Systems and methods for unauthorized activity defense
View Patent ↗A computer worm defense system comprises multiple containment systems tied together by a management system. Each containment system is deployed on a separate communication network and contains a worm sensor and a blocking system. In various embodiments, the computer worm may be transported from a production network, where the computer worm is not readily identifiable, to an alternate network in the worm sensor where the computer worm may be readily identifiable. Computer worm identifiers generated by a worm sensor of one containment system can be provided not only to the blocking system of the same containment system, but can also be distributed by the management system to blocking systems of other containment systems.
1. An unauthorized activity defense system comprising:
one or more unauthorized activity detection systems, each unauthorized activity detection system comprising
a malicious traffic sensor implemented in a computing device and configured to generate an identifier for malicious traffic propagating within a communication network, the malicious traffic sensor comprises
an analysis environment to analyze communications traffic filtered from the communication network, the filtered communications traffic comprises one or more suspicious characteristics associated with malicious traffic, and
a controller configured to monitor the analysis environment, and to determine whether the filtered communications traffic comprises malicious traffic, the controller to
monitor a processing of the filtered communications traffic within the analysis environment, and
when the filtered communications traffic is determined to comprise malicious traffic, generate the identifier for the malicious traffic based on anomalous behavior caused within the analysis environment during the processing of the filtered communications traffic.
2. The unauthorized activity defense system of claim 1 , wherein the analysis environment comprises a virtual computer system using machine virtualization technologies to analyze the processing of the filtered communications traffic in an alternate computer network.
3. The unauthorized activity defense system of claim 2 , wherein the malicious traffic sensor is configured to copy at least a portion of filtered communications traffic from the communication network, and the analysis environment is configured to analyze processing of the portion of filtered communications traffic to a virtual destination device in the alternate computer network.
4. The unauthorized activity defense system of claim 3 , wherein the analysis environment is further configured to
execute a virtual machine,
transmit the portion of filtered communications traffic to the virtual destination device, and
identify anomalous behavior by analysis of a response of the virtual destination device to the portion of filtered communications traffic.
5. The unauthorized activity defense system of claim 1 , wherein the analysis environment is transparent to and separate from the communication network.
6. The unauthorized activity defense system of claim 1 further comprising:
a malicious traffic blocking system in communication with the malicious traffic sensor over the communication network and configured to receive the identifier from the malicious traffic sensor to block the propagation of the malicious traffic within the communication network.
7. The unauthorized activity defense system of claim 1 , further comprising:
a management system in communication with the one or more unauthorized activity detection systems and configured to obtain the identifier from a malicious traffic sensor of a first unauthorized activity detection system of the one or more unauthorized activity detection systems and distribute the identifier to a malicious traffic blocking system of a second unauthorized activity detection system of the one or more unauthorized activity detection systems.
8. The unauthorized activity defense system of claim 7 , wherein the management system automatically distributes the identifier to the malicious traffic blocking system of the second unauthorized activity detection system.
9. The unauthorized activity defense system of claim 7 , wherein the management system charges a fee to a subscriber associated with the second unauthorized activity detection system for distributing the identifier to the malicious traffic blocking system of the second unauthorized activity detection system.
10. The unauthorized activity defense system of claim 1 , wherein the identifier comprises a signature.
11. The unauthorized activity defense system of claim 10 , wherein the signature comprises a universal resource locator (URL) and the blocking system is capable of filtering by URL.
12. The unauthorized activity defense system of claim 10 , wherein the signature is for use by an inline signature based intrusion detection system, the signature being shared with the inline signature based intrusion detection system.
13. The unauthorized activity defense system of claim 10 , wherein the signature comprises an access control list (ACL) entry for a network device capable of filtering network traffic, the signature being shared with the network device.
14. The unauthorized activity defense system of claim 1 , wherein the controller of each unauthorized activity detection system is further configured to copy at least a portion of network traffic from the communication network and monitor processing of the copied portion of network traffic.
15. The unauthorized activity defense system of claim 14 , wherein the controller of each unauthorized activity detection system is further configured to suppress return traffic generated by the at least a portion of network traffic copied from the communication network.
16. The unauthorized activity defense system of claim 1 , wherein the one or more suspicious characteristics indicate that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises malicious traffic.
17. The unauthorized activity defense system of claim 16 , wherein communications traffic is identified as suspicious based on a suspicious activity threshold.
18. The unauthorized activity defense system of claim 17 , wherein the suspicious activity threshold comprises a threshold in that individual commands within the communications traffic cause communications traffic to be identified as suspicious.
19. The unauthorized activity defense system of claim 17 , wherein the suspicious activity threshold comprises a threshold in that a combination of commands or a repetitive set of commands within the communications traffic cause communications traffic to be identified as suspicious.
20. The unauthorized activity defense system of claim 1 , wherein the malicious traffic is a passive computer worm propagating within the communication network.
21. The unauthorized activity defense system of claim 1 , further comprising the controller to monitor a processing of one or more data contents of the filtered communications traffic within the analysis environment.
22. The unauthorized activity defense system of claim 1 , further comprising the controller to monitor a processing of packets of the filtered communications traffic within the analysis environment.
23. The unauthorized activity defense system of claim 1 , further comprising the controller to monitor a processing of information within the filtered communications traffic.
24. A method comprising:
monitoring communications traffic from a communication network;
filtering the communications traffic from the communication network, the filtered communications traffic comprises one or more suspicious characteristics of malicious traffic, wherein the one or more suspicious characteristics indicating that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises malicious traffic;
determining whether the filtered communications traffic comprises malicious traffic by analyzing the filtered communications traffic, the analyzing comprising monitoring a processing of the filtered communications traffic within an analysis environment of an unauthorized activity detection system; and
when the filtered communications traffic is determined to comprise malicious traffic, generating an identifier for the malicious traffic based on anomalous behavior caused within the analysis environment during the processing of the filtered communications traffic.
25. The method of claim 24 , wherein the analysis environment comprises a virtual computer system using machine virtualization technologies to analyze the processing of the filtered communications traffic in an alternate computer network.
26. The method of claim 25 , further comprising:
copying at least a portion of filtered communications traffic from the communication network; and
analyzing processing of the portion of filtered communications traffic to a virtual destination device in the alternate computer network.
27. The method of claim 26 , wherein analyzing comprises:
executing a virtual machine;
transmitting the portion of filtered communications to the virtual destination device; and
identifying anomalous behavior by analyzing a response of the virtual destination device to the portion of filtered communications.
28. The method of claim 24 further comprising distributing the identifier to a second unauthorized activity detection system.
29. The method of claim 28 , wherein distributing the identifier is performed by a management system.
30. The method of claim 28 , wherein distributing the identifier comprises charging a fee to a subscriber associated with the second unauthorized activity detection system.
31. The method of claim 28 further comprising blocking the malicious traffic from propagating in a communication network associated with the second unauthorized activity detection system.
32. The method of claim 24 , wherein the analysis environment is transparent to and separate from the communication network.
33. The method of claim 24 , wherein generating the identifier further comprises:
generating a sequence of network activities within an alternate computer network of the analysis environment based on a pattern of network activities; and
determining the identifier by comparing observed behavior in the alternate computer network with behavior expected from the pattern of network activities.
34. The method of claim 33 , wherein the pattern of network activities comprises a pattern of access to one or more computing services in the alternate computing network.
35. The method of claim 33 , wherein the pattern of network activities dynamically changes over time.
36. The method of claim 24 , wherein the malicious traffic is a passive computer worm propagating within the communication network.
37. The method of claim 24 , further comprising:
detecting the malicious traffic within the communication network; and
blocking the propagation of the malicious traffic within the communication network.
38. The method of claim 24 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring processing of one or more data contents of the filtered communications traffic.
39. The method of claim 24 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of packets of the filtered communications traffic.
40. The method of claim 24 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of information within the filtered communications traffic.
41. A non-transitory machine readable medium having embodied thereon executable code, the executable code being executable by a processor to perform an unauthorized activity defense method comprising:
monitoring communications traffic from a communication network;
filtering the communications traffic from the communication network, the filtered communications traffic comprises one or more suspicious characteristics of malicious traffic, wherein the one or more suspicious characteristics indicating that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises malicious traffic;
determining whether the filtered communications traffic comprises malicious traffic by analyzing the filtered communications traffic, the analyzing comprising monitoring a processing of the filtered communications traffic within an analysis environment of an unauthorized activity detection system; and
when the filtered communications traffic is determined to comprise malicious traffic, generating an identifier for the malicious traffic based on anomalous behavior caused within the analysis environment during the processing of the filtered communications traffic.
42. The non-transitory machine readable medium of claim 41 , wherein the analysis environment comprises a virtual computer system using machine virtualization technologies to analyze the processing of the filtered communications traffic in an alternate computer network.
43. The non-transitory machine readable medium of claim 42 , wherein the unauthorized activity defense method further comprising:
copying at least a portion of filtered communications traffic from the communication network; and
analyzing processing of the portion of filtered communications traffic to a virtual destination device in the alternate computer network.
44. The non-transitory machine readable medium of claim 43 , wherein analyzing processing of the portion of the filtered communications traffic comprises:
executing a virtual machine;
transmitting the portion of filtered communications to the virtual destination device; and
identifying anomalous behavior by analyzing a response of the virtual destination device to the portion of filtered communications.
45. The non-transitory machine readable medium of claim 41 , wherein the unauthorized activity defense method further comprises distributing the identifier to a second unauthorized activity detection system.
46. The non-transitory machine readable medium of claim 45 , wherein distributing the identifier is performed by a management system.
47. The non-transitory machine readable medium of claim 45 , wherein distributing the identifier comprises charging a fee to a subscriber associated with the second unauthorized activity detection system.
48. The non-transitory machine readable medium of claim 45 , wherein the unauthorized activity defense method further comprises blocking the malicious traffic from propagating in a communication network associated with the second unauthorized activity detection system.
49. The non-transitory machine readable medium of claim 41 , wherein the analysis environment is transparent to and separate from the communication network.
50. The non-transitory machine readable medium of claim 41 , wherein generating the identifier further comprises:
generating a sequence of network activities within an alternate computer network of the analysis environment based on a pattern of network activities; and
determining the identifier by comparing observed behavior in the alternate computer network with behavior expected from the pattern of network activities.
51. The non-transitory machine readable medium of claim 5 , wherein the pattern of network activities comprises a pattern of access to one or more computing services in the alternate computing network.
52. The non-transitory machine readable medium of claim 50 , wherein the pattern of network activities dynamically changes over time.
53. The non-transitory machine readable medium of claim 41 , wherein the malicious traffic is a passive computer worm propagating within the communication network.
54. The non-transitory machine readable medium of claim 41 , wherein the unauthorized activity defense method further comprising:
detecting the malicious traffic within the communication network; and
blocking the propagation of the malicious traffic within the communication network.
55. The non-transitory machine readable medium of claim 41 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of one or more data contents in the filtered communications traffic.
56. The non-transitory machine readable medium of claim 41 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of information within the filtered communications traffic.
57. The non-transitory machine readable medium of claim 41 , further comprising the controller to monitor processing of packets of the filtered communications traffic within the analysis environment.