IP Library Granted Patent US 9,961,091
Granted Patent B2
US 9,961,091 · App. 15/227,520 · Granted May 1, 2018

Apparatus and method for characterizing the risk of a user contracting malicious software

Inventors: Joseph H. Levy (Eagle Mountain, UT); Matthew S. Wood (Salt Lake City, UT)
Assignee: SYMANTEC CORPORATION
H04L63/1408H04L63/0281H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,961,091
App. No.
15/227,520
Granted
May 1, 2018
Kind
B2
Abstract

A non-transitory computer readable storage medium includes executable instructions to identify specified network interactions initiated by a client machine. The specified network interactions are compared to normative values to produce a promiscuity score indicative of the risk of the client machine contracting malicious software. Depending upon the promiscuity score, prophylactic actions are optionally applied to the client machine.

Claims (43)

1. A server comprising:

a hardware processor; and

a memory storing instructions that are configured, when executed by the hardware processor, to cause the hardware processor to:

identify specified network interactions including a client machine initiating connections to network endpoints; and

evaluate a statistical deviation of the specified network interactions relative to a normative value for the client machine to produce a promiscuity score indicative of a risk of the client machine contracting malicious software, wherein the specified network interactions include:

a count of the network endpoints accessed during a specified time period;

countries associated with the network endpoints and risks associated with the countries;

Uniform Resource Locators (URLs) of the network endpoints and a length and character distribution structure of each URL;

combinations, sequences, or distributions of characters of a domain name in a domain name system query and the number of IP addresses the domain name system query resolves to;

executable file transfers between the client machine and the network endpoints and file characteristics associated with the executable files transferred; and

encrypted SSL and TLS session characteristics including one or more of a common name of an SSL/TLS certificate, a certificate authority, and a public key length.

2. The server of claim 1 , wherein the instructions stored in the memory are further configured, when executed by the hardware processor, to cause the hardware processor to apply a prophylactic action to the client machine based on the promiscuity score.

3. The server of claim 2 , wherein the prophylactic action is installing anti-virus software on the client machine.

4. The server of claim 2 , wherein the prophylactic action is isolating the client machine with a firewall.

5. The server of claim 2 , wherein the prophylactic action is automatically remediating an infection.

6. The server of claim 2 , wherein the prophylactic action is delivering an alert to an administrator.

7. The server of claim 1 , wherein the client machine is selected from the group consisting of a personal computer, a tablet, a smart phone, and a personal digital assistant.

8. The server of claim 1 , wherein the normative value for the client machine is a mean host communication count.

9. The server of claim 8 , wherein the mean host communication count is a total number of connections made by the client machine with a specific network endpoint.

10. The server of claim 8 , wherein the mean host communication count is a combination of a total number of unique network endpoints the client machine communicates with and a total number of connections made by the client machine with a specific network endpoint.

11. A method comprising:

identifying, by a computer, specified network interactions including a client machine initiating connections to network endpoints; and

evaluating, by the computer, a statistical deviation of the specified network interactions relative to a normative value for the client machine to produce a promiscuity score indicative of a risk of the client machine contracting malicious software, wherein the specified network interactions include:

a count of the network endpoints accessed during a specified time period;

countries associated with the network endpoints and risks associated with the countries;

Uniform Resource Locators (URLs) of the network endpoints and a length and character distribution structure of each URL;

combinations, sequences, or distributions of characters of a domain name in a domain name system query and the number of IP addresses the domain name system query resolves to;

executable file transfers between the client machine and the network endpoints and file characteristics associated with the executable files transferred; and

encrypted SSL and TLS session characteristics including one or more of a common name of an SSL/TLS certificate, a certificate authority, and a public key length.

12. The method of claim 11 , further comprising applying a prophylactic action to the client machine based on the promiscuity score.

13. The method of claim 11 , wherein the normative value for the client machine is a mean host communication count.

14. The method of claim 13 , wherein the mean host communication count is a combination of a total number of unique network endpoints the client machine communicates with and a total number of connections made by the client machine with a specific network endpoint.

15. A non-transitory computer readable storage medium, comprising executable instructions operable, when executed on a hardware processor, to:

identify specified network interactions including a client machine initiating connections to network endpoints; and

evaluate a statistical deviation of the specified network interactions relative to a normative value for the client machine to produce a promiscuity score indicative of a risk of the client machine contracting malicious software, wherein the specified network interactions include:

a count of the network endpoints accessed during a specified time period;

countries associated with the network endpoints and risks associated with the countries;

Uniform Resource Locators (URLs) of the network endpoints and a length and character distribution structure of each URL;

combinations, sequences, or distributions of characters of a domain name in a domain name system query and the number of IP addresses the domain name system query resolves to;

executable file transfers between the client machine and the network endpoints and file characteristics associated with the executable files transferred; and

encrypted SSL and TLS session characteristics including one or more of a common name of an SSL/TLS certificate, a certificate authority, and a public key length.

16. The non-transitory computer readable storage medium of claim 15 , wherein the executable instructions are further operable, when executed on the hardware processor, to apply a prophylactic action to the client machine based on the promiscuity score.

17. The non-transitory computer readable storage medium of claim 15 , wherein the normative value for the client machine is a mean host communication count.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2017
From: LEVY, JOSEPH H.; WOOD, MATTHEW S.
To: SOLERA NETWORKS, INC.
Reel/Frame 041159/0179 →
MERGER Recorded Feb 2, 2017
From: SOLERA NETWORKS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 041159/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2017
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 041596/0853 →
Continuity (2)
Continuation 13754810 · Jan 30, 2013
Related Publication 20160344750A1 · Nov 24, 2016