IP Library Granted Patent US 9,088,601
Granted Patent B2
US 9,088,601 · App. 13/308,539 · Granted Jul 21, 2015

Method and apparatus for detecting malicious software through contextual convictions, generic signatures and machine learning techniques

Inventors: Oliver Friedrichs (Woodside, CA); Alfred Huger (Calgary, CA); Adam J. O'Donnell (San Francisco, CA)
Assignee: Cisco Technology, Inc.
H04L63/1416G06F21/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,088,601
App. No.
13/308,539
Granted
Jul 21, 2015
Kind
B2
Abstract

Novel methods, components, and systems that enhance traditional techniques for detecting malicious software are presented. More specifically, methods, components, and systems that use important contextual information from a client system (such as recent history of events on that system), machine learning techniques, the automated deployment of generic signatures, and combinations thereof, to detect malicious software. The disclosed invention provides a significant improvement with regard to automation compared to previous approaches.

Claims (48)

1. A computer implemented method for determining whether a software application is malicious, comprising:

extracting a feature vector from said software application;

transmitting said feature vector from said software application to a server application;

receiving information from said server application relating to a determination as to whether the software application is benign or malicious based, at least in part, on said feature vector;

extracting metadata about the software application and gathering contextual information about a system on which the software application may be installed;

transmitting said metadata and contextual information to said server application, wherein the contextual information comprises websites visited by a client system and a geographic location of the client system;

receiving information from said server application relating to a determination as to whether the software application is benign or malicious based, at least in part, on said metadata and contextual information;

computing a generic fingerprint for the software application;

transmitting said generic fingerprint to said server application; and

receiving information from said server application relating to a determination as to whether the software application is benign or malicious based, at least in part, on said generic fingerprint; and

performing an action with respect to the software application based on the information received from the server application and that was generated based on the feature vector, the metadata, the contextual information, and the generic fingerprint.

2. A computer implemented method for determining whether a software application is malicious, comprising:

receiving at a server application information from a client application concerning:

(i) a feature vector from said software application;

(ii) metadata about the application and contextual information about a system on which the software application may be installed, wherein the contextual information comprises websites visited by a client system and a geographic location of the client system; and

(iii) a generic fingerprint for the software application;

applying a machine-learning derived classification algorithm to the feature vector, if feature vector information is received from the client application;

examining metadata concerning the software application and contextual information about the client system, if metadata and contextual information are received from the client system;

determining whether the generic signature should be deemed malicious, if a generic signature for the software application is received from the client application; and

making a determination as to whether the software application should be deemed malicious with regard to the client application; and

transmitting to the client application information generated based on the feature vector, the metadata, the contextual information, and the generic fingerprint and concerning the determination as to whether the software application should be deemed malicious.

3. The computer implemented method according to claim 2 , wherein said metadata is selected from the group consisting of traditional fingerprints and generic signatures.

4. The computer implemented method according to claim 2 , wherein said server application and said client application reside on separate and remote computing devices.

5. The computer implemented method according to claim 2 , wherein said client application continuously gathers contextual information.

6. Non-transitory computer readable storage medium containing instructions for making a determination concerning whether a software application is malicious, said instructions comprising instructions for:

extracting a feature vector from said software application;

transmitting said feature vector to a server application;

receiving information from said server application relating to a determination as to whether the software application is benign or malicious based, at least in part, on said feature vector;

extracting metadata about the software application and gathering contextual information about a system on which the software application may be installed;

transmitting said metadata and contextual information to the server application;

receiving information from said server application relating to a determination as to whether the software application is benign or malicious based, at least in part, on said metadata and contextual information, wherein the contextual information comprises websites visited by a client system and a geographic location of the client system;

computing a generic fingerprint for the software application;

transmitting said generic fingerprint to said server application; and

receiving information from said server application relating to a determination as to whether the software application is benign or malicious based, at least in part, on said generic fingerprint; and

performing an action with respect to the software application based on the information received from the server application and that was generated based on the feature vector, the metadata, the contextual information, and the generic fingerprint.

7. Non-transitory computer readable storage medium containing instructions for making a determination concerning whether a software application is malicious, said instructions comprising instructions for:

receiving at a server application information from a client application concerning:

(i) a feature vector from said software application;

(ii) metadata about the software application and contextual information about a system on which the software application may be installed, wherein the contextual information comprises websites visited by a client system and a geographic location of the client system; and

(iii) a generic fingerprint for the software application;

applying a machine-learning derived classification algorithm to the feature vector, if feature vector information is received from the client system;

examining metadata concerning the software application and contextual information about the client system, if metadata and contextual information are received from the client system;

determining whether the generic signature should be deemed malicious, if a generic signature for the software application is received from the client system;

making a determination as to whether the software application should be deemed malicious with regard to the client application; and

transmitting to the client application information generated based on the feature vector, the metadata, the contextual information, and the generic fingerprint and concerning the determination as to whether the software application should be deemed malicious to.

8. The non-transitory computer readable storage medium according to claim 7 , wherein said metadata is selected from the group consisting of traditional fingerprints and generic signatures.

9. The non-transitory computer readable storage medium according to claim 7 , wherein said server application and said client application reside on separate and remote computing devices.

10. The non-transitory computer readable storage medium according to claim 7 , wherein said client application continuously gathers contextual information.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2014
From: IMMUNET LLC
To: SOURCEFIRE LLC
Reel/Frame 033235/0701 →
CHANGE OF NAME Recorded Jul 2, 2014
From: IMMUNET CORPORATION
To: IMMUNET LLC
Reel/Frame 033267/0471 →
CHANGE OF NAME Recorded Mar 24, 2014
From: SOURCEFIRE, INC.
To: SOURCEFIRE LLC
Reel/Frame 032513/0481 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2014
From: SOURCEFIRE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 032513/0513 →
MERGER Recorded Jul 22, 2013
From: IMMUNET CORPORATION; CLOUD ACQUISITION CORPORATION
To: SOURCEFIRE, INC.
Reel/Frame 030847/0389 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2012
From: FRIEDRICHS, OLIVER; HUGER, ALFRED A.; O'DONNELL, ADAM J.
To: IMMUNET CORPORATION
Reel/Frame 027798/0676 →
Continuity (5)
Provisional Application 61418532 · Dec 1, 2012
Provisional Application 61418514 · Dec 1, 2012
Provisional Application 61418547 · Dec 1, 2012
Provisional Application 61418580 · Dec 1, 2012
Related Publication 20120210423A1 · Aug 16, 2012