Exploit detection of malware and malware families
According to one embodiment, a computerized method comprises, accessing information associated with one or more observed events, wherein one or more of the observed events constitutes an anomalous behavior; accessing a reference model based on a first plurality of events, the reference model comprises a first event of the first plurality of events, a second event of the first plurality of events and a relationship that identifies that the second event of the first plurality of events is based on the first event of the first plurality of events, wherein at least one of the first event and the second event constitutes an anomalous behavior; and comparing the information associated with the one or more observed events with the reference model to determine whether at least one observed event of the one or more observed events matches at least one of the first event of the first plurality of events or the second event of the first plurality of events that constitutes the anomalous behavior is provided.
1. A computerized method for detecting malware comprising:
accessing information associated with one or more observed events, wherein at least one of the one or more of the observed events includes an observed anomalous behavior;
accessing a reference model, the reference model is based on a first plurality of events and comprises a first event of the first plurality of events, a second event of the first plurality of events and a relationship that identifies that the second event of the first plurality of events is based on the first event of the first plurality of events, wherein at least one of the first event and the second event includes a first anomalous behavior and the relationship included in the first plurality of events includes a second anomalous behavior; and
analyzing, using a machine learning technique, (i) the information associated with the one or more observed events and (ii) the reference model to determine whether a level of correlation between the one or more observed events and the reference model is at least a first predetermined threshold;
responsive to determining the level of correlation is at least the first determined threshold, determining the one or more observed events are associated with malware; and
inferring that at least a third event has occurred without detection based on the reference model, wherein the third event is absent from the information associated with the one or more observed events,
wherein each of the one or more observed events, the first event of the first plurality of events, the second event of the first plurality of events, and the third event are each associated with at least one of: a process, a non-executable file, an address or a location within a storage module of an electronic device, a website address, or an Internet Protocol (IP) address.
2. The computerized method of claim 1 , wherein accessing the information associated with one or more observed events further comprises:
accessing one or more particulars of at least a first observed event of the one or more observed events, wherein the analyzing includes analysis of the one or more particulars.
3. The computerized method of claim 1 , wherein accessing the reference model further comprises accessing relationships between each event of the first plurality of events.
4. The computerized method of claim 1 further comprising:
enhancing, as a result of the analyzing using the machine learning technique, the reference model by adding at least an added first event to the reference model, the added first event being included in the information associated with the one or more observed events.
5. The computerized method of claim 4 , further comprising:
updating, as a result of the analyzing using the machine learning technique, one or more correlation rules for classifying malware.
6. The computerized method of claim 1 , wherein the one or more observed events matches with the reference model when the one or more observed events are present in the reference model.
7. The method of claim 1 , wherein each of the observed anomalous behavior, the first anomalous behavior and the second anomalous behavior is one of either: (i) a first atypical or malicious event, or (ii) a first atypical or malicious relationship.
8. A computerized method comprising:
accessing information associated with a first plurality of observed events, the first plurality of observed events comprising a first observed event, a second observed event and a relationship that identifies that the second observed event of the first plurality of observed events is based on the first observed event of the first plurality of observed events, wherein the relationship includes an observed anomalous behavior;
accessing a reference model, the reference model is based on a second plurality of events and comprises a first event of the second plurality of events, a second event of the second plurality of events and a relationship that identifies that the second event of the second plurality of events is based on the first event of the second plurality of events, wherein the relationship associated with the first event and the second event of the reference model includes an anomalous behavior;
analyzing, using the machine learning technique, the information associated with the first plurality of observed events and the reference model to determine whether a level of correlation between the one or more observed events and the reference model is at least a first predetermined threshold;
responsive to determining the level of correlation is at least the first determined threshold, determining the one or more observed events are associated with malware; and
inferring that at least a third event has occurred without detection based on the reference model, wherein the third event is absent from the information associated with the one or more observed events,
wherein each of the one or more observed events, the first event of the first plurality of events, the second event of the first plurality of events, and the third event are each associated with at least one of: a process, a non-executable file, an address or a location within a storage module of an electronic device, a website address, or an Internet Protocol (IP) address.
9. The computerized method of claim 8 , wherein accessing the first set of information further comprises:
accessing one or more particulars of at least one of the first observed event of the first of the plurality of observed events or the second observed event of the first plurality of observed events.
10. The computerized method of claim 8 , wherein accessing the reference model further comprises accessing relationships between each event of the plurality of observed events.
11. The computerized method of claim 8 further comprising:
inferring that at least a second relationship identifying that the third event is based on the first observed event of the first plurality of observed events has occurred without detection based on the reference model, wherein the inferred second relationship was not included in the information associated with first plurality of observed events.
12. The computerized method of claim 8 further comprising:
enhancing, as a result of the analyzing using the machine learning technique, the reference model by adding at least a second relationship identifying that a third event of the second plurality of events is based on the first event of the second plurality of events to the reference model, the added second relationship being included in the information associated with the first plurality of observed events.
13. The computerized method of claim 8 , wherein each of the observed anomalous behavior, the first anomalous behavior and the second anomalous behavior is one of either: (i) a first atypical or malicious event, or (ii) a first atypical or malicious relationship.
14. A system comprising:
one or more hardware processors; and
a non-transitory storage module communicatively coupled to the one or more processors, the storage module comprises
(i) an event log to receive and store information associated with one or more observed events, wherein each of the one or more observed events is associated with at least one of: a process, a non-executable file, an address or a location within a storage module of an electronic device, a website address, or an Internet Protocol (IP) address,
(ii) a machine learning data store to store one or more reference models,
(iii) a gathering logic in communication with the machine learning data store and the event log that, upon execution by the one or more processors,
(a) accesses the information associated with the plurality of observed events, and
(b) accesses the one or more reference models, and
(iv) a matching logic in communication with the gathering logic that, upon execution by the one or more processors, (1) analyzes, using a machine learning technique, the information associated with the one or more observed events and the one or more reference models to determine whether a level of correlation between the one or more observed events and the reference model is at least a first predetermined threshold, wherein a relationship included in at least one of the one or more reference models includes an anomalous behavior, and (2) responsive to determining the level of correlation is at least the first predetermined threshold, determining the one or more observed events are associated with malware; and
(v) a machine learning logic in communication with the machine learning data store and the event log control logic that, when executed by the one or more processors, infers that at least a first event has occurred without detection based on the reference model, wherein the inferred first event was not included in the information associated with the one or more observed events.
15. The system of claim 14 , wherein the information associated with the one or more observed events comprises a second event that includes an observed anomalous behavior.
16. The system of claim 14 , wherein a first reference model of the one or more reference models includes a first event of the first reference model, a second event of the first reference model and a relationship identifying that the second event of the first reference model is based on the first event of the first reference model.
17. The system of claim 14 , wherein a first reference model of the one or more reference models includes a mathematical union of a second reference model and a third reference model.
18. The system of claim 14 , wherein the accessing of the information associated with the one or more observed events and the accessing of the one or more reference models is triggered by reception of a predetermined amount of data.
19. The system of claim 14 , further comprising:
a machine learning logic in communication with the machine learning data store and the event log control logic that, when executed by the one or more processors, enhances a first reference model of the one or more reference models by adding at least one observed event to the first reference model of the one or more reference models, the added one or more observed events being included in the information associated with one or more observed events.
20. The computerized method of claim 14 , wherein the one or more observed events matches with the reference model when the one or more observed events are present in the reference model.
21. The system of claim 15 , wherein the observed anomalous behavior is one of either: (i) a first atypical or malicious event, or (ii) a first atypical or malicious relationship.
22. A system comprising:
one or more hardware processors; and
a non-transitory storage module communicatively coupled to the one or more processors, the storage module comprises (i) an event log to store received information associated with one or more observed events, (ii) a machine learning data store to store one or more reference models, and (iii) logic that, upon execution by the one or more processors, accesses the information associated with the one or more observed events from the event log;
accesses one or more reference models from the machine learning data store; and analyzes, using a machine learning technique, the information associated with the one or more observed events and at least one of the one or more reference models to determine whether a level of correlation between the one or more observed events and the reference model is at least a first predetermined threshold, wherein a relationship included in at least one of the one or more reference models includes an anomalous behavior;
responsive to determining the correlation is at least the first determined threshold, determines the one or more observed events are associated with malware; and
inferring that at least a third event has occurred without detection based on the reference model, wherein the third event is absent from the information associated with the one or more observed events,
wherein the one or more observed events and the third event are each associated with at least one of: a process, a non-executable file, an address or a location within a storage module of an electronic device, a website address, or an Internet Protocol (IP) address.
23. The system of claim 22 , wherein the information associated with the one or more observed events comprises at least a first event of the one or more observed events that includes the anomalous behavior.
24. The system of claim 22 , wherein a first reference model of the one or more reference models comprises at least a first event of the first reference model, a second event of the first reference model, and a relationship identifying that the second event of the first reference model is based on the first event of the first reference model, wherein each of the first event of the first reference model and the second event of the first reference model are each associated with at least one of: a process, a non-executable file, an address or a location within a storage module of an electronic device, a website address, or an Internet Protocol (IP) address.
25. The system of claim 22 further comprising:
a machine learning logic in communication with the machine learning data store and the event log that, when executed by the one or more processors, infers that at least a first event has occurred without detection based on at least a first reference model of the one or more the reference models, wherein the inferred first event was not included in the information associated with the one or more observed events.
26. The system of claim 22 further comprising:
a machine learning logic in communication with the machine learning data store and the event log that, when executed by the one or more processors, enhances a first reference model of the one or more reference models by adding at least one observed event to the first reference model of the one or more reference models, the added one or more observed events being included in the information associated with one or more observed events.
27. The method of claim 1 further comprising:
generating a visual representation illustrating a potential malware infection based on the analyzing of the information associated with the one or more observed events and the reference model, the visual representation comprising one or more nodes.
28. A system for detecting malware comprising:
one or more hardware processors; and
a non-transitory storage module communicatively coupled to the one or more processors, the storage module comprising logic that, upon execution by the one or more processors, performs operations comprising:
observing one or more events during processing of an object within a virtual machine;
selecting a reference model based on the one or more observed events, the reference model comprising a first event of a first plurality of events, a second event of the first plurality of events and a relationship that identifies that the second event of the first plurality of events is based on the first event of the first plurality of events, wherein at least one of the first event and the second event includes a first anomalous behavior and the relationship includes a second anomalous behavior;
analyzing, using a machine learning technique, (i) the information associated with the one or more observed events and (ii) the reference model to determine whether a level of correlation of the one or more observed events and the reference model is at least a first predetermined threshold;
responsive to determining the level of correlation is at least the first determined threshold, determining the one or more observed events are associated with malware; and
inferring that at least a third event has occurred without detection based on the reference model, wherein the third event is absent from the information associated with the one or more observed events,
wherein each of the one or more observed events, the first event of the first plurality of events, the second event of the first plurality of events, and the third event are each associated with at least one of: a process, a non-executable file, an address or a location within a storage module of an electronic device, a website address, or an Internet Protocol (IP) address.
29. The system of claim 28 , wherein the one or more processors and the storage module are included within an endpoint device.