IP Library Granted Patent US 9,197,654
Granted Patent B2
US 9,197,654 · App. 13/931,705 · Granted Nov 24, 2015

Rootkit detection by using HW resources to detect inconsistencies in network traffic

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,654
App. No.
13/931,705
Granted
Nov 24, 2015
Kind
B2
Abstract

A technique allows detection of covert malware that attempts to hide network traffic. By monitoring network traffic both in a secure trusted environment and in an operating system environment, then comparing the monitor data, attempts to hide network traffic can be detected, allowing the possibility of performing rehabilitative actions on the computer system to locate and remove the malware hiding the network traffic.

Claims (63)

1. A non-transitory computer readable medium with instructions stored thereon, the instructions comprising instructions that when executed cause a programmable device to:

monitor network traffic of the programmable device in an environment controlled by an operating system of the programmable device, producing a first monitor data;

monitor network traffic of the programmable device in a cryptographically secured hardware environment of the programmable device not controlled by the operating system, producing a second monitor data;

compare the first monitor data with the second monitor data; and

indicate whether the first monitor data is the same as the second monitor data.

2. The non-transitory computer readable medium of claim 1 , wherein the instructions that when executed cause the programmable device to compare the first monitor data with the second monitor data comprise instructions that when executed cause the programmable device to:

send the first monitor data from the environment controlled by the operating system to the cryptographically secured hardware environment; and

compare the first monitor data with the second monitor data in the cryptographically secured hardware environment.

3. The non-transitory computer readable medium of claim 1 , wherein the instructions that when executed cause the programmable device to compare the first monitor data with the second monitor data comprise instructions that when executed cause the programmable device to:

send the second monitor data from the cryptographically secured hardware environment to the environment controlled by the operating system; and

compare the first monitor data with the second monitor data in the environment controlled by the operating system.

4. The non-transitory computer readable medium of claim 1 , wherein the instructions that when executed cause the programmable device to compare the first monitor data with the second monitor data comprise instructions that when executed cause the programmable device to:

send the first monitor data and the second monitor data to an external facility; and

compare the first monitor data with the second monitor data in the external facility.

5. The non-transitory computer readable medium of claim 1 , wherein the instructions stored thereon further comprise instructions that when executed cause the programmable device to:

generate an alert indicating the presence of malware on the programmable device.

6. The non-transitory computer readable medium of claim 1 , wherein the instructions that when executed cause the programmable device to compare the first monitor data with the second monitor data comprise instructions that when executed cause the programmable device to:

limit the comparison by an exclude list.

7. The non-transitory computer readable medium of claim 1 , wherein the instructions stored thereon further comprise instructions that when executed cause the programmable device to generate a malware alert in the operating system environment or the cryptographically secured hardware environment.

8. The non-transitory computer readable medium of claim 7 , wherein the instructions that when executed cause the programmable device to generate a malware alert in the operating system environment or the cryptographically secured hardware environment comprise instructions for sending the malware alert via a network.

9. The non-transitory computer readable medium of claim 1 , wherein the instructions stored thereon further comprise instructions that when executed cause the programmable device to:

quarantine the programmable device.

10. A method of detecting malware, comprising:

monitoring network traffic of a programmable device in an environment controlled by an operating system for the programmable device, producing a first monitor data;

monitoring network traffic of the programmable device in a cryptographically secured hardware environment of the programmable device not controlled by the operating system, producing a second monitor data;

comparing the first monitor data with the second monitor data; and

indicating the presence of malware if the first monitor data does not match the second monitor data.

11. The method of claim 10 , wherein monitoring network traffic of a programmable device in an environment controlled by an operating system for the programmable device comprises:

monitoring network traffic in an intrusion detection system executing under control by the operating system.

12. The method of claim 10 , further comprising:

loading firmware for execution in the cryptographically secured hardware environment at powerup of the programmable device.

13. The method of claim 10 , wherein comparing the first monitor data with the second monitor data comprises:

sending the first monitor data to the cryptographically secured hardware environment; and

comparing the first monitor data with the second monitor data in the cryptographically secured hardware environment.

14. The method of claim 10 , further comprising:

quarantining the programmable device responsive to the indication of the presence of malware.

15. The method of claim 10 , wherein comparing the first monitor data with the second monitor data comprises:

sending the second monitor data to an intrusion detection system executing under control by the operating system; and

comparing the first monitor data with the second monitor data by the intrusion detection system.

16. The method of claim 10 , wherein comparing the first monitor data with the second monitor data comprises:

sending the first monitor data from the cryptographically secured hardware environment to an external facility for comparison with the second monitor data; and

sending the second monitor data from the intrusion detection system to the external facility for comparison with the first monitor data.

17. The method of claim 16 , wherein indicating the presence of malware comprises:

receiving an alert generated by the external facility.

18. The method of claim 10 , wherein indicating the presence of malware comprises:

displaying an alert indicating the presence of malware.

19. The method of claim 10 , wherein the first monitor data and the second monitor data comprise network flow data.

20. A programmable device, comprising:

a processor;

an operating system, comprising instructions that when executed by the processor control the processor and provide an operating system environment for other software to execute on the processor;

an intrusion detection software, comprising instructions that when executed by the processor in the operating system environment cause the processor to:

record network traffic of the programmable device as a first monitor data; and

a cryptographically secured hardware environment configured to record network traffic of the programmable device as a second monitor data, wherein the cryptographically secured hardware environment is outside of the operating system environment;

wherein the programmable device is configured to:

compare the first monitor data with the second monitor data; and

generate an alert if the first monitor data is not the same as the second monitor data.

21. The programmable device of claim 20 , wherein the first monitor data and the second monitor data comprise network flow data.

22. The programmable device of claim 20 ,

wherein intrusion detection system further comprises instructions that when executed by the processor in the operating system environment cause the processor to:

request the second monitor data from the cryptographically secured hardware environment; and

compare the first monitor data with the second monitor data by the intrusion detection system in the operating system environment.

23. The programmable device of claim 20 , wherein the intrusion detection software is configured to cause the process to record network traffic continuously.

24. The programmable device of claim 20 , wherein the programmable device is configured to compare the first monitor data and the second monitor data periodically.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2014
From: BEN-SHALOM, OMER; NAYSHTUT, ALEX; MUTTIK, IGOR
To: MCAFEE, INC.
Reel/Frame 032542/0453 →