IP Library Granted Patent US 9,888,030
Granted Patent B2
US 9,888,030 · App. 14/267,422 · Granted Feb 6, 2018

Detection of stealthy malware activities with traffic causality and scalable triggering relation discovery

Inventors: Danfeng Yao (Blacksburg, VA); Hao Zhang (Blacksburg, VA)
Assignee: Virginia Tech Intellectual Properties, Inc.
H04L63/145G06F21/316G06F21/32G06F21/566G06F2221/2133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,888,030
App. No.
14/267,422
Filed
May 1, 2014
Granted
Feb 6, 2018
Kind
B2
Art Unit
2492
USPC
726/22
Abstract

A computer system for distinguishing user-initiated network traffic from malware-initiated network traffic comprising at least one central processing unit (CPU) and a memory communicatively coupled to the CPU. The memory includes a program code executable by the CPU to monitor individual network events to determine for an individual network event whether the event has a legitimate root-trigger. Malware-initiated traffic is identified as an individual network event that does not have a legitimate root-trigger.

Claims (33)

1. A computer system for distinguishing user-initiated network traffic from malware-initiated network traffic, the system comprising:

at least one central processing unit (CPU);

memory communicatively coupled to the CPU, the memory comprising program code executable by said at least one CPU to perform the following steps:

monitoring a plurality of unknown individual network events and identifying a traffic dependency among them, said dependency used to detect anomalies by confirming the legitimacy of the mot-trigger events;

converting a plurality of individual network events and a plurality of root-trigger events into a plurality of event pairs with comparable pairwise attributes, said pairwise attributes comprising one of the following: similarities in event's time stamps, domain names, host names, IP addresses, process IDs (PID), HTTP request's referral fields, network requests types, network requests content, network requests flags, to determine if there is a parent-child relationship between said one network event and one of its subsequent events wherein said root-trigger events are said parent, said individual network events are said child and said parent and said child are not identical;

said parent-child relationships between said individual network events and said root-trigger events are unknown when said individual network events and said root-trigger events are converted into event pairs;

determining for an individual child network event whether said individual child event has a legitimate parent root-trigger event; and

identifying malware-initiated traffic as an individual network event that does not have a legitimate parent root-trigger event.

2. The system of claim 1 wherein said system uses a pairing algorithm to extract the pairwise features and conduct learning classifiers to identify the dependency.

3. The system of claim 2 wherein said the machine learning classifier is a binary classification method.

4. The system of claim 1 wherein said the pairing algorithm includes a dictionary comprised of key-value pairs used to store a current network event,

wherein said key of said dictionary is the domain attribute of an event and said value is a set of requests, whose domain attribute is the same as said key; and

an event with an unmatched key value is filtered out.

5. The system of claim 1 wherein a feature extraction method is used to transform two individual network events into comparable pairwise attributes which are processed by learning algorithms.

6. The system of claim 5 wherein a binary classification method is used to discover whether a triggering relation exists in an event pair or not.

7. The system of claim 1 wherein a triggering relation graph is used to identify events that do not have any valid root triggers events.

8. The system of claim 7 wherein said triggering relation graph is used to detect anomalous or malicious network activities.

9. The system of claim 1 wherein one or more cost matrices are defined to penalize missed parent-child relationships.

10. The system of claim 9 wherein said one or more cost matrices are defined to weigh false positives and false negatives differently.

11. The system of claim 10 wherein said one or more cost matrices are defined to penalize false negatives 10 times more than false positives.

12. The system of claim 1 wherein malware-initiated traffic is identified as an individual network event that does not have a legitimate parent root-trigger by iteratively pairing an individual child network event with a plurality of parent root-trigger events.

13. The system of claim 1 wherein said system uses a pairing algorithm to extract the pairwise features, then applies pre-defined rules to identify the parent-child relationships of new events based on their pairwise features.

14. A method for creating a model to detect malware comprising the steps of:

obtaining network data comprising individual network events and root-trigger events, wherein said root-trigger events are user input events that occur prior in time to said individual network events;

performing a pairing operation on two or more of said individual network events and at least one said root-trigger events to transform said individual network events and said root-trigger events into event pairings having comparable pairwise attributes, said pairwise attributes comprising a one-parent-multiple-children relationship between said root-trigger events and said two or more individual network events, wherein said root-trigger events are said parent, said individual network events are said children and said parent and said children are not identical;

said individual network events and said root-trigger events are unknown when said individual network events and said root-trigger events are converted into event pairings; and

said parent-child relationships or other lineage relationships between said individual network events and said root-trigger events are unknown when said individual network events and said root-trigger events are converted into event pairings;

building a classification model that is used to identify malware-initiated traffic as an individual network event that does not have a legitimate root-trigger event.

15. The method of claim 14 wherein one or more binary classification algorithms are used.

16. The method of claim 14 wherein a root-trigger event is paired with a first network event and said first network event is paired with a second network event.

17. The method of claim 1 wherein said parent and said children form a branch.

18. The method of claim 14 wherein said parent and children form a chain.

19. The method of claim 14 wherein said parent and children form a chain comprised of a grandparent-parent-child relationship.

Assignments (3)
CONFIRMATORY LICENSE Recorded Mar 10, 2016
From: VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 038050/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2014
From: YAO, DANFENG; ZHANG, HAO
To: VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY
Reel/Frame 033994/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2014
From: VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIVERSITY
To: VIRGINIA TECH INTELLECTUAL PROPERTIES, INC.
Reel/Frame 033995/0018 →
Continuity (3)
Continuation 13255567
Provisional Application 61210097 · Mar 13, 2009
Related Publication 20140310808A1 · Oct 16, 2014