IP Library Granted Patent US 9,832,227
Granted Patent B2
US 9,832,227 · App. 14/599,811 · Granted Nov 28, 2017

System and method for network level protection against malicious software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,832,227
App. No.
14/599,811
Granted
Nov 28, 2017
Kind
B2
Abstract

A method in one example implementation includes receiving information related to a network access attempt on a first computing device with the information identifying a software program file associated with the network access attempt. The method also includes evaluating a first criterion to determine whether network traffic associated with the software program file is permitted and then creating a restriction rule to block the network traffic if the network traffic is not permitted. The first criterion includes a trust status of the software program file. In specific embodiments, the method includes pushing the restriction rule to a network protection device that intercepts the network traffic associated with the software program file and applies the restriction rule to the network traffic. In more specific embodiments, the method includes searching a whitelist identifying trustworthy software program files to determine the trust status of the software program file.

Claims (45)

1. One or more non-transitory computer readable media that include code for execution and when executed by one or more processors causes the one or more processors to:

populate, by a computing device, a process traffic mapping database with host event information associated with a network access attempt initiated by a process executing on a host, wherein the host event information includes process traffic information and program file information corresponding to a plurality of program files on the host, the plurality of program files mapped to the process in the host and including at least one executable file and at least one library module loaded by the process executing on the host;

receive an inventory of program files stored on the host, wherein the inventory of program files includes identifications of new program files that have been added to the host;

determine a respective trust status of each program file identified in the inventory;

if a program file identified in the inventory is determined to be untrusted, obtain process traffic information corresponding to the program file from the process traffic mapping database;

create a rule for the program file using the obtained process traffic information; and

push the rule to a network protection device, wherein the rule is configured to allow network traffic associated with the program file to access a server subnet and to block network traffic associated with the program file from accessing a host subnet.

2. The one or more non-transitory computer readable media of claim 1 , wherein the inventory is received at predetermined intervals of time.

3. The one or more non-transitory computer readable media of claim 1 , wherein the trust status is determined based, at least in part, on one or more whitelists.

4. The one or more non-transitory computer readable media of claim 1 , wherein the trust status is determined based, at least in part, on one or more blacklists.

5. The one or more non-transitory computer readable media of claim 1 , wherein the trust status is determined based, at least in part, on one or more state changes of the program file.

6. The one or more non-transitory computer readable media of claim 1 , wherein the inventory includes identifications of any changed program files on the host.

7. The one or more non-transitory computer readable media of claim 1 , wherein the rule includes at least one of restricting network traffic associated with the program file and logging information related to network traffic associated with the program file.

8. The one or more non-transitory computer readable media of claim 1 , wherein the code for execution, when executed by the one or more processors, causes the one or more processors to:

receive the host event information at the computing device from the host.

9. The one or more non-transitory computer readable media of claim 1 , wherein the process traffic information comprises a source address and a destination port number of the network access attempt.

10. The one or more non-transitory computer readable media of claim 1 , wherein a process traffic mapping element of the host is queried to determine the plurality of program files mapped to the process in the process traffic mapping element of the host.

11. An apparatus, comprising:

a protection module;

a memory element comprising instructions associated with the protection module; and

one or more processors operable to execute the instructions to:

populate a process traffic mapping database with host event information associated with a network access attempt initiated by a process executing on a host, wherein the host event information includes process traffic information and program file information corresponding to a plurality of program files on the host, the plurality of program files mapped to the process in the host and including at least one executable file and at least one library module loaded by the process executing on the host;

receive an inventory of program files stored on the host, wherein the inventory of program files includes identifications of new program files that have been added to the host;

determine a respective trust status of each program file identified in the inventory;

if a program file identified in the inventory is determined to be untrusted, obtain process traffic information corresponding to the program file from the process traffic mapping database;

create a rule for the program file using the obtained process traffic information; and

push the rule to a network protection device, wherein the rule is configured to allow network traffic associated with the program file to access a server subnet and to block network traffic associated with the program file from accessing a host subnet.

12. The apparatus of claim 11 , wherein the inventory is received at predetermined intervals of time.

13. The apparatus of claim 11 , wherein the trust status is determined based on at least one of:

one or more whitelists;

one or more blacklists; and

one or more state changes of the program file.

14. The apparatus of claim 11 , wherein the inventory includes identifications of any changed program files on the host.

15. The apparatus of claim 11 , wherein the one or more processors are operable to execute the instructions to:

receive the host event information from the host.

16. The apparatus of claim 15 , wherein the process traffic information comprises a source address and a destination port number of the network access attempt, and wherein the process traffic information is mapped to program file information corresponding to the program file in the process traffic mapping database.

17. The method, comprising:

populating, by a computing device, a process traffic mapping database with host event information associated with a network access attempt initiated by a process executing on a host, wherein the host event information includes process traffic information and program file information corresponding to a plurality of program files on the host, the plurality of program files mapped to the process in the host and including at least one executable file and at least one library module loaded by the process executing on the host;

receiving an inventory of program files stored on the host, wherein the inventory of program files includes identifications of new program files that have been added to the host;

determining a respective trust status of each program file identified in the inventory;

if a program file identified in the inventory is determined to be untrusted, obtaining process traffic information corresponding to the program file from the process traffic mapping database;

creating a rule for the program file using the obtained process traffic information; and

pushing the rule to a network protection device, wherein the rule is configured to allow network traffic associated with the program file to access a server subnet and to block network traffic associated with the program file from accessing a host subnet.

18. The method of claim 17 , further comprising:

receiving the host event information at the computing device at the host.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →