IP Library Granted Patent US 9,912,681
Granted Patent B1
US 9,912,681 · App. 14/929,693 · Granted Mar 6, 2018

Injection of content processing delay in an endpoint

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,681
App. No.
14/929,693
Granted
Mar 6, 2018
Kind
B1
Abstract

A malware detection system (MDS) appliance is configured to inject delay associated with delivery and/or processing of communication traffic directed to one or more endpoints in a network. The appliance may be positioned within the network to intercept and analyze (e.g., replay and instrument) one or more network packets of the communication traffic to detect whether an object of the packet contains malware. However, such analysis, e.g., malware detection analysis, may require extensive processing at the appliance and, thus, consume a considerable amount of time. Accordingly, the MDS appliance may inject delay into the delivery and/or processing of the object on the endpoint until the malware detection analysis completes and the malware is validated.

Claims (53)

1. A method comprising:

receiving an object at an appliance coupled to a network, the object directed to an endpoint on the network;

determining whether a malware detection analysis of the object requires extensive processing at the appliance;

in response to determining that the malware detection analysis requires extensive processing:

initiating delay of execution of the object at the endpoint; and

performing the malware detection analysis at the appliance, the malware detection analysis spawning a virtual machine to encapsulate a process including the object, the virtual machine instrumented to monitor operation of the process as the process attempts to access first and second kernel resources to detect whether the process includes malware.

2. The method of claim 1 wherein receiving the object comprises intercepting communication traffic at the appliance, the communication traffic including one or more packets containing the object.

3. The method of claim 2 wherein initiating delay of execution of the object comprises initiating injection of delay associated with one of delivery and processing of the object at the endpoint.

4. The method of claim 3 wherein initiating injection of delay associated with the one of delivery and processing of the object comprises injecting delay through manipulation of a transport protocol for transmitting the packet between a source of the object and the endpoint.

5. The method of claim 3 wherein initiating injection of delay associated with the one of delivery and processing of the object comprises injecting delay through delayed execution of the object when the process is context switched at a virtualization module of the endpoint.

6. The method of claim 2 further comprising:

validating the monitored operation of the process including the object as malicious activity; and

notifying the endpoint that the object is malicious.

7. The method of claim 6 further comprising, in response to validating the monitored operation of the process including the object as malicious activity, instructing the endpoint to terminate processing of the object.

8. The method of claim 6 further comprising, in response to validating the monitored operation of the process including the object as malicious activity, delaying execution of the object until the endpoint terminates processing of the object.

9. The method of claim 1 further comprising:

in response to determining that the malware detection analysis does not require extensive processing, instructing the endpoint to perform the malware detection analysis at the endpoint, wherein the malware detection analysis spawns a container to encapsulate the process including the object, and wherein the container is instrumented to monitor operation of the process as the process attempts to access the first and second kernel resources to detect whether the process includes the malware.

10. The method of claim 1 wherein initiating delay of execution of the object at the endpoint includes initiating execution of dummy code.

11. The method of claim 1 wherein delay of execution of the object at the endpoint is less than approximately 10 seconds.

12. A system comprising:

a network interface connected to a network;

a memory coupled to the network interface and configured to store an object, an operating system and a virtual machine; and

a central processing unit (CPU) coupled to the memory and adapted to execute the operating system and virtual machine, wherein the operating system is configured to:

intercept the object directed to an endpoint on the network;

determine whether a malware detection analysis of the object requires extensive processing;

in response to determining that the malware detection analysis requires extensive processing:

initiate injection of delay associated with one of delivery and processing of the object at the endpoint; and

perform the malware detection analysis to spawn the virtual machine to encapsulate a process including the object, the virtual machine instrumented to monitor operation of the process as the process attempts to access first and second kernel resources to detect whether the process includes malware.

13. The system of claim 12 wherein the object is contained in a packet of communication traffic directed to the endpoint.

14. The system of claim 13 wherein the operating system is configured to initiate injection of delay by instructing the endpoint to manipulate a transport protocol for transmitting the packet between a source of the object and the endpoint.

15. The system of claim 13 wherein the operating system is configured to initiate injection of delay through initiation of delayed execution of the object when the process is context switched at a virtualization module of the endpoint.

16. The system of claim 13 wherein the operating system is further configured to:

validate the monitored operation of the process including the object as malicious activity; and

notify the endpoint that the object is malicious.

17. The system of claim 16 wherein the operating system is further configured to instruct the endpoint to terminate processing of the object.

18. The system of claim 16 wherein the operating system is further configured to instruct the endpoint to initiate delay of execution of the object until the endpoint terminates processing of the object.

19. The system of claim 12 wherein the operating system is further configured to, in response to determining that the malware detection analysis does not require extensive processing, instruct the endpoint to perform the malware detection analysis at the endpoint, wherein the malware detection analysis spawns a container to encapsulate the process including the object, and wherein the container is instrumented to monitor operation of the process as the process attempts to access the first and second kernel resources to detect whether the process includes the malware.

20. A method comprising:

receiving a first instruction to delay execution of a process at an endpoint, the first instruction received from an appliance in response to detection of an indication of malware present in the process when instrumented at the appliance;

injecting delay into the process by executing dummy code at the endpoint; and

delaying execution of the process through execution of the dummy code for a duration specified by the appliance.

21. The method of claim 20 wherein delaying execution of the process comprises delaying execution of the process for a period of time that consumes a scheduled time of execution for the process.

22. The method of claim 21 wherein delaying execution of the process further comprises yielding the scheduled time of execution for the process by initiating a software call to an operating system of the endpoint to re-assign the scheduled time to another process to execute.

23. A non-transitory computer readable medium including program instructions for execution on one or more processors, the program instructions when executed operable to:

receive an object at an appliance coupled to a network, the object directed to an endpoint on the network;

determine whether a malware detection analysis of the object requires extensive processing at the appliance;

in response to determining that the malware detection analysis requires extensive processing:

initiate delay of execution of the object at the endpoint by executing dummy code; and

perform the malware detection analysis at the appliance, the malware detection analysis spawning a virtual machine as a container to encapsulate a process including the object, the virtual machine instrumented to monitor operation of the process as the process attempts to access first and second kernel resources to detect whether the process includes malware.

24. The method of claim 20 further comprising:

receiving a second instruction, the second instruction received from the appliance in response to terminating instrumentation of the process at the appliance; and

resuming execution of the process at the endpoint.

25. The computer readable medium of claim 23 , wherein memory pages including the object are mapped into an address space of the process.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Sep 15, 2022
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 061434/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 061449/0366 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2015
From: ISMAEL, OSMAN ABDOUL; AZIZ, ASHAR
To: FIREEYE, INC.
Reel/Frame 036936/0214 →