IP Library Granted Patent US 9,609,005
Granted Patent B2
US 9,609,005 · App. 14/496,860 · Granted Mar 28, 2017

Cross-view malware detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,609,005
App. No.
14/496,860
Granted
Mar 28, 2017
Kind
B2
Abstract

In an example, a cross-view detection engine is disclosed for detecting malware behavior. Malware may attempt to avoid detection by remaining in volatile memory for as long as possible, and writing to disk only when necessary. To avoid detection, the malware may also provide a pseudo-driver at a file system level that performs legitimate-looking dummy operations. A firmware-level driver may simultaneously perform malicious operations. The cross-view detection engine detects this behavior by deconstructing call traces from the file system-level operations, and reconstructing call traces from firmware-level operations. If the traces do not match, the object may be flagged as suspicious.

Claims (49)

1. A computing apparatus comprising:

a processor;

a memory; and

one or more hardware and/or software logic elements comprising a crossview detection engine operable for:

observing a first operation performed by an executable object on the memory at a first computational abstraction level;

observing a substantially simultaneous second operation performed by the executable object on the memory at a second computational abstraction level, wherein the second abstraction level is different from the first abstraction level;

determining that the first operation does not substantially have the same computational effect as the second operation, comprising converting the first operation and the second operation into a comparable format; and

designating the executable object as suspect.

2. The computing apparatus of claim 1 , wherein the first abstraction level is a file system driver level.

3. The computing apparatus of claim 1 , wherein the second abstraction level is a firmware level.

4. The computing apparatus of claim 1 , wherein the second abstraction level is a lower abstraction level than the first abstraction level.

5. The computing apparatus of claim 1 , wherein the second operation is a write operation.

6. The computing apparatus of claim 1 , wherein acting on the determination comprises designating the executable object as malware.

7. The computing apparatus of claim 1 , wherein acting on the determination comprises designating the executable object as suspicious and reporting the executable object to a server.

8. The computing apparatus of claim 1 , wherein making a determination that the first operation does not substantially match the second operation comprises reconstructing one or more call traces from the second operation.

9. The computing apparatus of claim 1 , wherein making a determination that the first operation does not substantially match the second operation comprises deconstructing one or more call traces from the first operation.

10. The computing apparatus of claim 1 , wherein making a determination that the first operation does not substantially match the second operation comprises:

reconstructing one or more call traces from the second operation;

deconstructing one or more call traces from the first operation; and

comparing the reconstructed call traces to the deconstructed call traces.

11. The computing apparatus of claim 1 , wherein observing the first operation performed by the executable object on the memory at the first abstraction level comprises performing dynamic analysis of system-level call tracing.

12. The computing apparatus of claim 11 , wherein observing the first operation performed by the executable object on the memory at the first abstraction level further comprises real-time analysis of call traces.

13. The computing apparatus of claim 1 , wherein observing the substantially simultaneous second operation performed by the executable object on the memory at a second abstraction level comprises intercepting disk access information from disk protocols.

14. One or more non-transitory computer-readable mediums having stored thereon executable instructions for providing a cross-view detection engine operable for:

observing a first operation performed by an executable object on a memory at a first computational abstraction level;

observing a substantially simultaneous second operation performed by the executable object on the memory at a second computational abstraction level, wherein the second abstraction level is different from the first abstraction level;

determining that the first operation does not substantially have the same computational effect as the second operation, comprising converting the first operation and the second operation into a comparable format; and

designating the executable object as suspicious.

15. The one or more computer-readable mediums of claim 14 , wherein the first abstraction level is a file system driver level.

16. The one or more computer-readable mediums of claim 14 , wherein the second abstraction level is a firmware level.

17. The one or more computer-readable mediums of claim 14 , wherein the second abstraction level is a lower abstraction level than the first abstraction level.

18. The one or more computer-readable mediums of claim 14 , wherein the second operation is a write operation.

19. The one or more computer-readable mediums of claim 14 , wherein acting on the determination comprises designating the executable object as malware.

20. The one or more computer-readable mediums of claim 14 , wherein acting on the determination comprises designating the executable object as suspicious and reporting the executable object to a server.

21. The one or more computer-readable mediums of claim 14 , wherein making a determination that the first operation does not substantially match the second operation comprises:

reconstructing one or more call traces from the second operation;

deconstructing one or more call traces from the first operation; and

comparing the reconstructed call traces to the deconstructed call traces.

22. The one or more computer-readable mediums of claim 14 , wherein observing the first operation performed by the executable object on the memory at the first abstraction level comprises performing real-time dynamic analysis of system-level call tracing.

23. The one or more computer-readable mediums of claim 14 , wherein observing the substantially simultaneous second operation performed by the executable object on the memory at a second abstraction level comprises intercepting disk access information from disk protocols.

24. A computer-implemented method of providing a cross-view detection engine, comprising:

observing a first operation performed by an executable object on the memory at a first computational abstraction level;

observing a substantially simultaneous second operation performed by the executable object on the memory at a second computational abstraction level, wherein the second abstraction level is different from the first abstraction level;

determining that the first operation does not substantially have the same computational effect as the second operation, comprising converting the first operation and the second operation into a comparable format; and

designating the executable object as suspicious.

25. The method of claim 24 , wherein making a determination that the first operation does not substantially match the second operation comprises:

reconstructing one or more call traces from the second operation;

deconstructing one or more call traces from the first operation; and

comparing the reconstructed call traces to the deconstructed call traces.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2015
From: HUNT, SIMON; MANKIN, JENNIFER; ZIMMERMAN, JEFFREY
To: MCAFEE, INC.
Reel/Frame 034830/0697 →