IP Library Granted Patent US 8,291,499
Granted Patent B2
US 8,291,499 · App. 13/423,057 · Granted Oct 16, 2012

Policy based capture with replay to virtual machine

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,291,499
App. No.
13/423,057
Granted
Oct 16, 2012
Kind
B2
Abstract

A suspicious activity capture system can comprise a tap configured to copy network data from a communication network, and a controller. The controller is coupled to the tap and is configured to receive the copy of the network data from the tap, analyze the copy of the network data to flag the network data as suspicious, and simulate transmission of the network data to a destination device.

Claims (42)

1. An unauthorized activity capture system comprising:

a tap configured to copy network data from a communication network; and

a controller coupled to the tap and configured to receive the copy of the network data from the tap, compare the copy of the network data to at least one policy to determine if the copy of the network data has one or more characteristics of a computer worm, flag at least a portion of the copy of the network data as suspicious by flagging the at least a portion of the copy of the network data for replay in an analysis environment based upon the determination that the at least a portion of the compared copy of the network data has one or more characteristics of a computer worm, and replay transmission of the suspicious, flagged network data copied from the communication network to a destination device.

2. The unauthorized activity capture system of claim 1 wherein the at least one policy is configured to detect network data directed to a honey pot.

3. The unauthorized activity capture system of claim 1 wherein the at least one policy is configured to detect network data directed to a device that includes trade secret data.

4. The unauthorized activity capture system of claim 1 wherein the at least one policy is configured to detect an identity of a device to which network data is directed.

5. The unauthorized activity capture system of claim 1 wherein the at least one policy is configured to detect network data transmitted from a device that does not transmit network data in normal operation.

6. The unauthorized activity capture system of claim 1 wherein the at least one policy is configured to detect network data attempting to gain rights within the communication network.

7. The unauthorized activity capture system of claim 1 wherein the controller further comprises a virtual machine pool configured to store a virtual machine.

8. The unauthorized activity capture system of claim 1 wherein the one or more characteristics of a computer worm include being configured to duplicate itself for propagation.

9. An unauthorized activity capture system comprising:

a tap configured to copy network data from a communication network; and

a controller configured to receive the copy of the network data from the tap, compare the copy of the network data to at least one policy within a policy engine to determine if the copy of the network data has one or more characteristics of a computer worm, flag at least a portion of the copy of the network data as suspicious by flagging the at least a portion of the copy of the network data for replay in an analysis environment based upon the determination that the at least a portion of the analyzed copy of the network data has one or more characteristics of a computer worm, retrieve a virtual machine, configure a replayer to replicate the flagged at least a portion of the compared copy of the network data which contains suspicious activity to the virtual machine, and identify unauthorized activity by analyzing a behavior of the virtual machine in response to the replication of the flagged at least a portion of the compared copy of the network data.

10. The unauthorized activity capture system of claim 9 wherein the at least one policy is configured to detect network data directed to a honey pot.

11. The unauthorized activity capture system of claim 9 wherein the at least one policy is configured to detect network data directed to a device that includes trade secret data.

12. The unauthorized activity capture system of claim 9 wherein the at least one policy is configured to detect an identity of a device to which network data is directed.

13. The unauthorized activity capture system of claim 9 wherein the at least one policy is configured to detect network data transmitted from a device that does not transmit network data in normal operation.

14. The unauthorized activity capture system of claim 9 wherein the at least one policy is configured to detect network data attempting to gain rights within the communication network.

15. The unauthorized activity capture system of claim 9 wherein the unauthorized activity is the result of malware associated with the network data.

16. The unauthorized activity capture system of claim 9 wherein the controller further comprises a virtual machine pool configured to store the virtual machine.

17. The unauthorized activity capture system of claim 9 wherein the flagged at least a portion of the copy of network data is replicated between the replayer and the virtual machine over a virtual switch.

18. The unauthorized activity capture system of claim 9 wherein the one or more characteristics of a computer worm include being configured to duplicate itself for propagation.

19. An unauthorized activity capture method comprising:

copying network data from a communication network;

comparing the copied network data to at least one policy to determine if the copied network data has one or more characteristics of a computer worm;

flagging at least a portion of the copied network data as suspicious by flagging the at least a portion of the copy of the network data for replay in an analysis environment based upon the determination that the at least a portion of the compared copied network data has one or more characteristics of a computer worm; and

replaying transmission of the flagged at least a portion of the compared copied network data which was copied from the communication network to a destination device to identify unauthorized activity based on playback of the flagged suspicious at least a portion of the compared copy of the network data.

20. The method of claim 19 wherein replaying the transmission of the flagged at least a portion of the compared copied network data comprises:

retrieving a virtual machine configured to receive the flagged at least a portion of the compared copied network data;

configuring a replayer to transmit the flagged at least a portion of the compared copied network data to the virtual machine; and

performing a simulation by transmitting the flagged at least a portion of the compared copied network data to the virtual machine.

21. The method of claim 20 wherein retrieving the virtual machine includes accessing a virtual machine pool.

22. The method of claim 20 wherein the flagged at least a portion of the compared copied network data is transmitted between the replayer and the virtual machine over a virtual switch.

23. The method of claim 19 wherein the at least one policy is configured to detect network data directed to a honey pot.

24. The method of claim 19 wherein the at least one policy is configured to detect network data directed to a device that includes trade secret data.

25. The method of claim 19 wherein the at least one policy is configured to detect an identity of a device to which network data is directed.

26. The method of claim 19 wherein the at least one policy is configured to detect network data transmitted from a device that does not transmit network data in normal operation.

27. The method of claim 19 wherein the at least one policy is configured to detect network data attempting to gain rights within the communication network.

28. The method of claim 19 wherein identifying the unauthorized activity includes identifying malware associated with the network data.

29. The method of claim 19 wherein the one or more characteristics of a computer worm include being configured to duplicate itself for propagation.

30. A non-transitory computer readable medium comprising:

computer readable code configured to direct a processor to copy network data from a communication network, compare the copied network data to at least one policy within a policy engine to determine if the copied network data has one or more characteristics of a computer worm, flag at least a portion of the compared copied network data as suspicious by flagging the at least a portion of the copy of the network data for replay in an analysis environment based upon the determination that the at least a portion of the compared copied network data has one or more characteristics of a computer worm, and replay transmission of the flagged suspicious at least a portion of the compared copied network data copied from the network to a destination device to identify unauthorized activity based on playback of the flagged suspicious at least a portion of the compared copied network data.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 061449/0366 →
CHANGE OF NAME Recorded Sep 15, 2022
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 061434/0528 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2012
From: AZIZ, ASHAR; DRZEWIECKI, ADRIAN; RADHAKRISHNAN, RAMESH; MANNI, JAYARAMAN; AMIN, MUHAMMAD
To: FIREEYE, INC.
Reel/Frame 028268/0115 →