IP Library Granted Patent US 9,027,130
Granted Patent B1
US 9,027,130 · App. 13/970,248 · Granted May 5, 2015

Systems and methods for unauthorized activity defense

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,027,130
App. No.
13/970,248
Granted
May 5, 2015
Kind
B1
Abstract

A computer worm defense system comprises multiple containment systems tied together by a management system. Each containment system is deployed on a separate communication network and contains a worm sensor and a blocking system. In various embodiments, the computer worm may be transported from a production network, where the computer worm is not readily identifiable, to an alternate network in the worm sensor where the computer worm may be readily identifiable. Computer worm identifiers generated by a worm sensor of one containment system can be provided not only to the blocking system of the same containment system, but can also be distributed by the management system to blocking systems of other containment systems.

Claims (94)

1. An unauthorized activity defense system comprising:

one or more unauthorized activity detection systems, each unauthorized activity detection system comprising

a malicious traffic sensor implemented in a computing device and configured to generate an identifier for malicious traffic propagating within a communication network, the malicious traffic sensor comprises

an analysis environment to analyze communications traffic filtered from the communication network, the filtered communications traffic comprises one or more suspicious characteristics associated with malicious traffic, and

a controller configured to monitor the analysis environment, and to determine whether the filtered communications traffic comprises malicious traffic, the controller to

monitor a processing of the filtered communications traffic within the analysis environment, and

when the filtered communications traffic is determined to comprise malicious traffic, generate the identifier for the malicious traffic based on anomalous behavior caused within the analysis environment during the processing of the filtered communications traffic.

2. The unauthorized activity defense system of claim 1 , wherein the analysis environment comprises a virtual computer system using machine virtualization technologies to analyze the processing of the filtered communications traffic in an alternate computer network.

3. The unauthorized activity defense system of claim 2 , wherein the malicious traffic sensor is configured to copy at least a portion of filtered communications traffic from the communication network, and the analysis environment is configured to analyze processing of the portion of filtered communications traffic to a virtual destination device in the alternate computer network.

4. The unauthorized activity defense system of claim 3 , wherein the analysis environment is further configured to

execute a virtual machine,

transmit the portion of filtered communications traffic to the virtual destination device, and

identify anomalous behavior by analysis of a response of the virtual destination device to the portion of filtered communications traffic.

5. The unauthorized activity defense system of claim 1 , wherein the analysis environment is transparent to and separate from the communication network.

6. The unauthorized activity defense system of claim 1 further comprising:

a malicious traffic blocking system in communication with the malicious traffic sensor over the communication network and configured to receive the identifier from the malicious traffic sensor to block the propagation of the malicious traffic within the communication network.

7. The unauthorized activity defense system of claim 1 , further comprising:

a management system in communication with the one or more unauthorized activity detection systems and configured to obtain the identifier from a malicious traffic sensor of a first unauthorized activity detection system of the one or more unauthorized activity detection systems and distribute the identifier to a malicious traffic blocking system of a second unauthorized activity detection system of the one or more unauthorized activity detection systems.

8. The unauthorized activity defense system of claim 7 , wherein the management system automatically distributes the identifier to the malicious traffic blocking system of the second unauthorized activity detection system.

9. The unauthorized activity defense system of claim 7 , wherein the management system charges a fee to a subscriber associated with the second unauthorized activity detection system for distributing the identifier to the malicious traffic blocking system of the second unauthorized activity detection system.

10. The unauthorized activity defense system of claim 1 , wherein the identifier comprises a signature.

11. The unauthorized activity defense system of claim 10 , wherein the signature comprises a universal resource locator (URL) and the blocking system is capable of filtering by URL.

12. The unauthorized activity defense system of claim 10 , wherein the signature is for use by an inline signature based intrusion detection system, the signature being shared with the inline signature based intrusion detection system.

13. The unauthorized activity defense system of claim 10 , wherein the signature comprises an access control list (ACL) entry for a network device capable of filtering network traffic, the signature being shared with the network device.

14. The unauthorized activity defense system of claim 1 , wherein the controller of each unauthorized activity detection system is further configured to copy at least a portion of network traffic from the communication network and monitor processing of the copied portion of network traffic.

15. The unauthorized activity defense system of claim 14 , wherein the controller of each unauthorized activity detection system is further configured to suppress return traffic generated by the at least a portion of network traffic copied from the communication network.

16. The unauthorized activity defense system of claim 1 , wherein the one or more suspicious characteristics indicate that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises malicious traffic.

17. The unauthorized activity defense system of claim 16 , wherein communications traffic is identified as suspicious based on a suspicious activity threshold.

18. The unauthorized activity defense system of claim 17 , wherein the suspicious activity threshold comprises a threshold in that individual commands within the communications traffic cause communications traffic to be identified as suspicious.

19. The unauthorized activity defense system of claim 17 , wherein the suspicious activity threshold comprises a threshold in that a combination of commands or a repetitive set of commands within the communications traffic cause communications traffic to be identified as suspicious.

20. The unauthorized activity defense system of claim 1 , wherein the malicious traffic is a passive computer worm propagating within the communication network.

21. The unauthorized activity defense system of claim 1 , further comprising the controller to monitor a processing of one or more data contents of the filtered communications traffic within the analysis environment.

22. The unauthorized activity defense system of claim 1 , further comprising the controller to monitor a processing of packets of the filtered communications traffic within the analysis environment.

23. The unauthorized activity defense system of claim 1 , further comprising the controller to monitor a processing of information within the filtered communications traffic.

24. A method comprising:

monitoring communications traffic from a communication network;

filtering the communications traffic from the communication network, the filtered communications traffic comprises one or more suspicious characteristics of malicious traffic, wherein the one or more suspicious characteristics indicating that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises malicious traffic;

determining whether the filtered communications traffic comprises malicious traffic by analyzing the filtered communications traffic, the analyzing comprising monitoring a processing of the filtered communications traffic within an analysis environment of an unauthorized activity detection system; and

when the filtered communications traffic is determined to comprise malicious traffic, generating an identifier for the malicious traffic based on anomalous behavior caused within the analysis environment during the processing of the filtered communications traffic.

25. The method of claim 24 , wherein the analysis environment comprises a virtual computer system using machine virtualization technologies to analyze the processing of the filtered communications traffic in an alternate computer network.

26. The method of claim 25 , further comprising:

copying at least a portion of filtered communications traffic from the communication network; and

analyzing processing of the portion of filtered communications traffic to a virtual destination device in the alternate computer network.

27. The method of claim 26 , wherein analyzing comprises:

executing a virtual machine;

transmitting the portion of filtered communications to the virtual destination device; and

identifying anomalous behavior by analyzing a response of the virtual destination device to the portion of filtered communications.

28. The method of claim 24 further comprising distributing the identifier to a second unauthorized activity detection system.

29. The method of claim 28 , wherein distributing the identifier is performed by a management system.

30. The method of claim 28 , wherein distributing the identifier comprises charging a fee to a subscriber associated with the second unauthorized activity detection system.

31. The method of claim 28 further comprising blocking the malicious traffic from propagating in a communication network associated with the second unauthorized activity detection system.

32. The method of claim 24 , wherein the analysis environment is transparent to and separate from the communication network.

33. The method of claim 24 , wherein generating the identifier further comprises:

generating a sequence of network activities within an alternate computer network of the analysis environment based on a pattern of network activities; and

determining the identifier by comparing observed behavior in the alternate computer network with behavior expected from the pattern of network activities.

34. The method of claim 33 , wherein the pattern of network activities comprises a pattern of access to one or more computing services in the alternate computing network.

35. The method of claim 33 , wherein the pattern of network activities dynamically changes over time.

36. The method of claim 24 , wherein the malicious traffic is a passive computer worm propagating within the communication network.

37. The method of claim 24 , further comprising:

detecting the malicious traffic within the communication network; and

blocking the propagation of the malicious traffic within the communication network.

38. The method of claim 24 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring processing of one or more data contents of the filtered communications traffic.

39. The method of claim 24 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of packets of the filtered communications traffic.

40. The method of claim 24 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of information within the filtered communications traffic.

41. A non-transitory machine readable medium having embodied thereon executable code, the executable code being executable by a processor to perform an unauthorized activity defense method comprising:

monitoring communications traffic from a communication network;

filtering the communications traffic from the communication network, the filtered communications traffic comprises one or more suspicious characteristics of malicious traffic, wherein the one or more suspicious characteristics indicating that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises malicious traffic;

determining whether the filtered communications traffic comprises malicious traffic by analyzing the filtered communications traffic, the analyzing comprising monitoring a processing of the filtered communications traffic within an analysis environment of an unauthorized activity detection system; and

when the filtered communications traffic is determined to comprise malicious traffic, generating an identifier for the malicious traffic based on anomalous behavior caused within the analysis environment during the processing of the filtered communications traffic.

42. The non-transitory machine readable medium of claim 41 , wherein the analysis environment comprises a virtual computer system using machine virtualization technologies to analyze the processing of the filtered communications traffic in an alternate computer network.

43. The non-transitory machine readable medium of claim 42 , wherein the unauthorized activity defense method further comprising:

copying at least a portion of filtered communications traffic from the communication network; and

analyzing processing of the portion of filtered communications traffic to a virtual destination device in the alternate computer network.

44. The non-transitory machine readable medium of claim 43 , wherein analyzing processing of the portion of the filtered communications traffic comprises:

executing a virtual machine;

transmitting the portion of filtered communications to the virtual destination device; and

identifying anomalous behavior by analyzing a response of the virtual destination device to the portion of filtered communications.

45. The non-transitory machine readable medium of claim 41 , wherein the unauthorized activity defense method further comprises distributing the identifier to a second unauthorized activity detection system.

46. The non-transitory machine readable medium of claim 45 , wherein distributing the identifier is performed by a management system.

47. The non-transitory machine readable medium of claim 45 , wherein distributing the identifier comprises charging a fee to a subscriber associated with the second unauthorized activity detection system.

48. The non-transitory machine readable medium of claim 45 , wherein the unauthorized activity defense method further comprises blocking the malicious traffic from propagating in a communication network associated with the second unauthorized activity detection system.

49. The non-transitory machine readable medium of claim 41 , wherein the analysis environment is transparent to and separate from the communication network.

50. The non-transitory machine readable medium of claim 41 , wherein generating the identifier further comprises:

generating a sequence of network activities within an alternate computer network of the analysis environment based on a pattern of network activities; and

determining the identifier by comparing observed behavior in the alternate computer network with behavior expected from the pattern of network activities.

51. The non-transitory machine readable medium of claim 5 , wherein the pattern of network activities comprises a pattern of access to one or more computing services in the alternate computing network.

52. The non-transitory machine readable medium of claim 50 , wherein the pattern of network activities dynamically changes over time.

53. The non-transitory machine readable medium of claim 41 , wherein the malicious traffic is a passive computer worm propagating within the communication network.

54. The non-transitory machine readable medium of claim 41 , wherein the unauthorized activity defense method further comprising:

detecting the malicious traffic within the communication network; and

blocking the propagation of the malicious traffic within the communication network.

55. The non-transitory machine readable medium of claim 41 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of one or more data contents in the filtered communications traffic.

56. The non-transitory machine readable medium of claim 41 , wherein the monitoring of the processing of the filtered communications traffic within the analysis environment further comprises monitoring a processing of information within the filtered communications traffic.

57. The non-transitory machine readable medium of claim 41 , further comprising the controller to monitor processing of packets of the filtered communications traffic within the analysis environment.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063113/0150 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0140 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2016
From: AZIZ, ASHAR
To: FIREEYE, INC.
Reel/Frame 038034/0927 →