IP Library Granted Patent US 10,432,658
Granted Patent B2
US 10,432,658 · App. 14/600,885 · Granted Oct 1, 2019

Systems and methods for identifying and performing an action in response to identified malicious network traffic

Inventors: Gregory Thomas Back (Hendersonville, TN); Patrick Michael Cloke (Somerville, MA); Stephen Ralph Dicato, Jr. (Lynnfield, MA); Daniel Eugenio Espinal (Wellesley Hills, MA); Todd Aaron O'Boyle (Edwardsville, IL); John Sheldon Serafini (Hingham, MA)
Assignee: WATCHGUARD TECHNOLOGIES, INC.
H04L63/1441H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,432,658
App. No.
14/600,885
Granted
Oct 1, 2019
Kind
B2
Abstract

Computer-implemented systems, methods, and computer-readable media are provided for causing an action to be performed in response to a network communication, such as a malicious network communication. In accordance with some embodiments, a first network communication sent from a client device is received, and a protocol used in the first network communication is determined. Once the protocol is determined, the protocol may be implemented to enable a second network communication with the client device. An action to be performed based at least in part on the protocol may be identified, and an instruction may be sent to the client device in the second network communication.

Claims (32)

1. A computer-implemented method of determining a malware protocol being used by a malware application to communicate to a malicious system, so that a blackhole system may then use the determined protocol to direct a potentially infected client device to perform a conditional action, the method comprising:

responding to a determination using a list of domain names associated with malicious sources that a domain name received from the potentially infected client device is associated with a malicious system by sending the potentially infected client device an internet protocol (IP) address of the blackhole system rather than an IP address of the malicious system so as to intercept a first network communication from the potentially infected client device at the blackhole system;

determining a malware protocol of the malware application through pattern matching and real-time interaction with the potentially infected client device in an iterative process in which the blackhole system, in response to receiving the first network communication, attempts to establish a connection with the malware application from the potentially infected client device, by sending more than one response communications to that first network communication using a first guessed malware protocol and depending on whether or not that first guessed protocol establishes a connection with the malware application, iteratively using more than one successive, guessed malware protocols from a plurality of protocols, to the infected client device until a successful connection has been made to identify the corresponding guessed malware protocol as a matching protocol; and

the blackhole system using the matching protocol to emulate a malicious system by sending an instruction to the malware application to uninstall said malware application stored on the potentially infected client device.

2. The computer-implemented method of claim 1 , wherein the first network connection is established between the malware application and a subsystem that implements the malware protocol.

3. The computer-implemented method of claim 1 , wherein the conditional action includes gathering, at the potentially infected client device, information about the malware application.

4. The computer-implemented method of claim 1 , wherein the conditional action includes gathering, at the potentially infected client device, information about the potentially infected client device and sending said first network communication including the information.

5. The computer-implemented method of claim 1 , wherein the conditional action includes gathering, at the infected client device, information about a network connection.

6. The computer-implemented method of claim 1 , further comprising:

intercepting a communication from a compromised computer to the malicious system, wherein the compromised computer is the client device and wherein the communication is the first network communication; and

remediating malicious activity in the compromised computer by emulating the malicious system while sending the instruction to the malware application.

7. The computer-implemented method of claim 1 , further comprising:

intercepting a communication from a compromised computer to the malicious system, wherein the compromised computer is the client device and wherein the communication is the first network communication; and

gathering information about malicious activity in the compromised computer by emulating the malicious system while sending the instruction to the malware application.

8. A computer-implemented system for determining a malware protocol being used by a malware application to communicate to a malicious system, so that a blackhole system may then use the determined protocol to direct the client to perform a conditional action, comprising:

a memory device that stores instructions; and

one or more processors that execute the instructions to:

respond to a determination using a list of domain names associated with malicious sources that a domain name received from the potentially infected client device is associated with a malicious system by sending the potentially infected client device an internet protocol (IP) address of the blackhole system rather than an IP address of the malicious system so as to intercept a first network communication from the potentially infected client device at the blackhole system;

determine a malware protocol of the malware application through pattern matching and real-time interaction with the potentially infected client device in an iterative process in which the blackhole system, in response to receiving the first network communication, attempts to establish a connection with the malware application, by sending more than one response communications to that first communication using a first guessed malware protocol and depending on whether or not that first guessed protocol establishes a connection with the malware application, iteratively using more than one successive, guessed malware protocols from a plurality of protocols, to the potentially infected client device until a successful connection has been made to identify the corresponding guessed malware protocol as a matching protocol; and

use the matching protocol, by the blackhole system, to emulate a malicious system by sending an instruction to the malware application to uninstall said malware application stored on the potentially infected client device.

9. The system of claim 8 , wherein the connection is established between the malware application and a subsystem that implements the malware protocol.

10. The system of claim 8 , wherein the conditional action includes gathering, at the potentially infected client device, information about the malware application.

11. The system of claim 8 , wherein the conditional action includes gathering, at the potentially infected client device, information about the potentially infected client device and sending a network communication including the information.

12. The system of claim 8 , wherein the conditional action includes gathering, at the infected client device, information about a network connection.

13. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method of

using a list of domain names associated with malicious sources so as to determine a malware protocol being used by a malware application to communicate to a malicious system, so that a blackhole system may then use the determined protocol to direct a client device to perform a conditional action, the method comprising:

responding to a determination using said list of domain names associated with malicious sources that a domain name received from the potentially infected client device is associated with a malicious system by sending the potentially infected client device an internet protocol (IP) address of the blackhole system rather than an IP address of the malicious system so as to intercept a first network communication from the potentially infected client device at the blackhole system;

determining a malware protocol of the malware application through pattern matching and real-time interaction with the potentially infected client device in an iterative process in which the blackhole system, in response to receiving the first network communication, attempts to establish a connection with the malware application, by sending more than one response communications to that first communication using a first guessed malware protocol and depending on whether or not that first guessed protocol establishes a connection with the malware application, iteratively using more than one successive, guessed malware protocols from a plurality of protocols, to the infected client device until a successful connection has been made to identify the corresponding guessed malware protocol as a matching protocol; and

the blackhole system using the matching protocol to emulate a malicious system by sending an instruction to the malware application to uninstall said malware application stored on the potentially infected client device.

14. The non-transitory computer-readable medium of claim 13 , wherein the conditional action includes gathering, at the infected client device, information about the malware application.

15. The non-transitory computer-readable medium of claim 13 , wherein the conditional action includes gathering, at the infected client device, information about the infected client device.

16. The non-transitory computer-readable medium of claim 13 , wherein the conditional action includes gathering, at the infected client device, information about a network connection.

Assignments (10)
SECURITY INTEREST Recorded Jul 6, 2022
From: WATCHGUARD TECHNOLOGIES, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 060406/0682 →
SECURITY INTEREST Recorded Jul 6, 2022
From: WATCHGUARD TECHNOLOGIES, INC.
To: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P., AS COLLATERAL AGENT
Reel/Frame 060406/0720 →
RELEASE OF SECURITY INTEREST Recorded Jul 6, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 060406/0751 →
RELEASE OF SECURITY INTEREST Recorded Jun 1, 2020
From: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P.
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 052800/0973 →
SECURITY INTEREST Recorded Jun 1, 2020
From: WATCHGUARD TECHNOLOGIES, INC.
To: GOLDMAN SACHS BANK USA
Reel/Frame 052801/0668 →
SECURITY INTEREST Recorded May 7, 2018
From: WATCHGUARD TECHNOLOGIES, INC., AS GRANTOR
To: GOLDMAN SACHS SPECIALTY LENDING GROUP, L.P., AS COLLATERAL AGENT
Reel/Frame 045734/0051 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2018
From: PERCIPIENT NETWORKS, LLC
To: WATCHGUARD TECHNOLOGIES, INC.
Reel/Frame 045350/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2018
From: THE MITRE CORPORATION
To: PERCIPIENT NETWORKS, LLC
Reel/Frame 045202/0660 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2017
From: CLOKE, PATRICK MICHAEL; DICATO, STEPHEN RALPH, JR; ESPINAL, DANIEL EUGENIO; O'BOYLE, TODD AARON; SERAFINI, JOHN SHELDON
To: PERCIPIENT NETWORKS, LLC
Reel/Frame 043472/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2017
From: BACK, GREGORY THOMAS
To: THE MITRE CORPORATION
Reel/Frame 043472/0381 →
Cited By (1)
US 12,395,506