IP Library Granted Patent US 9,912,684
Granted Patent B1
US 9,912,684 · App. 14/320,201 · Granted Mar 6, 2018

System and method for virtual analysis of network data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,684
App. No.
14/320,201
Granted
Mar 6, 2018
Kind
B1
Abstract

A system is provided with one or more virtual machines and a replayer. The virtual machine(s) are configured to mimic operations of a first device. The replayer is configured to mimic operations of a second device. Herein, the replayer receives a portion of network data under analysis, dynamically modifies the portion of the network data, and transmits the modified portion of the network data to at least one virtual machine of the one or more virtual machines in accordance with a protocol sequence utilized between the first device and the second device.

Claims (47)

1. A system comprising:

one or more virtual machines including a first virtual machine that is configured to operate as a first device representing a first computing system processing a browser application that issues requests to access information from a web server; and

a controller being software different from the one or more virtual machines that, upon execution by at least one hardware processor, is configured to receive a portion of network data under analysis, dynamically modify the portion of the network data, and transmit the modified portion of the network data to at least the first virtual machine of the one or more virtual machines in accordance with a protocol sequence utilized by the first device in communications with a second device,

wherein the controller is further configured to create an identifier based on at least one communication anomaly or execution anomaly associated with operations performed by the one or more virtual machines, the controller to transmit the identifier for transmission over a network.

2. The system of claim 1 , wherein the controller is configured to replay the protocol sequence.

3. The system of claim 1 , wherein the network data includes a data flow.

4. The system of claim 3 , wherein the data flow comprises a plurality of packets that include a session identifier to identify a communication session associated with the network data.

5. The system of claim 4 further comprising a heuristic module that, upon execution by the at least one hardware processor, is configured to determine whether network data analyzed by the heuristic module is suspicious and to provide to the controller the portion of the network data being a part of the data flow that is determined to be suspicious.

6. The system of claim 3 , wherein a configuration of the first virtual machine of the one or more virtual machines is based on an analysis of a packet format of the data flow being data that is transmitted from the first device.

7. The system of claim 3 , wherein a configuration of the first virtual machine of the one or more virtual machines is based on an analysis of a packet format of the data flow being data that is transmitted to the first device.

8. The system of claim 1 , wherein the one or more virtual machines is configured to mimic operations of the first device representing the first computing system processing the browser application.

9. The system of claim 1 , wherein the controller mimics operations of the second device representing a second computing system operating as the web server.

10. The system of claim 1 , wherein the controller is further configured to dynamically modify information within a response to a request initiated from a virtual machine of the one or more virtual machines to maintain the protocol sequence between the controller and the virtual machine.

11. The system of claim 10 , wherein the information dynamically modified by the controller includes a destination address.

12. The system of claim 1 further comprising a virtual switch that simulates a communication network between the controller and the one or more virtual machines and routes data packets associated with the network data to predetermined ports of the one or more virtual machines.

13. The system of claim 1 , wherein a configuration of a virtual machine of the one or more virtual machines corresponds to one or more features of the second device that are affected by the network data.

14. The system of claim 13 , wherein the features of the second device include at least one of (i) ports that are to receive the network data or (ii) one or more device drivers that are to respond to the network data.

15. The system of claim 1 , wherein operations of the one or more virtual machines that process the modified portion of the network data are monitored for unauthorized activity.

16. The system of claim 15 , wherein the unauthorized activity is detected by comparing a sequence of activities conducted by the one or more virtual machines against a predetermined sequence of activities.

17. The system of claim 16 , wherein the unauthorized activity is detected when the sequence of activities conducted by the one or more virtual machines includes one or more packets in addition to a sequence of packets expected to be generated by the one or more virtual machines.

18. The system of claim 16 , wherein the unauthorized activity is detected when the sequence of activities conducted by the one or more virtual machines includes one or more packets that differ from a sequence of packets expected to be generated by the one or more virtual machines.

19. The system of claim 1 , wherein the one or more virtual machines is configured to mimic performance of an operating system of the first device.

20. The system of claim 1 , wherein the one or more virtual machines is configured to mimic performance of at least one of (i) a port of the first device or (ii) a driver of the first device being a destination device.

21. The system of claim 1 , wherein a virtual machine of the one or more virtual machines is based on a software profile of the first device that is included within the network data.

22. A system comprising:

one or more virtual machines configured to operate as a first device; and

a controller being different from the one or more virtual machines that, upon execution by at least one hardware processor, is configured to receive a portion of network data under analysis, dynamically modify the portion of the network data, and transmit the modified portion of the network data to at least first virtual machine of the one or more virtual machines in accordance with a protocol sequence utilized by the first device in communications with a second device,

wherein the controller is configured to (i) operate as the second device by dynamically modifying session variables in one or more packets of the network data to emulate a sequence of network communications from the first device, (ii) create an identifier based on at least one communication anomaly or execution anomaly associated with operations performed by the one or more virtual machines, and (iii) transmit the identifier for transmission over a network.

23. The system of claim 22 , wherein the session variables include a dynamically assigned port.

24. The system of claim 22 , wherein the session variables include a transaction identifier.

25. A non-transitory computer readable medium including software that, when executed by one or more hardware processors, performing operations comprising:

configuring one or more virtual machines to operate as a first device, the one or more virtual machines includes a first virtual machine that is configured to operate as the first device representing a first computing system processing a browser application that issues requests to access information from a web server;

configuring a controller to operate as a second device, the controller being a software separate component than any of the one or more virtual machines;

receiving, by the controller, a portion of network data under analysis;

dynamically modifying, by the controller, the portion of the network data;

transmitting, by the controller, the modified portion of the network data to the first virtual machine of the one or more virtual machines in accordance with a protocol sequence utilized between the first device and the second device;

creating, by the controller, an identifier based on at least one communication anomaly or execution anomaly associated with operations performed by the first virtual machine; and

transmitting, by the controller, the identifier over a network for use in malware detection by a computing system other than the first computing system.

26. The medium of claim 25 , wherein network data includes a data flow.

27. The medium of claim 26 , wherein the data flow comprises a plurality of packets that include a session identifier to identify a communication session associated with the network data between the first device being a destination device for the network data and the second device being a source device of the network data.

28. The medium of claim 26 , wherein the processor further performing an operation of determining whether network data associated with the data flow is suspicious and providing the portion of the network data being a part of the data flow that is determined to be suspicious, to the controller.

29. The medium of claim 25 , wherein the one or more virtual machines is configured to mimic operations of the first device representing a first computing system processing a browser application that issues requests to access information from a web server.

30. The medium of claim 29 , wherein the controller mimics operations of the second device representing a second computing system operating as the web server.

31. The medium of claim 25 , wherein the controller is configured to dynamically modify information within a response to a request initiated from a virtual machine of the one or more virtual machines to maintain the protocol sequence between the controller and the virtual machine.

32. The medium of claim 31 , wherein the information dynamically modified by the controller includes a destination address.

33. The medium of claim 25 , wherein the controller is configured to mimic operations of the second device by dynamically modifying session variables in one or more packets of the network data to emulate a sequence of network communications from the first device.

34. The medium of claim 33 , wherein the session variables include a dynamically assigned port.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0140 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063113/0150 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2017
From: AZIZ, ASHAR; RADHAKRISHNAN, RAMESH; ISMAEL, OSMAN
To: FIREEYE, INC.
Reel/Frame 041125/0169 →