IP Library Granted Patent US 9,954,872
Granted Patent B2
US 9,954,872 · App. 14/823,916 · Granted Apr 24, 2018

System and method for identifying unauthorized activities on a computer system using a data structure model

Inventors: Alen Capalik (Pacific Palisades, CA); David Andrews (Los Angeles, CA); Ben Becker (Santa Monica, CA)
Assignee: COUNTERTACK INC.
H04L63/1416H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,954,872
App. No.
14/823,916
Granted
Apr 24, 2018
Kind
B2
Abstract

A computer implemented method includes monitoring activity on the virtual machine. A plurality of activities being performed at the virtual machine is identified. Each of the activities includes an activity source, an activity target, and an association between the activity source and the activity target. The activity information is stored in the memory. The one or more of the activity sources, activity targets, and associations are transmitted to prevent future attacks.

Claims (48)

1. A computer implemented method of identifying unauthorized activities on a first computer system attached to a computer network, wherein the first computer system comprises one or more processors and memory, the method comprising:

monitoring activity on the first computer system;

identifying a plurality of activities being performed at the first computer system, wherein each of the activities includes an activity source, an activity target, and an association between the activity source and the activity target;

storing in the memory a data structure that identifies the activity sources, the activity targets, and the associations for the plurality of activities; and

transmitting to one or more computer systems other than the first computer system information identifying one or more of the activity sources, the activity targets, and the associations for preventing future attacks, to the one or more computer systems, associated with the one or more of the activity sources, the activity targets, and the associations.

2. The method of claim 1 , wherein the monitoring further comprises monitoring all activity on the first computer system.

3. The method of claim 1 , further comprising:

creating, from the stored information, a fingerprint indicative of the activity on the first computer system.

4. The method of claim 1 , wherein the activities comprise two or more of: a file initiating an execution of an instruction, an instruction reading a file, an instruction writing to a file, and receiving data through the network.

5. The method of claim 1 , wherein a respective activity target comprises one of: a file, a user, an instruction, a thread, data stream, and network socket connections.

6. The method of claim 1 , wherein a respective activity source comprises one of: a file, a user, an instruction, a thread, data stream, and network socket connections.

7. The method of claim 1 , further comprising:

graphically displaying at least a subset of the stored activities.

8. The method of claim 7 , wherein the displaying includes visually distinguishing at least a subset of the associations.

9. The method of claim 1 , wherein an activity target of a first activity of the plurality of activities is an activity source of a second activity of the plurality of activities.

10. The method of claim 1 , further comprising:

identifying a respective association between a first activity source and a first activity target as unauthorized, wherein the first activity target, when associated as a second activity source with a second activity target, causes unauthorized activities on the second activity target.

11. The method of claim 10 , further comprising:

tracking a transfer of malicious associations over time.

12. The method of claim 1 , further comprising:

identifying activity sources that are affected by unauthorized activities.

13. The method of claim 12 , wherein the identifying activity sources that are affected by unauthorized activities includes identifying activity sources that request to access a portion of memory that is set as non-executable.

14. The method of claim 12 , wherein:

instructions executed by the one or more processors have respective privilege levels;

respective activity sources have respective privilege levels; and

the identifying activity sources that are affected by unauthorized activities includes identifying activity sources that request to execute underprivileged instructions.

15. The method of claim 12 , wherein the identifying activity sources that are affected by unauthorized activities includes identifying data stream incoming from outside the first computer system.

16. The method of claim 1 , further comprising:

determining an activity status for the stored events, the activity status comprising one of:

a complete status, representing that a source of unauthorized activities is identified, and each activity target in the stored activities is associated with the source through one or more associations; and

an incomplete status, which represents that the source of unauthorized activities is not identified, or at least one activity target in the stored activities is not associated with the source through one or more associations.

17. The method of claim 1 , further comprising:

determining an activity level representing a frequency of unauthorized activities on the first computer system during a predefined time interval.

18. The method of claim 1 , further comprising:

identifying a respective activity as unauthorized based on a determination that the respective activity is associated with an unauthorized activity that is distinct from the respective activity.

19. The method of claim 1 , wherein the association includes a type that represents whether or not the activity source has modified the activity target to perform the unauthorized activities.

20. A first computer system, comprising:

one or more processors; and

memory storing one or more programs, the one or more programs including instructions for:

monitoring activity on the first computer system;

identifying a plurality of activities being performed at the first computer system, where each of the activities includes an activity source, an activity target, and an association between the activity source and the activity target;

storing in the memory a data structure that identifies the activity sources, the activity targets, and the associations for the plurality of activities; and

transmitting to one or more computer systems other than the first computer system information identifying one or more of the activity sources, the activity targets, and the associations for preventing future attacks, to the one or more computer systems, associated with the one or more of the activity sources, the activity targets, and the associations.

21. A computer readable storage medium, including one or more programs for execution by one or more processors of a first computer system, the one or more programs including instructions for:

monitoring activity on the first computer system;

identifying a plurality of activities being performed at the first computer system, where each of the activities includes an activity source, an activity target, and an association between the activity source and the activity target;

storing in memory of the first computer system a data structure that identifies the activity sources, the activity targets, and the associations for the plurality of activities; and

transmitting to one or more computer systems other than the first computer system information identifying one or more of the activity sources, activity targets, and associations for preventing future attacks, to the one or more computer systems, associated with the one or more of the activity sources, the activity targets, and the associations.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS DATA PREVIOUSLY RECORDED AT REEL: 70134 FRAME: 0413. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY TEREST . Recorded Feb 14, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070235/0936 →
SECURITY INTEREST Recorded Feb 6, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070134/0413 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2023
From: CAPALIK, ALEN; ANDREWS, DAVID; BECKER, BEN
To: NEURALIQ, INC.
Reel/Frame 065863/0605 →
CHANGE OF NAME Recorded Dec 13, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 065988/0365 →
CHANGE OF NAME Recorded Dec 13, 2023
From: NEURALIQ, INC.
To: COUNTERTACK, INC.
Reel/Frame 065990/0848 →
CHANGE OF NAME Recorded Sep 28, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 065082/0434 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2018
From: PACIFIC WESTERN BANK
To: COUNTERTACK INC.
Reel/Frame 045923/0804 →
SECURITY INTEREST Recorded Nov 21, 2016
From: COUNTERTACK INC.
To: PACIFIC WESTERN BANK
Reel/Frame 040384/0329 →
Continuity (3)
Continuation 13163590 · Jun 17, 2011
Provisional Application 61358367 · Jun 24, 2010
Related Publication 20150381638A1 · Dec 31, 2015