IP Library Granted Patent US 9,674,210
Granted Patent B1
US 9,674,210 · App. 14/554,492 · Granted Jun 6, 2017

Determining risk of malware infection in enterprise hosts

Inventors: Alina M. Oprea (Arlington, MA); Ting-Fang Yen (Waltham, MA); Viktor Heorhiadi (Chapel Hill, NC); Michael Kendrick Reiter (Chapel Hill, NC); Ari Juels (Brookline, MA)
Assignees: EMC IP Holding Company LLC; University of North Carolina at Chapel Hill
H04L63/1425H04L63/0272H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,210
App. No.
14/554,492
Filed
Nov 26, 2014
Granted
Jun 6, 2017
Kind
B1
Art Unit
2435
USPC
726/25
Abstract

A processing device comprises a processor coupled to a memory and is configured to obtain data characterizing host devices of a computer network of an enterprise. The data is applied to a logistic regression model to generate malware infection risk scores for respective ones of the host devices. The malware infection risk scores indicate likelihoods that the respective host devices will become infected with malware. The logistic regression model incorporates features of the host devices including at least user demographic features, virtual private network (VPN) activity features and web activity features of the host devices, and the data characterizing the host devices comprises data for the incorporated features. Proactive measures are taken to prevent malware infection in a subset of the host devices based at least in part on the malware infection risk scores. The processing device may be implemented in the computer network or an associated network security system.

Claims (62)

1. A method comprising steps of:

obtaining data characterizing host devices of a computer network of an enterprise;

applying the data to a logistic regression model to generate malware infection risk scores for respective ones of the host devices; and

taking one or more proactive measures to prevent malware infection in one or more of the host devices based at least in part on the malware infection risk scores;

wherein the malware infection risk scores indicate likelihoods that the respective host devices will become infected with malware;

wherein the logistic regression model incorporates a plurality of features of the host devices as respective model variables including at least user demographic features, virtual private network (VPN) activity features and web activity features of the host devices;

wherein the user demographic features incorporated by the logistic regression model comprise at least one of user level in enterprise hierarchy and user technical level;

wherein the VPN activity features incorporated by the logistic regression model comprise number of VPN connections and duration of the VPN connections;

wherein the web activity features incorporated by the logistic regression model comprise web usage features and domain reputation features, the web usage features comprising number of distinct domains visited and the domain reputation features comprising number of connections challenged by web proxy and number of connections consented by web proxy;

wherein the data characterizing the host devices comprises data for the plurality of features incorporated by the logistic regression model; and

wherein the steps are performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 wherein taking one or more proactive measures further comprises:

identifying a subset of the host devices having malware infection risk scores above a specified threshold; and

applying the one or more proactive measures to the host devices in the subset but not to the host devices outside of the subset.

3. The method of claim 1 wherein the user demographic features incorporated by the logistic regression model further comprise one or more of user gender and user geographic location.

4. The method of claim 1 wherein the data characterizing the host devices for the user demographic features is obtained at least in part from one or more employee databases of the enterprise.

5. The method of claim 1 wherein the VPN activity features incorporated by the logistic regression model further comprise one or more of amount of data sent over VPN connections and number of external network addresses of VPN connections.

6. The method of claim 1 wherein the data characterizing the host devices for the VPN activity features is obtained at least in part from VPN logs of the enterprise.

7. The method of claim 1 wherein the web activity features incorporated by the logistic regression model further comprise visited web site category features.

8. The method of claim 7 wherein the visited web site category features comprise one or more of number of chat sites visited, number of file transfer sites visited, number of freeware sites visited, number of gaming sites visited, number of social-networking sites visited, number of streaming sites visited and number of non-categorized sites visited.

9. The method of claim 7 wherein the domain reputation features further comprise one or more of number of connections blocked by web proxy and number of new domains visited.

10. The method of claim 1 wherein the data characterizing the host devices for the web activity features is obtained at least in part from web proxy logs of the enterprise.

11. The method of claim 1 further comprising generating the logistic regression model.

12. The method of claim 11 wherein generating the logistic regression model comprises:

identifying a plurality of potential malware infection related features of the host devices;

obtaining data indicative of actual malware infection of particular ones of the host devices;

determining correlations of the data indicative of actual malware infection with respective ones of the potential malware infection related features;

selecting a subset of the potential malware infection related features based on said correlations; and

configuring the logistic regression model to incorporate the selected subset of the potential malware infection related features as said plurality of features of the host devices incorporated by the logistic regression model.

13. The method of claim 12 wherein obtaining data indicative of actual malware infection comprises obtaining that data at least in part from anti-virus logs of the enterprise.

14. An article of manufacture comprising a processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device:

to obtain data characterizing host devices of a computer network of an enterprise;

to apply the data to a logistic regression model to generate malware infection risk scores for respective ones of the host devices; and

to take one or more proactive measures to prevent malware infection in one or more of the host devices based at least in part on the malware infection risk scores;

wherein the malware infection risk scores indicate likelihoods that the respective host devices will become infected with malware;

wherein the logistic regression model incorporates a plurality of features of the host devices as respective model variables including at least user demographic features, virtual private network (VPN) activity features and web activity features of the host devices;

wherein the user demographic features incorporated by the logistic regression model comprise at least one of user level in enterprise hierarchy and user technical level;

wherein the VPN activity features incorporated by the logistic regression model comprise number of VPN connections and duration of the VPN connections;

wherein the web activity features incorporated by the logistic regression model comprise web usage features and domain reputation features, the web usage features comprising number of distinct domains visited and the domain reputation features comprising number of connections challenged by web proxy and number of connections consented by web proxy; and

wherein the data characterizing the host devices comprises data for the plurality of features incorporated by the logistic regression model.

15. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

said at least one processing device being configured:

to obtain data characterizing host devices of a computer network of an enterprise;

to apply the data to a logistic regression model to generate malware infection risk scores for respective ones of the host devices; and

to take one or more proactive measures to prevent malware infection in one or more of the host devices based at least in part on the malware infection risk scores;

wherein the malware infection risk scores indicate likelihoods that the respective host devices will become infected with malware;

wherein the logistic regression model incorporates a plurality of features of the host devices as respective model variables including at least user demographic features, virtual private network (VPN) activity features and web activity features of the host devices;

wherein the user demographic features incorporated by the logistic regression model comprise at least one of user level in enterprise hierarchy and user technical level;

wherein the VPN activity features incorporated by the logistic regression model comprise number of VPN connections and duration of the VPN connections;

wherein the web activity features incorporated by the logistic regression model comprise web usage features and domain reputation features, the web usage features comprising number of distinct domains visited and the domain reputation features comprising number of connections challenged by web proxy and number of connections consented by web proxy; and

wherein the data characterizing the host devices comprises data for the plurality of features incorporated by the logistic regression model.

16. The apparatus of claim 15 wherein the data characterizing the host devices for the user demographic features is obtained at least in part from one or more employee databases of the enterprise.

17. The apparatus of claim 15 wherein the data characterizing the host devices for the VPN activity features is obtained at least in part from VPN logs of the enterprise.

18. The apparatus of claim 15 wherein the data characterizing the host devices for the web activity features is obtained at least in part from web proxy logs of the enterprise.

19. A network security system comprising the apparatus of claim 15 .

20. The article of manufacture of claim 14 wherein the program code when executed by said at least one processing device further causes said at least one processing device to generate the logistic regression model by:

identifying a plurality of potential malware infection related features of the host devices;

obtaining data indicative of actual malware infection of particular ones of the host devices;

determining correlations of the data indicative of actual malware infection with respective ones of the potential malware infection related features;

selecting a subset of the potential malware infection related features based on said correlations; and

configuring the logistic regression model to incorporate the selected subset of the potential malware infection related features as said plurality of features of the host devices incorporated by the logistic regression model.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
CONFIRMATORY LICENSE Recorded Sep 7, 2016
From: UNIVERSITY OF NORTH CAROLINA, CHAPEL HILL
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 039923/0356 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2015
From: HEORHIADI, VIKTOR; REITER, MICHAEL KENDRICK
To: UNIVERSITY OF NORTH CAROLINA AT CHAPEL HILL
Reel/Frame 036059/0438 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2015
From: OPREA, ALINA M.; YEN, TING-FANG; JUELS, ARI
To: EMC CORPORATION
Reel/Frame 036059/0305 →