IP Library Granted Patent US 10,439,904
Granted Patent B2
US 10,439,904 · App. 15/171,707 · Granted Oct 8, 2019

System and method of determining malicious processes

Inventors: Khawar Deen (Sunnyvale, CA); Navindra Yadav (Cupertino, CA); Anubhav Gupta (Sunnyvale, CA); Shashidhar Gandham (Fremont, CA); Rohit Chandra Prasad (Sunnyvale, CA); Abhishek Ranjan Singh (Pleasanton, CA); Shih-Chun Chang (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,439,904
App. No.
15/171,707
Granted
Oct 8, 2019
Kind
B2
Abstract

Systems, methods, and computer-readable media for managing compromised sensors in multi-tiered virtualized environments. A method includes determining a lineage for a process within the network and then evaluating, through knowledge of the lineage, the source of the command that initiated the process. The method includes capturing data from a plurality of capture agents at different layers of a network, each capture agent of the plurality of capture agents configured to observe network activity at a particular location in the network, developing, based on the data, a lineage for a process associated with the network activity and, based on the lineage, identifying an anomaly within the network.

Claims (27)

1. A method comprising:

capturing data from a first capturing agent at a physical layer within a network, a second capturing agent at a hypervisor layer of the network and a third capturing agent at a virtual layer of the network;

developing, the data, a lineage for a process associated with network activity;

analyzing the lineage, for any anomaly within the network; and

identifying an anomaly in the network in response to the analyzing revealing at least one of the following conditions:

the process was triggered by an external command;

the process was triggered by a hidden command that was not accidental;

the lineage does not follow an expected pattern;

wherein the lineage is a sequence of commands and/or processes that triggered the process associated with network activity.

2. A system comprising:

a processor; and

a non-statutory computer-readable storage medium storing instructions which, when executed by the processor, cause the processor to perform operations comprising:

capturing data from a first capturing agent at a physical layer within a network, a second capturing agent at a hypervisor layer of the network and a third capturing agent at a virtual layer of the network;

developing, based on the data, a lineage for a process associated with network activity; and

analyzing the lineage, for any anomaly within the network; identifying an anomaly in the network in response to the analyzing revealing at least one of the following conditions:

the process was triggered by an external command; the process was triggered by a hidden command that was not accidental;

the lineage does not follow an expected pattern;

wherein the lineage is a sequence of commands and/or processes that triggered the process associated with network activity.

3. A computer-readable storage device storing instructions which, when executed by a processor, cause the processor to perform operations comprising:

capturing data from a first capturing agent at a physical layer within a network, a second capturing agent at a hypervisor layer of the network and a third capturing agent at a virtual layer of the network;

developing, based on the data, a lineage for a process associated with network activity; and

analyzing the lineage, for any anomaly within the network; and

identifying an anomaly in the network in response to the analyzing revealing at least one of the following conditions:

the process was triggered by an external command;

the process was triggered by a hidden command that was not accidental;

the lineage does not follow an expected pattern;

wherein the lineage a sequence of commands and/or processes that triggered the process associated with network activity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2016
From: DEEN, KHAWAR; YADAV, NAVINDRA; GUPTA, ANUBHAV; GANDHAM, SHASHIDHAR; PRASAD, ROHIT CHANDRA; SINGH, ABHISHEK RANJAN; CHANG, SHIH-CHUN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 039930/0165 →
Continuity (2)
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20160357957A1 · Dec 8, 2016