access command is a command to transmit data via the network connection.

12. The computer-implemented method of claim 11 , wherein the command to transmit data via the network connection comprises: a file transfer protocol (FTP) request, a simple mail transfer protocol (SMTP) session request, a server message block (SMB) file transfer request, a Distributed File System (DFS) request or a Network Basic Input/Output (NetBIOS) session service request.

13. The computer-implemented method of claim 8 , wherein determining the network access command is malicious comprises:

determining the network access command comprises a command to transmit a subset of data via the network connection.

14. The computer-implemented method of claim 13 , wherein the subset of data comprises: configuration data, user identification data, registry data or contact data.

15. The computer-implemented method of claim 8 , further comprising:

preventing the network access command from accessing a second virtual machine, the second virtual machine not associated with the content.

Assignments (14)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
SECURITY INTEREST Recorded Jan 8, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066050/0947 →
MERGER Recorded Jun 16, 2015
From: M86 SECURTIY, INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 035926/0716 →
SECURITY AGREEMENT Recorded Jul 10, 2012
From: TRUSTWAVE HOLDINGS, INC.; TW SECURITY CORP.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 028518/0700 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2012
From: AVINTI ACQUISITION CORPORATION, INC.
To: M86 SECURITY, INC.
Reel/Frame 027777/0691 →
SECURITY AGREEMENT Recorded Mar 30, 2011
From: M86 SECURITY, INC.; M86 AMERICAS, INC.; AVINTI ACQUISITION CORP.
To: PROVIDENCE TMT DEBT OPPORTUNITY FUND II L.P.; PECM STRATEGIC FUNDING L.P.
Reel/Frame 026065/0804 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2008
From: GREEN, DAVID E.; PAYNE, RICHARD; WOOD, TREVOR
To: AVINTI CORPORATION
Reel/Frame 021652/0608 →