IP Library Granted Patent US 9,674,215
Granted Patent B2
US 9,674,215 · App. 15/204,929 · Granted Jun 6, 2017

Software program identification based on program behavior

Inventors: Paul Michael Martini (San Diego, CA); Peter Anthony Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/1441H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,215
App. No.
15/204,929
Granted
Jun 6, 2017
Kind
B2
Abstract

Operations performed by a software application instance executed by a computing device are monitored. A determination is made that a particular operation performed matches an application signature representing a particular software application. In response, a match score is added to a total score for the software application. In response to determining that the total score is greater than or equal to a threshold, the software is classified.

Claims (62)

1. A method performed by data processing apparatus, the method comprising:

receiving, by a network gateway of a network, a message from a server addressed to a client hosted on the network;

running a first instance of a software application of the message in a sandbox that is separate from the client;

identifying, for the first instance of the software application, application signatures each representing one or more software applications, each application signature including a risk score threshold and one or more operation sequences each including a plurality of sequence operations;

monitoring operations performed by the first instance of the software application to generate a first risk score for the software application based on the operation sequences;

determining that the software application has passed a first risk test in response to determining that the first risk score is less than each risk score threshold;

responsive to determining that the software application has passed the first risk test, routing the message to the client;

running a second instance of the software application by the client;

identifying, for the second instance of the software application, the application signatures;

monitoring operations performed by the second instance of the software application to generate a second risk score for the software application based on the operation sequences;

determining that the software application has failed a second risk test in response to determining that the second risk score is greater than or equal to one of the risk score thresholds; and

in response to determining that the software application has failed the second risk test, performing a configured action.

2. The method of claim 1 , wherein the first instance of the software application behaves differently than the second instance of the software application due to differences between the sandbox and the client.

3. The method of claim 1 , wherein the network gateway and the client are under the same administrative control.

4. The method of claim 1 , wherein:

identifying, for the first instance of the software application, application signatures comprises accessing the application signatures from a particular storage location; and

identifying, for the second instance of the software application, application signatures comprises accessing the application signatures from the particular storage location.

5. The method of claim 1 , wherein the configured action performance is dependent on device performing the configured action.

6. The method of claim 5 , wherein the configured action does not include shutting down the device if the device performing the configured action is the network gateway; and

wherein the configured action does include shutting down the device if the device performing the configured action is not the network gateway.

7. A system comprising:

a network gateway of a network, the network gateway configured to:

receive a message from a server addressed to a client hosted on the network:

run a first instance of a software application of the message in a sandbox that is separate from the client;

identify, for the first instance of the software application, application signatures each representing one or more software applications, each application signature including a risk score threshold and one or more operation sequences each including a plurality of sequence operations;

monitor operations performed by the first instance of the software application to generate a first risk score for the software application based on the operation sequences;

determine that the software application has passed a first risk test in response to determining that the first risk score is less than each risk score threshold;

responsive to determining that the software application has passed the first risk test, route the message to the client; and

the client configured to:

run a second instance of the software application;

identify, for the second instance of the software application, the application signatures;

monitor operations performed by the second instance of the software application to generate a second risk score for the software application based on the operation sequences;

determine that the software application has failed a second risk test in response to determining that the second risk score is greater than or equal to one of the risk score thresholds; and

in response to determining that the software application has failed the second risk test, perform a configured action.

8. The system of claim 7 , wherein the first instance of the software application behaves differently than the second instance of the software application due to differences between the sandbox and the client.

9. The system of claim 7 , wherein the network gateway and the client are under the same administrative control.

10. The system of claim 7 , wherein:

identifying, for the first instance of the software application, application signatures comprises accessing the application signatures from a particular storage location; and

identifying, for the second instance of the software application, application signatures comprises accessing the application signatures from the particular storage location.

11. The system of claim 7 , wherein the configured action performance is dependent on device performing the configured action.

12. The system of claim 11 , wherein the configured action does not include shutting down the device if the device performing the configured action is the network gateway; and

wherein the configured action does include shutting down the device if the device performing the configured action is not the network gateway.

13. A non-transitory computer storage media tangibly encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, by a network gateway of a network, a message from a server addressed to a client hosted on the network;

running a first instance of a software application of the message in a sandbox that is separate from the client;

identifying, for the first instance of the software application, application signatures each representing one or more software applications, each application signature including a risk score threshold and one or more operation sequences each including a plurality of sequence operations;

monitoring operations performed by the first instance of the software application to generate a first risk score for the software application based on the operation sequences;

determining that the software application has passed a first risk test in response to determining that the first risk score is less than each risk score threshold;

responsive to determining that the software application has passed the first risk test, routing the message to the client;

running a second instance of the software application by the client;

identifying, for the second instance of the software application, the application signatures;

monitoring operations performed by the second instance of the software application to generate a second risk score for the software application based on the operation sequences;

determining that the software application has failed a second risk test in response to determining that the second risk score is greater than or equal to one of the risk score thresholds; and

in response to determining that the software application has failed the second risk test, performing a configured action.

14. The computer storage media of claim 13 , wherein the first instance of the software application behaves differently than the second instance of the software application due to differences between the sandbox and the client.

15. The computer storage media of claim 13 , wherein the network gateway and the client are under the same administrative control.

16. The computer storage media of claim 13 , wherein:

identifying, for the first instance of the software application, application signatures comprises accessing the application signatures from a particular storage location; and

identifying, for the second instance of the software application, application signatures comprises accessing the application signatures from the particular storage location.

17. The computer storage media of claim 13 , wherein the configured action performance is dependent on device performing the configured action.

18. The computer storage media of claim 17 , wherein the configured action does not include shutting down the device if the device performing the configured action is the network gateway; and

wherein the configured action does include shutting down the device if the device performing the configured action is not the network gateway.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2016
From: MARTINI, PAUL MICHAEL; MARTINI, PETER ANTHONY
To: IBOSS, INC.
Reel/Frame 040605/0631 →
Continuity (2)
Continuation 14818271 · Aug 4, 2015
Related Publication 20170041338A1 · Feb 9, 2017