IP Library Granted Patent US 10,084,817
Granted Patent B2
US 10,084,817 · App. 14/482,696 · Granted Sep 25, 2018

Malware and exploit campaign detection system and method

Inventors: Mohamed Saher (Austin, TX); Jayendra Pathak (Austin, TX)
Assignee: NSS Labs, Inc.
H04L63/1491G06F17/30864G06F21/53G06F21/566H04L63/0272H04L63/1416H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,817
App. No.
14/482,696
Granted
Sep 25, 2018
Kind
B2
Abstract

A malware and exploit campaign detection system and method are provided that cannot be detected by the malware or exploit campaign. The system may provide threat feed data to the vendors that produce in-line network security and end point protection (anti virus) technologies. The system may also be used as a testing platform for 3 rd party products. Due to the massive footprint of the system's cloud infrastructure and disparate network connections and geo-location obfuscation techniques, NSS can locate and monitor malware across the globe and provide detailed threat analysis for each specific region, as they often support and host different malware/cybercrime campaigns.

Claims (24)

1. A malware and exploit campaign detection system, comprising:

a plurality of computer systems;

a capture stack that is configured to issue a uniform resource locator to each computer system to download a piece of malicious code;

a replay stack that is configured to test the piece of malicious code in a live environment and generate data about the replay of the piece of malicious code;

a proxy stack that is configured to perform testing of the piece of malicious code without accessing the uniform resource locator, wherein the testing includes a formulation of remote parameters of an original malicious website, pulling and reassembling the archive of the original malicious website, unpacking the archive, and launching a fully-functional copy of the original malicious website; and

a master hypervisor controller that controls the capture stack, the replay stack and the proxy stack.

2. The system of claim 1 , wherein the capture stack, the replay stack and the proxy stack run in parallel.

3. The system of claim 1 further comprising a zero day module that identifies zero day attacks.

4. The system of claim 1 further comprising Structured Query Language (SQL) servers configured to store data of the computer system.

5. The system of claim 1 further comprising a transfer server.

6. The system of claim 1 , wherein the capture stack is configured to create a copy of the piece of malicious code and catalogs operating system changes caused by the piece of malicious code.

7. The system of claim 1 , wherein the capture stack is configured to capture communications with the plurality of computer systems.

8. The system of claim 1 , wherein each stack is one or more server computers.

9. The system of claim 8 , wherein each stack has a virtual machine.

10. A malware and exploit campaign detection method, method comprising:

providing a plurality of computer systems;

executing a capturing process, wherein the capturing process issues a uniform resource locator to each computer system to download a piece of malicious code;

executing a replay process, wherein the replay process tests the piece of malicious code in a live environment and generates data about the replay process of the piece of malicious code;

executing a proxying process, the proxying process performs testing of the piece of malicious code without accessing the uniform resource locator, wherein the proxying process includes a formulation of remote parameters of an original malicious website, pulling and reassembling the archive of the original malicious website, unpacking the archive, and launching a fully-functional copy of the original malicious website; and

controlling, using a master hypervisor controller, the capture process, the replay process and the proxy process.

11. The method of claim 10 further comprising executing the capture process, the replay process and the proxy process in parallel.

12. The method of claim 10 further comprising identifying, using a zero day module, zero day attacks.

13. The method of claim 10 , wherein executing the capturing process further comprises creating a copy of the piece of malicious code and cataloging operating system changes caused by the piece of malicious code.

14. The method of claim 10 , wherein executing the capturing process further comprises capturing communications with the plurality of computer systems.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 4, 2018
From: COMERICA BANK
To: NSS LABS, INC.
Reel/Frame 045722/0963 →
SECURITY INTEREST Recorded Mar 30, 2018
From: NSS LABS, INC.
To: SILICON VALLEY BANK
Reel/Frame 045400/0631 →
SECURITY INTEREST Recorded Mar 31, 2016
From: NSS LABS, INC.
To: COMERICA BANK
Reel/Frame 038166/0019 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2014
From: SAHER, MOHAMED; PATHAK, JAYENDRA
To: NSS LABS, INC.
Reel/Frame 034160/0969 →
Continuity (2)
Provisional Application 61876704 · Sep 11, 2013
Related Publication 20150074810A1 · Mar 12, 2015
Cited By (29)
US 12,190,330 US 12,200,006 US 12,204,564 US 12,216,794 US 12,223,060 US 12,259,882 US 12,265,896 US 12,273,367 US 12,277,232 US 12,282,564 US 12,288,233 US 12,299,065 US 12,335,297 US 12,348,485 US 12,353,405 US 12,353,563 US 12,375,527 US 12,381,915 US 12,412,140 US 12,425,437 US 12,536,329 US 12,587,555 US 12,591,828 US 12,609,938 US 12,641,108 US 12,688,324 US 12,694,044 US 12,705,382 US 12,718,167