IP Library Granted Patent US 10,110,618
Granted Patent B1
US 10,110,618 · App. 15/009,411 · Granted Oct 23, 2018

System and methods to detect mobile credential leaks during dynamic analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,110,618
App. No.
15/009,411
Granted
Oct 23, 2018
Kind
B1
Abstract

The present disclosure relates to systems and methods for detecting malware. In some embodiments, a method may include detecting, via a processor, a user login event at an application; dynamically comparing, via the processor, the user login event with one or more expected behaviors associated with the application; and determining, via the processor, whether the application is potential malware based at least in part on a result of the comparing.

Claims (64)

1. A method for detecting malware, comprising:

detecting, via a processor, a user login event at an application;

monitoring, via the processor, response activity of the application based at least in part on the user login event, the monitoring comprising at least an evaluation of traffic associated with the application;

determining whether the application is a known application or an unknown application, wherein the known application includes a list of expected behaviors stored in a database repository, and the unknown application has no expected behaviors stored in the database repository;

upon determining the application is the known application:

retrieving, via a communication link, one or more expected behaviors of the application from the database repository; and

upon determining the application is the unknown application:

running a legitimate use of one or more libraries associated with the application; and

identifying, via the processor, one or more observed behaviors of the application based at least in part on the running;

dynamically comparing, via the processor, the user login event with the one or more expected behaviors associated with the application when the application is determined to be the known application, or dynamically comparing the user login event with the one or more observed behaviors when the application is determined to be the unknown application; and

determining, via the processor, whether the application is potential malware based at least in part on a result of the comparing.

2. The method of claim 1 , wherein the dynamically comparing comprises:

comparing any one or more of server traffic, or application text, or application icons, or server Uniform Resource Locators (URLs), or required libraries associated with the user login event with a database of known one or more expected behaviors associated with the application.

3. The method of claim 2 , wherein the dynamically comparing further comprises:

decrypting the server traffic.

4. The method of claim 1 , wherein detecting the user login event comprises:

detecting one or more expected behaviors associated with a login event.

5. The method of claim 4 , wherein the one or more expected behaviors associated with the login event comprise any one or more of server traffic, or application text, or application icons, or server URLs, or required libraries.

6. The method of claim 1 , wherein the dynamically comparing comprises:

dynamically analyzing one or more behaviors associated with the legitimate use of the one or more libraries associated with the application; and

comparing any one or more of server traffic, or application text, or application icons, or server URLs, or required libraries associated with the user login event with the analyzed one or more behaviors associated with the legitimate use of the one or more libraries associated with the application.

7. The method of claim 1 , further comprising:

upon determining the application is potential malware, reporting the potential malware to the user.

8. The method of claim 7 , wherein reporting the potential malware to the user comprises:

detecting that the user login event has resulted in communication of one or more user login details to the malware application; and

reporting that communication to the user.

9. An apparatus for detecting malware comprising:

a processor;

a memory in electronic communication with the processor, wherein the memory stores computer readable executable instructions that when executed by the processor cause the processor to:

detect, via a processor, a user login event at an application;

monitor, via the processor, response activity of the application based at least in part on the user login event, the monitoring comprising at least an evaluation of traffic associated with the application;

determine whether the application is a known application or an unknown application, wherein the known application includes a list of expected behaviors stored in a database repository, and the unknown application has no expected behaviors stored in the database repository;

upon determining the application is the known application:

retrieve, via a communication link, one or more expected behaviors of the application from the database repository; and

upon determining the application is the unknown application:

run a legitimate use of one or more libraries associated with the application; and

identify, via the processor, one or more observed behaviors of the application based at least in part on the running;

dynamically compare, via the processor, the user login event with the one or more expected behaviors associated with the application when the application is determined to be the known application, or dynamically comparing the user login event with the one or more observed behaviors when the application is determined to be the unknown application; and

determine, via the processor, whether the application is potential malware based at least in part on a result of the comparing.

10. The apparatus of claim 9 , wherein the instructions to dynamically compare are further executable by the processor to:

compare any one or more of server traffic, or application text, or application icons, or server Uniform Resource Locators (URLs), or required libraries associated with the user login event with a database of known one or more expected behaviors associated with the application.

11. The apparatus of claim 10 , wherein the instructions to dynamically compare are further executable by the processor to:

decrypt the server traffic.

12. The apparatus of claim 9 , wherein the instructions to detect the user login event are further executable by the processor to:

detect one or more expected behaviors associated with a login event.

13. The apparatus of claim 9 , wherein the instructions to dynamically compare are further executable by the processor to:

dynamically analyze one or more behaviors associated with the legitimate use of the one or more libraries associated with the application; and

compare any one or more of server traffic, or application text, or application icons, or server URLs, or required libraries associated with the user login event with the analyzed one or more behaviors associated with the legitimate use of the one or more libraries associated with the application.

14. The apparatus of claim 9 , wherein upon determining the application is potential malware, the instructions are further executable by processor to:

report the potential malware to the user.

15. The apparatus of claim 14 , wherein the instructions to report the potential malware to the user are further executable by the processor to:

detect that the user login event has resulted in communication of one or more user login details to the malware application; and

report that communication to the user.

16. The apparatus of claim 9 , further comprising a non-transitory computer-readable storage medium storing instructions executable by the processor to:

detect, via a processor, a user login event at an application;

monitor, via the processor, response activity of the application based at least in part on the user login event, the monitoring comprising at least an evaluation of traffic associated with the application;

determine whether the application is a known application or an unknown application, wherein the known application includes a list of expected behaviors stored in a database repository, and the unknown application has no expected behaviors stored in the database repository;

upon determining the application is the known application:

retrieve, via a communication link, one or more expected behaviors of the application from the database repository; and

upon determining the application is the unknown application:

run a legitimate use of one or more libraries associated with the application; and

identify, via the processor, one or more observed behaviors of the application based at least in part on the running;

dynamically compare, via the processor, the user login event with the one or more expected behaviors associated with the application when the application is determined to be the known application, or dynamically comparing the user login event with the one or more observed behaviors when the application is determined to be the unknown application; and

determine, via the processor, whether the application is potential malware based at least in part on a result of the comparing.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jan 30, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051759/0845 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2016
From: MAO, JUN; LI, JINGHAO
To: SYMANTEC CORPORATION
Reel/Frame 037613/0339 →