IP Library Granted Patent US 8,763,118
Granted Patent B2
US 8,763,118 · App. 13/629,765 · Granted Jun 24, 2014

Classification of software on networked systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,763,118
App. No.
13/629,765
Granted
Jun 24, 2014
Kind
B2
Abstract

A method and system for the classification of software in networked systems, includes: determining a software received by a sensor is attempting to execute on a computer system of the sensor; classifying the software as authorized or unauthorized to execute, and gathering information on the software by the sensor if the software is classified as unauthorized to execute. The sensor sends the information on the software to one or more actuators, which determine whether or not to act on one or more targets based on the information. If so, then the actuator sends a directive to the target(s). The target(s) updates its responses according to the directive. The classification of the software is definitive and is not based on heuristics or rules or policies and without any need to rely on any a priori information about the software.

Claims (37)

1. A method, comprising:

intercepting an execution attempt by software on a computing system;

classifying the software as authorized or unauthorized to execute on the computing system based on a set of identifiers that represents a set of software authorized to execute on the computing system;

gathering information about the software if the software is classified as unauthorized to execute on the computing system by correlating network packets with the software, wherein the network packets are correlated with the software by a time of the execution attempt or by matching a checksum of at least a portion of the software with a checksum of a pattern in the network packets, and the information gathered through the correlating step enables one or more targets to identify or block instances of the software; and

sending the information to one or more actuators for analysis and generation of a directive for the one or more targets.

2. The method of claim 1 , wherein the identifier comprises one or more of a hash of at least a portion of a set of bits representing the software, a checksum of at least a portion of a set of bits representing the software, a message digest of at least a portion of a set of bits representing the software, an operating system file name, an operating system file system internal designator, an operating system attribute, a file system attribute, and meta-data.

3. The method of claim 1 , further comprising:

generating an identifier for the software; and

determining if the identifier is a member of the set of identifiers,

wherein the software is classified as unauthorized to execute on the computer system if the identifier is not a member of the set of identifiers.

4. The method of claim 1 , wherein the software is classified after the software has executed on the computing system.

5. The method of claim 1 , wherein the information sent to the actuators includes one or more pieces of information from the correlated network packets.

6. The method of claim 5 , wherein the one or more pieces of information include one or more of: a source Internet Protocol (IP) address, a destination IP address, a source port, a destination port, a packet payload signature, and a packet header signature.

7. At least one computer readable medium comprising program instructions that when executed by a processor:

intercept an execution attempt by software on a computing system;

classify the software as authorized or unauthorized to execute on the computing system based on a set of identifiers that represents a set of software authorized to execute on the computing system;

gather information about the software if the software is classified as unauthorized to execute on the computing system by correlating network packets with the software, wherein the network packets are correlated with the software by a time of the execution attempt or by matching a checksum of at least a portion of the software with a checksum of a pattern in the network packets, and the information gathered through the correlating step enables one or more targets to identify or block instances of the software; and

send the information to one or more actuators for analysis and generation of a directive for the one or more targets.

8. The at least one computer readable medium of claim 7 , comprising further program instructions that when executed by a processor:

generate an identifier for the software; and

determine if the identifier is a member of the set of identifiers,

wherein the software is classified as unauthorized to execute on the computer system if the identifier is not a member of the set of identifiers.

9. The at least one computer readable medium of claim 7 , wherein the information sent to the actuators includes one or more pieces of information from the correlated network packets.

10. The at least one computer readable medium of claim 9 , wherein the one or more pieces of information include one or more of: a source Internet Protocol (IP) address, a destination IP address, a source port, a destination port, a packet payload signature, and a packet header signature.

11. An apparatus, comprising:

a computing system;

at least one sensor coupled to the computing system, the sensor configured to:

intercept an execution attempt by software on the computing system;

classify the software as authorized or unauthorized to execute on the computing system based on a set of identifiers that represents a set of software authorized to execute on the computing system;

gather information about the software if the software is classified as unauthorized to execute on the computing system by correlating network packets with the software, wherein the network packets are correlated with the software by a time of the execution attempt or by matching a checksum of at least a portion of the software with a checksum of a pattern in the network packets, and the information gathered through the correlating step enables one or more targets to identify or block instances of the software; and

send the information to one or more actuators for analysis and generation of a directive for the one or more targets.

12. The apparatus of claim 11 , wherein the identifier comprises one or more of a hash of at least a portion of a set of bits representing the software, a checksum of at least a portion of a set of bits representing the software, a message digest of at least a portion of a set of bits representing the software, an operating system file name, an operating system file system internal designator, an operating system attribute, a file system attribute, and meta-data.

13. The apparatus of claim 11 , wherein the sensor is further configured to:

generate an identifier for the software; and

determine if the identifier is a member of the set of identifiers,

wherein the software is classified as unauthorized to execute on the computer system if the identifier is not a member of the set of identifiers.

14. The apparatus of claim 11 , wherein the information sent to the actuators includes one or more pieces of information from the correlated network packets.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →