IP Library Granted Patent US 9,930,065
Granted Patent B2
US 9,930,065 · App. 14/668,329 · Granted Mar 27, 2018

Measuring, categorizing, and/or mitigating malware distribution paths

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,930,065
App. No.
14/668,329
Granted
Mar 27, 2018
Kind
B2
Abstract

Systems and methods for event path traceback may utilize a processor and a path traceback and categorization (ATC) module in communication with the processor. The processor may be configured to perform processing associated with receiving network traffic from a network. The ATC module may be configured to perform processing associated with identifying an event within the network traffic, tracing a sequence of network transactions related to the event, and outputting an annotated event path (AMP) including data about the event and the sequence of network transactions related to the event. Performing processing associated with tracing the sequence of network transactions may comprise reconstructing a sequence of transactions within the network traffic that led to the event while filtering out unrelated traffic within the network traffic.

Claims (63)

1. A system for event path traceback comprising:

at least one processor; and

a data storage device having computer readable program code embodied therewith;

the at least one processor configured to execute the computer readable program code to perform processing associated with receiving network traffic from a network; and

an attack path traceback and categorization module in communication with the at least one processor, the attack path traceback and categorization module being configured to perform processing associated with identifying an event within the network traffic;

tracing a sequence of network transactions related to the event; and

outputting an annotated malware path including data about the event and the sequence of network transactions related to the event;

wherein performing processing associated with tracing the sequence of network transactions comprises:

reconstructing a sequence of transactions within the network traffic that led to the event based on a download referrer, at least one surrogate referrer indicator, and at least one of a drive-by uniform resource identifier similarity and a download domain recurrence, wherein the at least one surrogate referrer indicator is not the download referrer, and

filtering out unrelated traffic within the network traffic.

2. The system of claim 1 , wherein the attack path traceback and categorization module is further configured to perform processing associated with determining a cause of the event based on the sequence of network transactions.

3. The system of claim 2 , wherein the cause is an update, a social engineering attack, or a drive-by download.

4. The system of claim 2 , wherein the at least one surrogate referrer indicator comprises at least one of:

a candidate exploit domain age;

a download path length; and

a user agent popularity.

5. The system of claim 1 , wherein performing processing associated with identifying the event comprises detecting the event within the network traffic and other network traffic conducted by a computer on the network affected by the event within a period of time near the event.

6. The system of claim 1 , wherein performing processing associated with outputting the annotated malware path comprises automatically labeling at least one node within the sequence.

7. The system of claim 6 , wherein performing processing associated with outputting the annotated malware path further comprises adding each node to the annotated malware path.

8. The system of claim 1 , wherein performing processing associated with tracing the sequence of network transactions comprises analyzing at least one of the following features of at least two nodes of the network traffic:

location;

referrer;

domain in uniform resource identifier;

uniform resource identifier in content;

same domain;

commonly exploitable content; and

same effective second level domains.

9. The system of claim 1 , further comprising a malware download defense module in communication with the processor, the malware download defense module being configured to perform processing associated with receiving the annotated malware path and creating a countermeasure based on statistical data in the annotated malware path.

10. The system of claim 9 , wherein performing processing associated with creating the countermeasure comprises identifying a landing node, an injection node, and an exploit node for an event within the annotated malware path, wherein the event is caused by a drive-by download.

11. The system of claim 9 , wherein performing processing associated with creating the countermeasure comprises generating a report for display, the report comprising at least a portion of the annotated malware path.

12. The system of claim 9 , wherein the malware download defense module is further configured to perform processing associated with training a new malware download defense module based on the created countermeasure.

13. A method for event path traceback comprising:

performing processing associated with receiving, with a processor, network traffic from a network;

performing processing associated with identifying, with an attack path traceback and categorization module in communication with the processor, an event within the network traffic;

performing processing associated with tracing, with the attack path traceback and categorization module, a sequence of network transactions related to the event; and

performing processing associated with outputting, with the attack path traceback and categorization module, an annotated malware path including data about the event and the sequence of network transactions related to the event;

wherein performing processing associated with tracing the sequence of network transactions comprises:

performing processing associated with reconstructing a sequence of transactions within the network traffic that led to the event based on a download referrer, at least one surrogate referrer indicator and at least one of a drive-by uniform resource identifier similarity and a download domain recurrence, wherein the at least one surrogate referrer indicator is not the download referrer, and

filtering out unrelated traffic within the network traffic.

14. The method of claim 13 , wherein the event is caused by an executable download on a computer on the network.

15. The method of claim 14 , further comprising performing processing associated with determining, with the attack path traceback and categorization module, a cause of the event based on the sequence of network transactions.

16. The method of claim 15 , wherein the cause is an update, a social engineering attack, or a drive-by download.

17. The method of claim 15 , wherein the at least one surrogate referrer indicator at least one of:

a candidate exploit domain age;

a download path length; and

a user agent popularity.

18. The method of claim 13 , wherein performing processing associated with identifying the event comprises detecting the event within the network traffic and other network traffic conducted by a computer on the network affected by the event within a period of time near the event.

19. The method of claim 13 , wherein performing processing associated with outputting the annotated malware path comprises automatically labeling at least one node within the sequence.

20. The method of claim 19 , wherein performing processing associated with outputting the annotated malware path further comprises adding each node to the annotated malware path.

21. The method of claim 13 , wherein performing processing associated with tracing the sequence of network transactions comprises analyzing at least one of the following features of at least two nodes of the network traffic:

location;

referrer;

domain in uniform resource identifier;

uniform resource identifier in content;

same domain;

commonly exploitable content; and

same effective second level domains.

22. The method of claim 13 , further comprising:

performing processing associated with receiving, with a malware download defense module in communication with the processor, the annotated malware path; and

performing processing associated with creating, with the malware download defense module, a countermeasure based on statistical data in the annotated malware path.

23. The method of claim 22 , wherein performing processing associated with creating the countermeasure comprises identifying a landing node, an injection node, and an exploit node for an event within the annotated malware path, wherein the event is caused by a drive-by download.

24. The method of claim 22 , wherein performing processing associated with creating the countermeasure comprises generating a report for display, the report comprising at least a portion of the annotated malware path.

25. The method of claim 22 , further comprising performing processing associated with training, with the malware download defense module, a new malware download defense module based on the created countermeasure.

Assignments (19)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 070086/0189 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048386/0329 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: DAMBALLA, INC.
Reel/Frame 044535/0907 →
SECURITY INTEREST Recorded Dec 27, 2017
From: DAMBALLA, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044492/0654 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: DAMBALLA, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040297/0988 →
CONFIRMATORY LICENSE Recorded Sep 30, 2016
From: UNIVERSITHY OF GEORGIA
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 040193/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2016
From: NELMS, TERRY LEE; PERDISCI, ROBERTO
To: UNIVERSITY OF GEORGIA RESEARCH FOUNDATION, INC.; DAMBALLA, INC.
Reel/Frame 038999/0244 →