IP Library Granted Patent US 9,948,671
Granted Patent B2
US 9,948,671 · App. 14/317,785 · Granted Apr 17, 2018

Method and system for network-based detecting of malware from behavioral clustering

Inventors: Roberto Perdisci (Smyrna, GA); Wenke Lee (Atlanta, GA); Gunter Ollmann (Norcross, GA)
Assignee: Damballa, Inc.
H04L63/145G06F21/56H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,948,671
App. No.
14/317,785
Granted
Apr 17, 2018
Kind
B2
Abstract

A computerized system and method for performing behavioral clustering of malware samples, comprising: executing malware samples in a controlled computer environment for a predetermined time to obtain Hypertext Transfer Protocol. HTTP traffic; clustering the malware samples into at least one cluster based on network behavioral information from the HTTP traffic; and extracting, using the at least one processor, network signatures from the HTTP traffic information for each cluster, the network signatures being indicative of malware infection.

Claims (44)

1. A computerized method for detecting at least one malicious Hypertext Transfer Protocol (HTTP) request based on behavioral clustering of malware samples, comprising:

collecting information about at least one HTTP request from malware samples in a controlled computer environment for a predetermined time;

clustering, the malware samples into at least one cluster based on structural similarities among a plurality of the HTTP requests, the structural similarities comprising similarities between: a request method, Uniform Resource Locator (URL) path, URL page name, a parameter name, and a parameter value;

applying a single-linkage hierarchical clustering algorithm and a Davies-Bouldin (DB) cluster validity index to create a plurality of clusters;

merging together two or more of the plurality of clusters into meta clusters based on at least one HTTP behavior of each of the two or more of the plurality of clusters;

extracting network signatures from the information about the at least one HTTP request for each at least one cluster, the network signatures being indicative of malware infection; and

detecting at least one malicious HTTP request based on at least one of the extracted network signatures.

2. The method of claim 1 , further comprising clustering the malware samples into coarse-grain clusters based on statistical features extracted from the malicious HTTP request of the malware samples.

3. The method of claim 2 , further comprising finding a fine-grain distance between malware samples.

4. The method of claim 3 , further comprising applying a single-linkage hierarchical clustering algorithm and a Davies-Bouldin (DB) cluster validity index to split each coarse-grain cluster into fine-grain clusters based on structural features.

5. The method of claim 4 , wherein the merging together of the clusters comprises:

defining a cluster centroid for each of the fine-grain malware clusters;

defining distances between cluster centroids; and

grouping together malware samples that are very close to each other based on the determined distances.

6. The method of claim 5 , further comprising using the information about the at least one HTTP request generated by the malware samples in each meta-cluster as input to an automatic network signature generation algorithm.

7. The method of claim 6 , further comprising extracting network signatures from the malware samples in meta-clusters.

8. The method of claim 7 , further comprising filtering out network signatures that generate false positives.

9. A computerized system for detecting at least one malicious Hypertext Transfer Protocol (HTTP) request based on behavioral clustering of malware samples, comprising:

a non-transitory device comprising at least one processor configured for:

collecting information about at least one HTTP request information from malware samples in a controlled computer environment for a predetermined time;

clustering, using at least one processor, the malware samples into at least one cluster based on structural similarities among a plurality of the HTTP requests, the structural similarities comprising similarities between: a request method, Uniform Resource Locator (URL) path, URL page name, a parameter name, and a parameter value;

applying a single-linkage hierarchical clustering algorithm and a Davies-Bouldin (DB) cluster validity index to create a plurality of clusters;

merging together two or more of the plurality of clusters into meta clusters, based on at least one HTTP behavior or each of the two or more of the plurality of clusters;

extracting, using the at least one processor, network signatures from the information about the at least one HTTP request for each at least one cluster, the network signatures being indicative of malware infection; and

detecting, using the at least one processor, at least one malicious HTTP request based on at least one of the extracted network signatures.

10. The system of claim 9 , wherein the processor is further configured for clustering the malware samples into coarse-grain clusters based on statistical features extracted from the malicious HTTP request of the malware samples.

11. The system of claim 10 , wherein the processor is further configured for finding a fine-grain distance between malware samples.

12. The system of claim 11 , wherein the processor is further configured for applying a single-linkage hierarchical clustering algorithm and a Davies-Bouldin (DB) cluster validity index to split each coarse-grain cluster into fine-grain clusters based on structural features.

13. The system of claim 12 , wherein the merging together of the clusters comprises:

defining a cluster centroid for each of the fine-grain malware clusters;

defining distances between cluster centroids; and

grouping together malware samples that are very close to each other based on the determined distances.

14. The system of claim 13 , wherein the processor is further configured for using the information about the at least one HTTP request generated by the malware samples in each meta-cluster as input to an automatic network signature generation algorithm.

15. The system of claim 14 , wherein the processor is further configured for extracting network signatures from the malware samples in meta-clusters.

16. The system of claim 15 , wherein the processor is further configured for filtering out network signatures that generate false positives.

17. A computerized method for detecting at least one malicious Hypertext Transfer Protocol (HTTP) request based on behavioral clustering of malware samples, comprising:

collecting information about at least one HTTP request from malware samples in a controlled computer environment for a predetermined time;

clustering, the malware samples into at least one cluster based on statistical features among a plurality of HTTP requests, the statistical features comprising: a total number of HTTP requests, a number of GET requests, a number of POST requests, an average length of URLs, an average number of parameters in the request; an average amount of data sent by POST requests, and an average length of the response;

after clustering based on statistical features, clustering, the malware samples into at least one cluster based on structural similarities among the plurality of the HTTP requests;

identify a cluster centroid of each malware cluster;

identify a distance between cluster centroids;

merging together two or more of the plurality of clusters into meta clusters, based on the distance between the two or more cluster centroids;

extracting network signatures from the information about the at least one HTTP request for each at least one cluster, the network signatures being indicative of malware infection; and

detecting at least one malicious HTTP request based on at least one of the extracted network signatures.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 070086/0189 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048386/0329 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: DAMBALLA, INC.
Reel/Frame 044535/0907 →
SECURITY INTEREST Recorded Dec 27, 2017
From: DAMBALLA, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044492/0654 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: DAMBALLA, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040297/0988 →
RELEASE OF SECURITY INTEREST Recorded Sep 8, 2016
From: SILICON VALLEY BANK
To: DAMBALLA, INC.
Reel/Frame 039678/0960 →
SECURITY INTEREST Recorded May 14, 2015
From: DAMBALLA, INC.
To: SILICON VALLEY BANK
Reel/Frame 035639/0136 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2014
From: PERDISCI, ROBERTO; LEE, WENKE; OLLMANN, GUNTER
To: DAMBALLA, INC.
Reel/Frame 033764/0949 →
Continuity (3)
Continuation 13008257 · Jan 18, 2011
Provisional Application 61296288 · Jan 19, 2010
Related Publication 20150026808A1 · Jan 22, 2015