IP Library Granted Patent US 10,043,001
Granted Patent B2
US 10,043,001 · App. 15/359,004 · Granted Aug 7, 2018

Methods and apparatus for control and detection of malicious content using a sandbox environment

Inventors: Anup Ghosh (Centreville, VA); Scott Cosby (Alexandria, VA); Alan Keister (Oakton, VA); Benjamin Bryant (Alexandria, VA); Stephen Taylor (Washington, DC)
Assignee: Invincea, Inc.
G06F21/53G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,043,001
App. No.
15/359,004
Granted
Aug 7, 2018
Kind
B2
Abstract

A non-transitory processor-readable medium storing code representing instructions to cause a processor to perform a process includes code to cause the processor to receive a set of indications of allowed behavior associated with an application. The processor is also caused to initiate an instance of the application within a sandbox environment. The processor is further caused to receive, from a monitor module associated with the sandbox environment, a set of indications of actual behavior of the instance of the application in response to initiating the instance of the application within the sandbox environment. The processor is also caused to send an indication associated with an anomalous behavior if at least one indication from the set of indications of actual behavior does not correspond to an indication from the set of indications of allowed behavior.

Claims (49)

1. An apparatus, comprising:

a memory; and

a processor operatively coupled to the memory, the processor configured to receive a set of indications of allowed behavior specific to a first application, the processor configured to initiate an instance of the first application within a sandbox environment, the instance of the first application configured to initiate an instance of a second application within the sandbox environment,

the processor configured to receive, from a monitor associated with the sandbox environment, an indication that the instance of the second application is attempting to modify a registry key, the processor configured to classify the attempt to modify the registry key as an anomalous behavior for the second application based on an indication of modifying the registry key not being in the set of indications of allowed behavior specific to the first application,

the processor configured to define and store a signature for the second application using a cryptographic hash value of a file associated with the second application in response to classifying the attempt to modify the registry key as an anomalous behavior for the second application, and

the processor configured to terminate the second application in response to classifying the attempt to modify the registry key as an anomalous behavior for the second application.

2. The apparatus of claim 1 , wherein the processor is configured to initiate the instance of the first application within the sandbox environment based on the sandbox environment recognizing the first application.

3. The apparatus of claim 1 , wherein the processor is configured to exclude an instance of a third application from executing within the sandbox environment based on the sandbox environment not recognizing the third application.

4. A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:

receive a set of indications of allowed behavior specific to a first application;

initiate an instance of the first application within a sandbox environment;

receive, from a monitor associated with the sandbox environment, an indication that an instance of a second application initiated by the instance of the first application is attempting to modify a registry key; and

terminate the instance of the second application based on an indication of modifying the registry key not being within the set of indications of allowed behavior specific to the first application.

5. The non-transitory processor-readable medium of claim 4 , wherein the code to cause the processor to initiate includes code to cause the processor to initiate the instance of the first application within the sandbox environment based on the sandbox environment recognizing the first application.

6. The non-transitory processor-readable medium of claim 4 , the code further comprising code to cause the processor to:

exclude an instance of a third application from executing within the sandbox environment based on the sandbox environment not recognizing the third application.

7. The non-transitory processor-readable medium of claim 4 , wherein the set of indications of allowed behavior specific to the first application is defined and associated with the first application prior to initiating the instance of the first application within the sandbox environment.

8. The non-transitory processor-readable medium of claim 4 , the code further comprising code to cause the processor to:

initiate an instance of a third application within the sandbox environment;

receive, from the monitor associated with the sandbox environment, an indication that the instance of the third application is attempting to modify the registry key; and

allow the instance of the third application to modify the registry key based on an indication of modifying the registry key being within a set of indications of allowed behavior specific to the third application.

9. The non-transitory processor-readable medium of claim 4 , further comprising code to cause the processor to:

define a signature for the second application using a cryptographic hash value of a file associated with the second application based on the indication of modifying the registry key not being within the set of indications of allowed behavior specific to the first application; and

store the signature as an attribute of the second application such that additional information regarding the second application can be identified using the signature.

10. The non-transitory processor-readable medium of claim 4 , further comprising code to cause the processor to:

revise the set of indications of allowed behavior specific to the first application based on the indication that the instance of the second application is attempting to modify the registry key.

11. The non-transitory processor-readable medium of claim 4 , wherein the indication that the instance of the second application is attempting to modify the registry key includes a trace associated with a source of an instruction causing the instance of the second application to attempt to modify the registry key.

12. The non-transitory processor-readable medium of claim 4 , wherein the set of indications of allowed behavior specific to the first application is based at least in part on a trust level associated with the first application.

13. A method, comprising:

initiating an instance of a first application within a sandbox environment based on the sandbox environment recognizing the first application;

identifying a set of indications of allowed behavior specific to the first application;

identifying that an instance of a second application initiated by the instance of the first application is attempting to modify a registry key;

classifying the attempt to modify the registry key as an anomalous behavior for the second application based on an indication of modifying the registry key not being in the set of indications of allowed behavior specific to the first application;

defining a signature for the second application using a cryptographic hash value of a file associated with the second application in response to the classifying; and

storing the signature as an attribute of the second application such that additional information regarding the second application can be identified using the signature.

14. The method of claim 13 , further comprising:

terminating the second application based on the indication of modifying the registry key not being in the set of indications of allowed behavior specific to the first application.

15. The method of claim 13 , further comprising:

excluding an instance of a third application from executing within the sandbox environment based on the sandbox environment not recognizing the third application.

16. The method of claim 13 , wherein the set of indications of allowed behavior specific to the first application is defined and associated with the first application prior to initiating the instance of the first application within the sandbox environment.

17. The method of claim 13 , further comprising:

revising the set of indications of allowed behavior associated with the first application in response to the anomalous behavior.

18. The method of claim 13 , further comprising:

initiating an instance of a third application within the sandbox environment;

identifying that the instance of the third application is attempting to modify the registry key; and

allowing the instance of the third application to modify the registry key based on an indication of modifying the registry key being in a set of indications of allowed behavior specific to the third application.

19. The method of claim 13 , further comprising:

storing with the signature a trace associated with a source of an instruction causing the instance of the second application to attempt to modify the registry key.

20. The method of claim 13 , wherein the set of indications of allowed behavior specific to the first application is based at least in part on a trust level associated with the first application.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053124/0380 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: INVINCEA, INC.
Reel/Frame 055555/0308 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: INVINCEA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0314 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: INVINCEA, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053124/0380 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2016
From: GHOSH, ANUP; COSBY, SCOTT; KEISTER, ALAN; BRYANT, BENJAMIN; TAYLOR, STEPHEN
To: INVINCEA, INC.
Reel/Frame 040407/0738 →
Continuity (4)
Continuation 14797847 · Jul 13, 2015
Continuation 13690452 · Nov 30, 2012
Provisional Application 61566162 · Dec 2, 2011
Related Publication 20170200004A1 · Jul 13, 2017
Cited By (5)
US 12,222,869 US 12,242,653 US 12,455,957 US 12,578,984 US 12,602,474