IP Library Granted Patent US 9,876,806
Granted Patent B2
US 9,876,806 · App. 14/496,158 · Granted Jan 23, 2018

Behavioral detection of malware agents

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,876,806
App. No.
14/496,158
Granted
Jan 23, 2018
Kind
B2
Abstract

In an example, a detection engine identifies potential malware objects according to behavior. In order to circumvent blacklists and fingerprint-based detection, a malware server may frequently change domain names, and change the fingerprints of distributed malware agents. A malware agent may perform only an initial DNS lookup, and thereafter communicate with the malware command-and-control server via “naked” HTTP packets using the raw IP address of the server. The detection engine identifies malware agents by this behavior. In one example, if an executable object makes repeated HTTP requests to an address after the DNS lookup “time to live” has expired, the object may be flagged as potential malware.

Claims (17)

1. A computing apparatus, implemented by a hardware processor and memory, for detecting behavior of a malware agent, comprising: a network interface operable for connecting to a data network; and one or more logic elements, including at least the hardware processor and memory, comprising a detection engine operable for: inspecting an HTTP request provided on the network interface; identifying a domain name server (DNS) request associated with the HTTP request, the DNS request having a time-to-live; determining that the time-to-live of the DNS request is expired; designating the HTTP request as suspicious based at least in part on the expiration of the DNS request; and determining that the DNS request occurred before an intervening DNS request, and designating the HTTP request as not malware; wherein the detection engine is further operable for designating a parent process of the HTTP request as suspicious.

2. The computing apparatus of claim 1 , wherein the detection engine is further operable for designating the parent process as malware.

3. The computing apparatus of claim 1 , wherein the detection engine is further operable for taking remediative action on the parent process.

4. The computing apparatus of claim 1 , wherein the detection engine is further operable for: determining that the parent process is designated on a whitelist; and taking no remediative action on the parent process.

5. The computing apparatus of claim 1 , wherein the detection engine is further operable for notifying a security server of the HTTP request.

6. The computing apparatus of claim 5 , wherein the detection engine is further operable for receiving threat intelligence from the security server.

7. The computing apparatus of claim 1 , wherein the detection engine is further operable for classifying incoming traffic as one of DNS, hypertext transfer protocol (HTTP), and other traffic.

8. The computing apparatus of claim 7 , wherein the detection engine is further operable for ignoring traffic classified as other traffic.

9. The computing apparatus of claim 1 , wherein the detection engine is further operable for: detecting a DNS request; and storing response parameters for the DNS request.

10. One or more non-transitory computer-readable mediums for detecting behavior of a malware agent having stored thereon executable instructions for providing a detection engine operable for: inspecting an HTTP request; identifying a domain name server (DNS) request associated with the HTTP request, the DNS request having a time-to-live; determining that the time-to-live of the DNS request is expired; designating the HTTP request as suspicious based at least in part on the expiration of the DNS request; and determining that the DNS request occurred before an intervening DNS request, and designating the HTTP request as not malware; wherein the detection engine is further operable for designating a parent process of the HTTP request as suspicious.

11. The one or more computer-readable mediums of claim 10 , wherein the detection engine is further operable for designating the parent process as malware.

12. The one or more computer-readable mediums of claim 10 , wherein the detection engine is further operable for taking remediative action on the parent process.

13. The one or more computer-readable mediums of claim 10 , wherein the detection engine is further operable for: determining that the parent process is designated on a whitelist; and taking no remediative action on the parent process.

14. The one or more computer-readable mediums of claim 10 , wherein the detection engine is further operable for notifying a security server of the HTTP request.

15. The one or more computer-readable mediums of claim 14 , wherein the detection engine is further operable for receiving threat intelligence from the security server.

16. A computer-implemented method of detecting behavior of a malware agent, comprising: inspecting an HTTP request provided in a network packet received on a network interface; identifying a domain name server (DNS) request associated with the HTTP request, the DNS request having a time-to-live; determining that the time-to-live of the DNS request is expired; designating the HTTP request and a parent process of the network packet as suspicious based at least in part on the expiration of the DNS request; and determining that the DNS request occurred before an intervening DNS request, and designating the HTTP request as not malware; designating a parent process of the HTTP request as suspicious.

17. The method of claim 16 , further comprising: determining that the parent process has previously provided at least one other HTTP request with an expired DNS request; and designating the network packet and the parent process as malware based at least in part on the determining.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2014
From: MONDIGUING, STEPHEN; CRUZ, BENJAMIN
To: MCAFEE INC.
Reel/Frame 034081/0757 →