IP Library Granted Patent US 9,104,864
Granted Patent B2
US 9,104,864 · App. 13/658,977 · Granted Aug 11, 2015

Threat detection through the accumulated detection of threat characteristics

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,104,864
App. No.
13/658,977
Granted
Aug 11, 2015
Kind
B2
Abstract

Embodiments of the present disclosure provide for improved capabilities in the detection of malware, where malware threats are detected through the accumulated identification of threat characteristics for targeted computer objects. Methods and systems include dynamic threat detection providing a first database that correlates a plurality of threat characteristics to a threat, wherein a presence of the plurality of the threat characteristics confirms a presence of the threat; detecting a change event in a computer run-time process; testing the change event for a presence of one or more of the plurality of characteristics upon detection of the change event; storing a detection of one of the plurality of characteristics in a second database that accumulates detected characteristics for the computer run-time process; and identifying the threat when each one of the plurality of characteristics appears in the second database.

Claims (16)

1. A computer program product embodied in a non-transitory computer readable medium that, when executing on one or more computers, performs the steps of:

providing a first database that correlates a plurality of threat characteristics to a threat, wherein a presence of the plurality of the threat characteristics confirms a presence of the threat;

detecting a change event in a computer run-time process;

testing the change event for a presence of one or more of the plurality of threat characteristics upon detection of the change event;

storing a detection of one of the plurality of threat characteristics in a second database that accumulates detected characteristics for the computer run-time process;

scaling the plurality of threat characteristics in the first database to a number of relevant threat characteristics based upon accumulated detected characteristics in the second database using an inverted threat index that associates each of a number of particular characteristics with one or more particular threats, and for each one of the one or more particular threats, further specifies how many particular characteristics are used to identify the one of the one or more particular threats, thereby updating the first database as threat characteristics are detected in change events; and

identifying the threat when the number of relevant threat characteristics appear in the second database.

2. The computer program product of claim 1 , wherein the threat includes a malware threat to a computer facility.

3. The computer program product of claim 1 , wherein the threat includes a violation of an enterprise security policy.

4. The computer program product of claim 1 , wherein the characteristic is a functionality of a computer program.

5. The computer program product of claim 1 , wherein one of the threat characteristics is a property of a computer program.

6. The computer program product of claim 1 , wherein one of the threat characteristics is a portion of program code.

7. The computer program product of claim 1 , wherein the computer run-time process includes at least one of an access to a file, a process, a mutual exclusion object, and a registry key.

8. The computer program product of claim 1 , wherein the second database accumulates detected characteristics for each of a plurality of computer run-time processes.

9. The computer program product of claim 1 , wherein the first database correlates a different plurality of characteristics to each one of a plurality of different threats.

10. The computer program product of claim 1 , further comprising code that performs the step of creating a new threat characteristic for inclusion into the first database when the detected change event is identified as a new threat by a threat identification facility but is not currently in the first database.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
RELEASE OF SECURITY INTEREST Recorded Jul 28, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: SOPHOS LIMITED
Reel/Frame 053334/0220 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
SECURITY AGREEMENT Recorded Feb 3, 2014
From: SOPHOS LIMITED
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032152/0896 →
CHANGE OF NAME Recorded Apr 11, 2013
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 030194/0299 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2012
From: PENTON, CLIFFORD; MICHLIN, IRENE
To: SOPHOS PLC
Reel/Frame 029180/0824 →