IP Library Granted Patent US 9,100,425
Granted Patent B2
US 9,100,425 · App. 13/308,522 · Granted Aug 4, 2015

Method and apparatus for detecting malicious software using generic signatures

Inventors: Oliver Friedrichs (Woodside, CA); Alfred Huger (Calgary, CA); Adam J. O'Donnell (San Francisco, CA)
Assignee: Cisco Technology, Inc.
H04L63/1416G06F21/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,100,425
App. No.
13/308,522
Granted
Aug 4, 2015
Kind
B2
Abstract

Novel methods, components, and systems for automatically detecting malicious software are presented. More specifically, methods, components, and systems for the automated deployment of generic signatures to detect malicious software. Even more specifically, computer implemented methods for determining whether a software application is likely malicious including computing at a client component a generic fingerprint for a software application, transmitting the generic fingerprint data to a server component, receiving at the client component information from the server component relating to the generic fingerprint of the software application, and following a prescribed set of actions based on the information received from the server.

Claims (53)

1. A computer implemented method for determining whether a software application is likely malicious, comprising:

receiving, at a server component, both a specific fingerprint and a generic fingerprint computed at a client component for a software application received at the client component;

storing, at the server component, a blacklist comprising a plurality of specific fingerprints of software applications known to be malicious;

storing, at the server component, a data structure comprising a plurality of known generic fingerprints and, for each known generic fingerprint, a set of specific fingerprints associated with the known generic fingerprint;

determining whether the software application is conclusively malicious by comparing the received specific fingerprint to the blacklist of specific fingerprints;

in the event the software application is not determined to be conclusively malicious from comparing the received specific fingerprint to the blacklist of specific fingerprints, determining that the software application is conclusively malicious in response to the number of malicious specific fingerprints associated with one of the known generic fingerprints that matches the received generic fingerprint exceeding a predetermined threshold; and

transmitting to the client component an indication of whether the software application is malicious or benign from processing the received specific fingerprint and the received generic fingerprint.

2. A non-transitory computer readable storage medium, provided at a server component, encoded with software comprising computer executable instructions and when the software is executed operable to:

receive both a specific fingerprint and a generic fingerprint computed at a client component for a software application received at the client component;

store in a memory a blacklist comprising a plurality of specific fingerprints of software applications known to be malicious;

store in the memory a data structure comprising a plurality of known generic fingerprints and, for each known generic fingerprint, a set of specific fingerprints associated with the known generic fingerprint;

determine whether the software application is conclusively malicious by comparing the received specific fingerprint to the blacklist of specific fingerprints;

in the event the software application is not determined to be conclusively malicious from comparing the received specific fingerprint to the blacklist of specific fingerprints, determine that the software application is conclusively malicious in response to the number of malicious specific fingerprints associated with one of the known generic fingerprints that matches the received generic fingerprint exceeding a predetermined threshold; and

transmit to the client component an indication of whether the software application is malicious or benign from processing the received specific fingerprint and the received generic fingerprint.

3. An apparatus, comprising:

a memory configured to store a blacklist comprising a plurality of specific fingerprints of software applications known to be malicious and to store a data structure comprising a plurality of known generic fingerprints and, for each known generic fingerprint, a set of specific fingerprints associated with the known generic fingerprint; and

a processor configured to:

receive both a specific fingerprint and a generic fingerprint computed at a client component for a software application received at the client component;

determine whether the software application is conclusively malicious by comparing the received specific fingerprint to the blacklist of specific fingerprints;

in the event the software application is not determined to be conclusively malicious from comparing the received specific fingerprint to the blacklist of specific fingerprints, determine that the software application is conclusively malicious in response to the number of malicious specific fingerprints associated with one of the known generic fingerprints that matches the received generic fingerprint exceeding a predetermined threshold; and

transmit to the client component an indication of whether the software application is malicious or benign from processing the received specific fingerprint and the received generic fingerprint.

4. The computer implemented method according to claim 1 , wherein:

in the event the software application is not determined to be conclusively malicious from comparing the received specific fingerprint to the blacklist of specific fingerprints, determining that the software application is possibly malicious in response to the number of malicious specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being one or more but being less than the predetermined threshold.

5. The computer implemented method according to claim 1 , further comprising:

storing, at the server component, a whitelist comprising a plurality of specific fingerprints of software applications known to be benign;

determining whether the software application is conclusively benign by comparing the received specific fingerprint to the whitelist of specific fingerprints; and

transmitting to the client component an indication that software application is benign in response to determining that the specific fingerprint is conclusively benign.

6. The computer implemented method according to claim 5 , wherein the determination of whether the software application is conclusively malicious based on the received generic fingerprint is performed only in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints.

7. The computer implemented method according to claim 5 , wherein:

in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints, determining whether the software application is conclusively benign in response to the number of benign specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint exceeding another predetermined threshold and none of the specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being malicious.

8. The computer implemented method according to claim 5 , wherein:

in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints, determining whether the software application is possibly benign in response to one or more specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being benign.

9. The non-transitory computer readable storage medium according to claim 2 , further comprising computer executable instructions operable to:

determine, in the event the software application is not determined to be conclusively malicious from comparing the received specific fingerprint to the blacklist of specific fingerprints, that the software application is possibly malicious in response to the number of malicious specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being one or more but being less than the predetermined threshold.

10. The non-transitory computer readable storage medium according to claim 2 , further comprising computer executable instructions operable to:

store a whitelist comprising a plurality of specific fingerprints of software applications known to be benign;

determine whether the software application is conclusively benign by comparing the received specific fingerprint to the whitelist of specific fingerprints; and

transmit to the client component an indication that software application is benign in response to determining that the specific fingerprint is conclusively benign.

11. The non-transitory computer readable storage medium according to claim 10 , wherein the computer executable instructions that determine whether the software application is conclusively malicious based on the received generic fingerprint are executed only in the event the software application is determined neither to be conclusively benign nor conclusively malicious from the computer executable instructions that compare the received specific fingerprint to the whitelist and blacklist of specific fingerprints.

12. The non-transitory computer readable storage medium according to claim 10 , further comprising computer executable instructions operable to:

determine, in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints, whether the software application is conclusively benign in response to the number of benign specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint exceeding another predetermined threshold and none of the specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being malicious.

13. The non-transitory computer readable storage medium according to claim 10 , further comprising computer executable instructions operable to:

determine, in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints, whether the software application is possibly benign in response to one or more specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being benign.

14. The apparatus according to claim 3 , wherein the processor is further configured to determine, in the event the software application is not determined to be conclusively malicious from comparing the received specific fingerprint to the blacklist of specific fingerprints, that the software application is possibly malicious in response to the number of malicious specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being one or more but being less than the predetermined threshold.

15. The apparatus according to claim 3 , wherein the processor is further configured to:

store a whitelist comprising a plurality of specific fingerprints of software applications known to be benign;

determine whether the software application is conclusively benign by comparing the received specific fingerprint to the whitelist of specific fingerprints; and

transmit to the client component an indication that software application is benign in response to determining that the specific fingerprint is conclusively benign.

16. The apparatus according to claim 15 , wherein the processor is further configured to determine whether the software application is conclusively malicious based on the received generic fingerprint only in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints.

17. The apparatus according to claim 15 , wherein the processor is further configured to:

determine, in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints, whether the software application is conclusively benign in response to the number of benign specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint exceeding another predetermined threshold and none of the specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being malicious.

18. The apparatus according to claim 15 , wherein the processor is further configured to:

determine, in the event the software application is determined neither to be conclusively benign nor conclusively malicious from comparing the received specific fingerprint to the whitelist and blacklist of specific fingerprints, whether the software application is possibly benign in response to one or more specific fingerprints associated with the known generic fingerprint that matches the received generic fingerprint being benign.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2014
From: IMMUNET LLC
To: SOURCEFIRE LLC
Reel/Frame 033235/0701 →
CHANGE OF NAME Recorded Jul 2, 2014
From: IMMUNET CORPORATION
To: IMMUNET LLC
Reel/Frame 033267/0471 →
CHANGE OF NAME Recorded Mar 24, 2014
From: SOURCEFIRE, INC.
To: SOURCEFIRE LLC
Reel/Frame 032513/0481 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2014
From: SOURCEFIRE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 032513/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2012
From: FRIEDRICHS, OLIVER; HUGER, ALFRED A.; O'DONNELL, ADAM J.
To: IMMUNET CORPORATION
Reel/Frame 027797/0740 →
Continuity (5)
Provisional Application 61418532 · Dec 1, 2010
Provisional Application 61418514 · Dec 1, 2010
Provisional Application 61418547 · Dec 1, 2010
Provisional Application 61418580 · Dec 1, 2010
Related Publication 20120210422A1 · Aug 16, 2012