IP Library Patent Application 14458065
Patent Application
App. No. 14/458,065

EMULATING SHELLCODE ATTACKS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/458,065
Abstract

A system includes one or more “BotMagnet” modules that are exposed to infection by malicious code. The BotMagnets may include one or more virtual machines hosing operating systems in which malicious code may be installed and executed without exposing sensitive data or other parts of a network. In particular, outbound traffic may be transmitted to a Sinkhole module that implements a service requested by the outbound traffic and transmits responses to the malicious code executing within the BotMagnet. In the case of shellcode attacks, unsuccessful attacks may be emulated by selecting a corresponding emulator that will receive and execute instructions, as would a successful shellcode attack. Events occurring on the BotMagnet and Sinkhole are correlated and used to characterize the malicious code. The characterization may be transmitted to other computer systems in order to detect instances of the malicious code.

Claims (69)

1 . A method comprising:

executing, on a computer system including one or more processors, a characterizing module and an engagement module and a sinkhole module each executing one or more services on one or more ports;

detecting, by the engagement module, suspicious activities by a source with respect to the one or more ports of the engagement module;

allowing, by the engagement module, installation by the source of a malicious module in the engagement module;

forwarding, by the engagement module, traffic generated by the malicious module, to the sinkhole module;

responding, by the sinkhole module, to the traffic by processing the traffic and a transmitting a simulated response to the malicious module according to a service of the one or more services of the sinkhole module;

transmitting by the engagement module a first plurality of events describing behavior of the malicious module executing within the engagement module;

transmitting by the sinkhole module a second plurality of events processing of the traffic by the sinkhole module;

correlating, by the characterizing module the first and second plurality of events to generate a descriptor of the malicious module; and

using by one of the computer system and a different computer system, the descriptor to at least one of prevent an attempt to install the malicious module and remove an instance of the malicious module on the one of the computer system and the different computer system.

2 . The method of claim 1 , wherein the engagement module includes one or more virtual machines executing on the computer system and each executing one or more of the one or more services.

3 . The method of claim 2 , wherein the one or more virtual machines each hosts an operating system instance.

4 . The method of claim 2 , wherein the sinkhole module includes one or more virtual machines executing on the computer system and each executing one or more of the one or more services.

5 . The method of claim 2 , wherein the engagement module and sinkhole module are executed within a single host operating system instance.

6 . The method of claim 1 , further comprising:

detecting generation of the traffic by the malicious module;

identifying a service requested by the traffic; and

instantiating the sinkhole module and provisioning the sinkhole module with the service in response to detecting generation of the traffic and identifying the service.

7 . The method of claim 1 , further comprising:

transforming the traffic, by the sinkhole module, to obtain transformed data;

forwarding, by the sinkhole module, the transformed data to a destination specified in the traffic; and

receiving, by the sinkhole module, an external response to the transformed data; and

wherein the second plurality of events include the external response.

8 . The method of claim 7 , further comprising substituting an address of the sinkhole module in the transformed data for a source address included in the traffic.

9 . The method of claim 1 , wherein a descriptor of the malicious module includes at least one of:

actions and corresponding times of actions taken by the malicious module; and

a signature of the executable code defining the malicious module.

10 . The method of claim 1 , wherein:

the traffic includes a request for an address for a command and control module, the method; and

the simulated response includes an address of the sinkhole module.

11 . The method of claim 1 , wherein the first plurality of events include at least one of:

scanning by the malicious module of ports of one or more addresses in a network of the computer system;

downloading of additional executable code by the malicious module;

attempting to upload payload data by the malicious module to one of the computer system and the other computer system;

attempting to contact a command and control module; and

generating malicious traffic.

12 . A method comprising:

providing, on a computer system, an engagement module and a sinkhole module executing a plurality of virtual machines executing a plurality of services on a plurality of ports;

detecting, by the engagement module, suspicious activities by a source with respect to one or more of the plurality of ports of the engagement module;

allowing, by the engagement module, installation by the source of a malicious module in a virtual machine of the plurality of virtual machines of the engagement module;

forwarding, by the engagement module, traffic generated by the malicious module, to the sinkhole module;

responding, by the sinkhole module, to the traffic by processing the traffic and a transmitting a response to the malicious module according to a service of the plurality of services of the sinkhole module;

transmitting by the engagement module and sinkhole module a plurality of events describing the suspicious activities, installation of the malicious module, the traffic, and the responses to a characterizing module;

generating, by the characterizing module, a descriptor of the malicious module according to the plurality of events; and

using by one of the computer system and a different computer system, the descriptor to at least one of detect an attempt to install the malicious module and remove an instance of the malicious module on the one of the computer system and the different computer system.

13 . The method of claim 12 , wherein the plurality of virtual machines of the engagement module and sinkhole module each hosts an operating system instance.

14 . The method of claim 12 , wherein the engagement module and sinkhole module are executed within a single host operating system instance.

15 . The method of claim 12 , further comprising:

detecting generation of the traffic by the malicious module;

identifying a service requested by the traffic; and

instantiating the sinkhole module and provisioning the sinkhole module with the service in response to detecting generation of the traffic and identifying the service;

16 . The method of claim 12 , further comprising:

transforming the traffic, by the sinkhole module, to obtain transformed data;

forwarding, by the sinkhole module, the transformed data to a destination specified in the traffic; and

receiving, by the sinkhole module, an external response to the transformed data; and

wherein the second plurality of events include the external response.

17 . The method of claim 16 , further comprising substituting an address of the sinkhole module in the transformed data for a source address included in the traffic.

18 . The method of claim 1 , wherein a descriptor of the malicious module includes at least one of:

actions and corresponding times of actions taken by the malicious module; and

a signature of the executable code defining the malicious module.

19 . The method of claim 12 , wherein:

the traffic includes a request for an address for a command and control module, the method; and

the simulated response includes an address of the sinkhole module.

20 . The method of claim 1 , wherein the plurality of events include at least one of:

scanning by the malicious module of ports of one or more addresses in a network of the computer system;

downloading of additional executable code by the malicious module;

attempting to upload payload data by the malicious module to one of the computer system and the other computer system;

attempting to contact a command and control module; and

generating malicious traffic.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: ATTIVO NETWORKS, INC.
To: SENTINELONE, INC.
Reel/Frame 062607/0046 →
SECURITY INTEREST Recorded May 7, 2020
From: ATTIVO NETWORKS, INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 052601/0978 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2014
From: VISSAMSETTY, VENU; SINGH, NAVTEJ; KAJEKAR, SACHIN
To: ATTIVO NETWORKS INC.
Reel/Frame 033519/0276 →