IP Library Granted Patent US 9,680,861
Granted Patent B2
US 9,680,861 · App. 14/015,704 · Granted Jun 13, 2017

Historical analysis to identify malicious activity

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,680,861
App. No.
14/015,704
Granted
Jun 13, 2017
Kind
B2
Abstract

Systems and methods may use historical analysis to identify malicious activity. A discovery/recovery system may comprise a processor in communication with a network and in communication with a database. The discovery/recovery system may gather filtered historical network data associated with an asset associated with the network. The discovery/recovery system may analyze the filtered historical network data to determine whether a subset of the filtered historical network data is associated with a malware infection of the asset.

Claims (53)

1. A method comprising:

gathering and storing, using at least one processor in communication with a network, historical network data associated with a plurality of hardware assets associated with the network;

detecting a malware infection of at least one asset within the plurality of hardware assets associated with the network, wherein the detecting is not based on the historical network data;

responsive to the detecting the malware infection, identifying, with the at least one processor in communication with the network, historical network data associated with the at least one infected asset associated with the network, the historical network data having been gathered prior to the detection of the malware infection;

responsive to the detecting the malware infection, analyzing, with the at least one processor, the identified historical network data to determine whether a subset of the identified historical network data is associated with the malware infection of the at least one infected asset; and

present, using the at least one processor, a notification that the at least one asset is infected with malware and the analyzed identified historical network data to a user.

2. The method of claim 1 , wherein the identified historical network data comprises historical network communication data.

3. The method of claim 2 , wherein the analyzing comprises identifying a destination and/or source associated with the historical network communication data and identifying a reputation associated with the destination and/or source, measuring a statistical feature of a new destination and/or source associated with the historical network communication data and determining a likely reputation of the new destination and/or source, analyzing a header associated with the historical network communication data, and/or analyzing a referrer associated with the historical network communication data.

4. The method of claim 3 , wherein:

the destination and/or source comprises a domain, an IP address, a URL path, and/or a resource; and

the new destination and/or source comprises a domain, an IP address, a URL path, and/or a resource.

5. The method of claim 1 , wherein the identified historical network data comprises an historical network file download.

6. The method of claim 5 , wherein the analyzing comprises identifying a source associated with the historical network file download and identifying a reputation associated with the source, measuring a statistical feature of a new source associated with the historical network file download and determining a likely reputation of the new source, analyzing the historical network file download using a third party commodity, identifying a static structure of the historical network file download, identifying a behavioral trait of the historical network file download, and/or allowing a file associated with the historical network file download to execute and examining a result of the executing.

7. The method of claim 6 , wherein:

the source comprises a domain, an IP address, a URL path, and/or a resource; and

the new source comprises a domain, an IP address, a URL path, and/or a resource.

8. The method of claim 1 , wherein the identified historical network communication data comprises suspicious network traffic.

9. The method of claim 8 , further comprising: monitoring, with the at least one processor, network traffic to and/or from the at least one asset associated with the network; assessing, with the at least one processor, the network traffic to determine a destination and/or source for the network traffic and/or content of the network traffic; determining, with the at least one processor, whether the network traffic is suspicious network traffic based on the assessed destination and/or source and/or content; and capturing, with the at least one processor, metadata associated with the suspicious network traffic and storing the metadata in a database in communication with the at least one processor.

10. The method of claim 9 , wherein the monitoring comprises monitoring a transport protocol of the network traffic, monitoring an application protocol of the network traffic, monitoring a destination and/or source of the network traffic, and/or monitoring content of the network traffic.

11. The method of claim 9 , wherein the determining whether the network traffic is suspicious network traffic is based on a low reputation score associated with the destination and/or source for the network traffic, a suspicious DGA cluster associated with the destination and/or source for the network traffic, a suspicious DGA cluster associated with the content of the network traffic, and/or a suspicious content element within the content of the network traffic.

12. The method of claim 9 , further comprising:

when the network traffic is determined to be suspicious network traffic, indexing, with the at least one processor, the metadata.

13. The method of claim 9 , wherein the metadata comprises a source port, a destination port, a transport protocol, an application protocol, a time stamp, a duration, a source identifier, a destination identifier, a bytes in count, a bytes out count, a connection success indicator, a connection status, a DNS RR set, HTTP data, a file within the content of the network traffic, the content of the network traffic, and/or a subsequent communication.

14. The method of claim 9 , further comprising:

when the network traffic is determined to be suspicious network traffic, sending, with the at least one processor, a report indicating that the network traffic is determined to be suspicious network traffic to a display in communication with the at least one processor.

15. The method of claim 9 , wherein determining whether the network traffic is suspicious network traffic comprises determining that all traffic to and/or from the at least one asset is suspicious network traffic when the at least one asset is an asset with a potential malware infection.

16. A system comprising:

a non-transitory device comprising at least one processor in communication with a network and in communication with a database, the at least one processor being constructed and arranged to:

gather and store, using the at least one processor, historical network data associated with a plurality of hardware assets associated with the network;

detect a malware infection of at least one asset within the plurality of hardware assets associated with the network, wherein the detecting is not based on the historical network data;

responsive to the detection of the malware infection of the at least one asset associated with the network, identify, with the at least one processor in communication with the network, historical network data associated with the at least one infected asset associated with the network, the historical network data having been gathered prior to the detection of the malware infection;

responsive to the detection of the malware infection, analyze, with the at least one processor, the identified historical network data to determine whether a subset of the identified historical network data is associated with the malware infection of the at least one infected asset; and

present, using the at least one processor, a notification that the at least one asset is infected with malware and the analyzed identified historical network data to a user.

17. The system of claim 16 , wherein the identified historical network data comprises historical network communication data.

18. The system of claim 17 , wherein the at least one processor is constructed and arranged to analyze the identified historical network data by identifying a destination and/or source associated with the historical network communication data and identifying a reputation associated with the destination and/or source, measuring a statistical feature of a new destination and/or source associated with the historical network communication data and determining a likely reputation of the new destination and/or source, analyzing a header associated with the historical network communication data, and/or analyzing a referrer associated with the historical network communication data.

19. The system of claim 18 , wherein:

the destination and/or source comprises a domain, an IP address, a URL path, and/or a resource; and

the new destination and/or source comprises a domain, an IP address, a URL path, and/or a resource.

20. The system of claim 16 , wherein the identified historical network data comprises an historical network file download.

21. The system of claim 20 , wherein the at least one processor is constructed and arranged to analyze the identified historical network data by identifying a source associated with the historical network file download and identifying a reputation associated with the source, measuring a statistical feature of a new source associated with the historical network file download and determining a likely reputation of the new source, analyzing the historical network file download using a third party commodity, identifying a static structure of the historical network file download, identifying a behavioral trait of the historical network file download, and/or allowing a file associated with the historical network file download to execute and examining a result of the executing.

22. The system of claim 21 , wherein:

the destination comprises a domain, an IP address, a URL path, and/or a resource; and

the new destination comprises a domain, an IP address, a URL path, and/or a resource.

23. The system of claim 16 , wherein the identified historical network communication data comprises suspicious network traffic.

24. The system of claim 23 , wherein the at least one processor is constructed and arranged to: monitor network traffic to and/or from the at least one asset associated with the network; assess the network traffic to determine a destination and/or source for the network traffic and/or content of the network traffic; determine whether the network traffic is suspicious network traffic based on the assessed destination and/or source and/or content; and capture metadata associated with the suspicious network traffic and store the metadata in the database.

25. The system of claim 24 , wherein the monitoring comprises monitoring a transport protocol of the network traffic, monitoring an application protocol of the network traffic, monitoring a destination of the network traffic, and/or monitoring content of the network traffic.

26. The system of claim 24 , wherein the determining whether the network traffic is suspicious network traffic is based on a low reputation score associated with the destination and/or source for the network traffic, a suspicious DGA cluster associated with the destination and/or source for the network traffic, a suspicious DGA cluster associated with the content of the network traffic, and/or a suspicious content element within the content of the network traffic.

27. The system of claim 24 , wherein the at least one processor is further constructed and arranged to:

when the network traffic is determined to be suspicious network traffic, index the metadata.

28. The system of claim 24 , wherein the metadata comprises a source port, a destination port, a transport protocol, an application protocol, a time stamp, a duration, a source identifier, a destination identifier, a bytes in count, a bytes out count, a connection success indicator, a connection status, a DNS RR set, HTTP data, a file within the content of the network traffic, the content of the network traffic, and/or a subsequent communication.

29. The system of claim 24 , wherein the at least one processor is further constructed and arranged to:

when the network traffic is determined to be suspicious network traffic, send a report indicating that the network traffic is determined to be suspicious network traffic to a display in communication with the at least one processor.

30. The system of claim 24 , wherein the at least one processor is constructed and arranged to determine whether the network traffic is suspicious network traffic with a method comprising determining that all traffic to and/or from the asset is suspicious network traffic when the asset is an asset with a potential malware infection.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 070086/0189 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048386/0329 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: DAMBALLA, INC.
Reel/Frame 044535/0907 →
SECURITY INTEREST Recorded Dec 27, 2017
From: DAMBALLA, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044492/0654 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: DAMBALLA, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040297/0988 →
RELEASE OF SECURITY INTEREST Recorded Sep 8, 2016
From: SILICON VALLEY BANK
To: DAMBALLA, INC.
Reel/Frame 039678/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2015
From: WARD, JOSEPH; HOBSON, ANDREW
To: DAMBALLA, INC.
Reel/Frame 037170/0533 →
SECURITY INTEREST Recorded May 14, 2015
From: DAMBALLA, INC.
To: SILICON VALLEY BANK
Reel/Frame 035639/0136 →