IP Library Granted Patent US 9,413,781
Granted Patent B2
US 9,413,781 · App. 14/216,453 · Granted Aug 9, 2016

System and method employing structured intelligence to verify and contain threats at endpoints

Inventors: Sean Cunningham (Washington, DC); Robert Dana (Springfield, VA); Joseph Nardone (Arlington, VA); Joseph Faber (Round Hill, VA); Kevin Arunski (Sterling, VA)
Assignee: FireEye, Inc.
H04L63/1441G06F21/554H04L29/06877H04L29/06884H04L63/14H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,413,781
App. No.
14/216,453
Granted
Aug 9, 2016
Kind
B2
Abstract

A system and method to detect and contain threatening executable code by employing a threat monitor, verifier, endpoint agent, and a security information and event management module. The system and method are a departure from and an improvement over conventional systems in that, among other things, the system and method allow an investigator to determine whether a threat has persisted or executed, and allow that information to be communicated back to the detection mechanism (or other system) such that a user (or machine) may make a decision to take further action such as to contain the threat quickly and/or permit the system to do so automatically.

Claims (83)

1. A computerized method to identify potentially malicious code at an endpoint in a network, the method comprising the steps of:

via a threat monitor:

monitoring network data,

extracting at least one set of network data, and

processing the at least one set of network data to generate a report;

via a verifier including an agent coordinator, issuing at least one of (i) instructions, and (ii) indicators to an endpoint agent based on the report; and

processing, via the endpoint agent, the at least one of (i) instructions, and (ii) indicators to generate verification information,

wherein the verification information is processed via the verifier by comparing the verification information to at least one of (a) data obtained from another endpoint, and (b) data obtained from a security information and event management module (SIEM).

2. The computerized method according to claim 1 , wherein the verification information includes audit data.

3. The computerized method according to claim 2 , wherein the audit data includes hit data.

4. The computerized method according to claim 1 , further comprising the step of:

providing the verification information to the verifier.

5. The computerized method according to claim 4 , further comprising the step of:

processing, via the verifier, the verification information to determine whether it indicates a verified threat.

6. The computerized method according to claim 1 , further comprising the step of:

changing the configuration of the threat monitor based on the verification information.

7. The computerized method according to claim 1 , wherein the report includes structured threat intelligence.

8. The computerized method according to claim 1 , further comprising the step of:

providing the verification information to at least one of (a) the verifier, (b) the SIEM, and (c) the threat monitor.

9. The computerized method according to claim 1 , wherein the processing of the at least one set of network data is performed by an analyzer of the threat monitor, the analyzer includes software executed by a hardware processor of the endpoint.

10. The computerized method according to claim 9 , wherein the analyzer is a static analyzer.

11. The computerized method according to claim 9 , wherein the analyzer is a dynamic analyzer.

12. The computerized method according to claim 1 , further comprising the step of:

processing the report via a report analyzer of the verifier to generate the at least one of (i) instructions and (ii) indicators.

13. The computerized method according to claim 1 , wherein the processing of the at least one of (i) instructions and (ii) indicators is performed via an audit module that generates audit data, the audit module being software executed by a hardware processor of the endpoint.

14. The computerized method according to claim 13 , further comprising the step of:

storing the audit data in a buffered storage module.

15. The computerized method according to claim 13 , wherein the audit data is processed by an indicator matcher to produce the verification information.

16. The computerized method according to claim 1 , further comprising the step of:

performing a containment action on the endpoint via the endpoint agent based on the verification information.

17. The computerized method according to claim 16 , wherein the containment action is taken by a containment agent of the endpoint agent.

18. The computerized method according to claim 17 , wherein the containment agent is installed on the endpoint pursuant to instructions contained in a containment package configured by the agent coordinator.

19. A system operable to identify potentially malicious code on an endpoint in a network, the system comprising:

a threat monitor operable to monitor network data, to extract at least one set of network data, and to process the at least one set of network data to generate a report; and

a verifier including an agent coordinator operable to issue at least one of (i) instructions and (ii) indicators to an endpoint agent based on the report;

wherein,

the endpoint agent is operable to process the at least one of (i) instructions and (ii) indicators to generate verification information, and

the endpoint agent includes a containment agent operable to perform a containment action based on the verification information.

20. The system according to claim 19 , wherein the containment agent is installed on the endpoint pursuant to instructions contained in a containment package configured by the agent coordinator based on the verification information.

21. The system according to claim 19 , wherein the verifier is operable to process the verification information to determine whether it indicates a verified threat.

22. The system according to claim 19 ,

wherein,

the report includes structured threat intelligence, and

the verifier is operable to process the structured threat intelligence to issue the at least one of (i) instructions and (ii) indicators.

23. The system according to claim 19 , wherein the threat monitor includes an analyzer configured to process the at least one set of network data, the analyzer includes software executed by a hardware processor of the endpoint.

24. The system according to claim 23 , wherein the analyzer is a static analyzer.

25. The system according to claim 23 , wherein the analyzer is a dynamic analyzer.

26. The system according to claim 19 , wherein the verifier includes a report analyzer operable to generate the at least one of (i) instructions and (ii) indicators.

27. The system according to claim 19 , wherein the endpoint agent includes an audit module operable to process the at least one of (i) instructions and (ii) indicators to generate audit data, the audit module being software executed by a hardware processor of the endpoint.

28. The system according to claim 27 , wherein the endpoint agent includes a buffered storage module operable to store the audit data.

29. The system according to claim 27 , wherein the endpoint agent includes an indicator matcher operable to process audit data to produce the verification information.

30. A system operable to identify potentially malicious code on an endpoint in a network, the system comprising:

a controller configured to manage,

a threat monitor operable to monitor network data, to extract at least one set of network data, and to process the at least one set of network data to generate a report, and

a verifier including an agent coordinator operable to issue at least one of (i) instructions and (ii) indicators to an endpoint agent based on the report,

wherein,

the endpoint agent is operable to process the at least one of (i) instructions and (ii) indicators to generate verification information, and

the verifier includes a report analyzer operable to generate the at least one of (i) instructions and (ii) indicators.

31. The system according to claim 30 , further comprising:

an agent coordinator of the verifier,

wherein,

at least one of (i) the threat monitor and (ii) the agent coordinator is stored at a memory location on the endpoint.

32. The system according to claim 30 , further comprising:

an agent coordinator of the verifier,

wherein,

at least one of (i) the threat monitor and (ii) the agent coordinator is stored at a middleware layer communicatively coupled to a communication network.

33. The system according to claim 30 , wherein the verifier is operable to process the verification information to determine whether the verification information indicates a verified threat associated with the endpoint.

34. The system according to claim 30 ,

wherein,

the report includes structured threat intelligence, and

the verifier is operable to process the structured threat intelligence to issue the at least one of (i) instructions and (ii) indicators.

35. The system according to claim 30 , wherein the threat monitor includes an analyzer configured to process the at least one set of network data, the analyzer includes software executed by a hardware processor of the endpoint.

36. The system according to claim 35 , wherein the analyzer is a static analyzer.

37. The system according to claim 35 , wherein the analyzer is a dynamic analyzer.

38. The system according to claim 30 ,

wherein,

the controller is communicatively coupled to the threat monitor and the verifier via a communication network, and

the system further includes a SIEM managed by the controller that correlates verification information with intelligence gathered from at least one of (i) the endpoint agent, (ii) other endpoints, and (iii) other threat monitoring systems.

39. The system according to claim 30 , wherein the endpoint agent includes an audit module operable to process the at least one of (i) instructions and (ii) indicators to generate audit data, the audit module being software executed by a hardware processor of the endpoint.

40. The system according to claim 39 , wherein the endpoint agent includes a buffered storage module operable to store the audit data.

41. The system according to claim 39 , wherein the endpoint agent includes an indicator matcher operable to process audit data to produce the verification information.

42. The system according to claim 30 , wherein the endpoint agent includes a containment agent operable to perform a containment action based on the verification information.

43. The system according to claim 42 , wherein the containment agent is installed on the endpoint pursuant to instructions contained in a containment package configured by the agent coordinator based on the verification information.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: FIREEYE, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0776 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0771 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2016
From: CUNNINGHAM, SEAN; DANA, ROBERT; NARDONE, JOSEPH; FABER, JOSEPH; ARUNSKI, KEVIN
To: FIREEYE, INC.
Reel/Frame 037724/0567 →
Continuity (2)
Provisional Application 61800796 · Mar 15, 2013
Related Publication 20140344926A1 · Nov 20, 2014