IP Library Granted Patent US 9,672,359
Granted Patent B2
US 9,672,359 · App. 14/793,683 · Granted Jun 6, 2017

Real-time network updates for malicious content

Inventors: Boris Yanovsky (Saratoga, CA); Scott D. Eikenberry (Menlo Park, CA); Bhuvanasundar Rachamreddy (Sunnyvale, CA); Nick Bilogorskiy (Sunnyvale, CA); Gayatri Bhimaraju (Cupertino, CA)
Assignee: SONICWALL INC.
G06F21/566H04L51/04H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,672,359
App. No.
14/793,683
Granted
Jun 6, 2017
Kind
B2
Abstract

A global response network collects, analyzes, and distributes “cross-vector” threat-related information between security systems to allow for an intelligent, collaborative, and comprehensive real-time response.

Claims (72)

1. A method for establishing the reputation of message components, the method comprising:

transmitting over a network communication interface a request for data from a first electronic computing device;

receiving the requested data over the network communication interface;

executing instructions out of a memory, wherein execution of the instructions by a processor breaks the received data into a plurality of component parts, wherein the plurality of component parts are stored in a database;

receiving a first set of information from a second electronic computing device, wherein the received first set of information is associated with a bad reputation and includes a plurality of constituent components, and a processor at the second electronic computing device generates the plurality of constituent components from data contained in a message by breaking the data contained in the message into the plurality of constituent components;

comparing the received plurality of constituent components with the plurality of component parts;

identifying that at least one of the constituent components of the plurality of constituent components matches at least one of the component parts;

associating each of the plurality of component parts with a threat, wherein the database is updated with information indicating that the plurality of component parts are associated with the threat;

transmitting over a network communication interface a second request for additional data from the first electronic computing device;

receiving the additional requested data over the network communication interface;

breaking the additional received data into a plurality of additional component parts;

storing the plurality of additional component parts in the database;

receiving a second set of information from a second electronic computing device, wherein the received information is associated with the bad reputation and includes a plurality of additional constituent components, and the processor at the second electronic computing device generates the plurality of additional constituent components from data contained in a second message by breaking the data from the second message into the plurality of additional constituent components;

comparing the received plurality of additional constituent components with the plurality of additional component parts and with the plurality of constituent components;

identifying that at least one of the additional constituent components of the plurality of additional constituent components matches at least one of the plurality of additional component parts or at least one of the plurality of constituent components; and

associating each of the plurality of additional component parts with the threat, wherein the database is updated with information indicating that the plurality of additional component parts are associated with the threat.

2. The method of claim 1 , further comprising:

periodically transmitting over the network communication interface requests for other additional data from the first electronic computing device;

receiving the plurality of other additional requested data over the network communication interface;

the processor executing instructions out of a memory breaking the received data into a plurality of other additional component parts; and

storing the other additional component parts in the database.

3. The method of claim 1 , wherein the bad reputation associated with the first set of information is identified by the processor at the second electronic computing device according to one or more votes from one or more users.

4. The method of claim 1 , wherein the bad reputation associated with the first set of information is identified by the processor executing instructions out of the memory at the second electronic computing device to include at least one of a computer virus or malware.

5. The method of claim 1 , wherein the processor executing instructions out of the memory also generates a signature from the data contained in the message, the signature associated with a recognized pattern in the message.

6. A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for performing a method for establishing the reputation of message components, the method comprising:

transmitting over a network communication interface a request for data from a first electronic computing device;

receiving the requested data over the network communication interface;

breaking the received data into a plurality of component parts, wherein the plurality of component parts are stored in a database;

receiving a first set of information from a second electronic computing device, wherein the received first set of information is associated with a bad reputation and includes a plurality of constituent components, and a processor at the second electronic computing device generates the plurality of constituent components from data contained in a message by breaking the data contained in the message into the plurality of constituent components;

comparing the received plurality of constituent components with the plurality of component parts;

identifying that at least one of the constituent components of the plurality of constituent components matches at least one of the component parts;

associating each of the plurality of component parts with a threat, wherein the database is updated with information indicating that the plurality of component parts are associated with the threat;

transmitting over a network communication interface a second request for additional data from the first electronic computing device;

receiving the additional requested data over the network communication interface;

breaking the additional received data into a plurality of additional component parts;

storing the plurality of additional component parts in the database;

receiving a second set of information from the second electronic computing device, wherein the received information is associated with the bad reputation and includes a plurality of additional constituent components, and the processor at the second electronic computing device generates the plurality of additional constituent components from data contained in a second message by breaking the data from the second message into the plurality of additional constituent components;

comparing the received plurality of additional constituent components with the plurality of additional component parts and with the plurality of constituent components;

identifying that at least one of the additional constituent components of the plurality of additional constituent components matches at least one of the plurality of additional component parts or at least one of the plurality of constituent components; and

associating each of the plurality of the plurality of additional component parts with the threat, wherein the database is updated with information indicating that the plurality of additional component parts are associated with the threat.

7. The non-transitory computer-readable storage medium of claim 6 , the program further executable to:

periodically transmit over the network communication interface requests for other additional data from the first electronic computing device;

receive the other additional requested data over the network communication interface; a processor executing instructions out of a memory breaking the received data into a plurality of more other additional component parts; and

store the plurality of more other additional component parts in a database.

8. The non-transitory computer-readable storage medium of claim 6 , wherein the bad reputation associated with the first set of information is identified by the processor at the second electronic computing device according to one or more votes from one or more users.

9. The non-transitory computer-readable storage medium of claim 6 , wherein the bad reputation associated with the first set of information is identified by the processor executing instructions out of the memory at the second electronic computing device to include at least one of a computer virus or malware.

10. The non-transitory computer-readable storage medium of claim 6 , wherein the processor executing instructions out of the memory also generates a signature from the data contained in the message, the signature associated with a recognized pattern in the message.

11. A system for establishing the reputation of message components, the system comprising:

a data center electronic computing device including a processor, a memory, and one or more network communication interfaces, wherein the data center electronic computing device:

transmits over a network communication interface of the one or more network communication interfaces a request for data from a first electronic computing device;

receives the requested data over the network communication interface of the one or more network communication interfaces;

breaks the received data into a plurality of component parts, wherein the plurality of component parts are stored in a database; and

receives a first set of information from a second electronic computing device, wherein the received first set of information is associated with a bad reputation and includes a plurality of constituent components, and a processor at the second electronic computing device generates the plurality of constituent components from data contained in a message by breaking the data contained in the message into the plurality of constituent components;

compares the received plurality of constituent components with the plurality of component parts;

identifies that at least one of the constituent components of the plurality of constituent components matches at least one of the component parts;

associates each of the component parts with a threat, wherein the database is updated with information indicating that the component parts are associated with the threat;

transmits over a network communication interface of the one or more network communication interfaces a second request for additional data from the first electronic computing device;

receives the additional requested data over the network communication interface of the one or more network communication interfaces;

breaks the additional received data into a plurality of additional component parts;

stores the plurality of additional component parts in the database;

receives a second set of information from the second electronic computing device, wherein the received information is associated with the bad reputation and includes a plurality of additional constituent components, and the processor at the second electronic computing device generates the plurality of additional constituent components from data contained in a second message by breaking the data from the second message into the plurality of additional constituent components;

compares the received plurality of additional constituent components with the plurality of additional component parts and with the plurality of constituent components;

identifies that at least one of the additional constituent components of the plurality of additional constituent components matches at least one of the plurality of additional component parts or at least one of the plurality of constituent components; and

associates each of the plurality of the plurality of additional component parts with the threat, wherein the database is updated with information indicating that the plurality of additional component parts are associated with the threat.

12. The system of claim 11 , wherein the data center electronic computing device:

periodically transmits over the network communication interface of the one or more network communication interfaces requests for other additional data from the first electronic computing device;

receives the other additional requested data over the network communication interface of the one or more network communication interfaces;

breaks the received data into a plurality of more other additional component parts; and

stores the plurality of more other additional component parts in the database.

13. The system of claim 11 , wherein the bad reputation associated with the first set of information is identified by the processor at the second electronic computing device according to one or more votes from one or more users.

14. The system of claim 11 , wherein the bad reputation associated with the first set of information is identified by the processor executing instructions out of the memory at the second electronic computing device to include at least one of a computer virus or malware.

15. The system of claim 11 , wherein the processor executing instructions out of the memory at the second electronic computing device also generates a signature from the data contained in the message, the signature associated with a recognized pattern in the message.

Assignments (25)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Jan 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044997/0017 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF REEL 037160 FRAME 0142 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0812 →
RELEASE OF REEL 037160 FRAME 0239 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0115 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037160 FRAME 0171 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0253 →
MERGER Recorded Dec 12, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037277/0824 →
CHANGE OF NAME Recorded Dec 12, 2015
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 037277/0815 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2015
From: YANOVSKY, BORIS; EIKENBERRY, SCOTT D.; RACHAM, BHUVAN; BILOGORSKIY, NICK; BHIMARAJU, GAYATRI
To: SONICWALL, INC.
Reel/Frame 037277/0796 →
MERGER Recorded Dec 12, 2015
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 037277/0801 →
CONVERSION AND NAME CHANGE Recorded Dec 12, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037278/0872 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - NOTES Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 037160/0142 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - TERM LOAN Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037160/0239 →
SUPPLEMENTAL PATENT SECURITY AGREEMENT - ABL Recorded Nov 25, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; BOOMI, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037160/0171 →
Continuity (4)
Continuation 13967210 · Aug 14, 2013
Continuation 12661470 · Mar 16, 2010
Provisional Application 61160613 · Mar 16, 2009
Related Publication 20160026797A1 · Jan 28, 2016