IP Library Granted Patent US 10,257,212
Granted Patent B2
US 10,257,212 · App. 15/384,025 · Granted Apr 9, 2019

Method and system for detecting malware

Inventors: Emmanouil Antonakakis (Dunwoody, GA); Robert Perdisci (Smyrna, GA); Wenke Lee (Atlanta, GA); Gunter Ollmann (Norcross, GA)
Assignee: Help/Systems, LLC
H04L63/1416G06F9/45508G06F21/577G06N99/005H04L29/12066H04L61/1511H04L63/145H04L63/1408H04L63/1491H04L29/06H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,257,212
App. No.
15/384,025
Granted
Apr 9, 2019
Kind
B2
Abstract

A system and method of analysis. NX domain names are collected from an asset in a real network. The NX domain names are domain names that are not registered. The real network NX domain names are utilized to create testing vectors. The testing vectors are classified as benign vectors or malicious vectors based on training vectors. The asset is then classified as infected if the NX testing vector created from the real network NX domain names is classified as a malicious vector.

Claims (42)

1. A method of analysis, comprising:

collecting, using at least one decoy virtual machine, honeypot NX domain names from at least one known infected asset in at least one real network, the honeypot NX domain names being domain names that are not registered;

collecting, using the at least one decoy virtual machine, real network NX domain names from at least one asset in the at least one real network;

grouping the honeypot NX domain names and the real network NX domain names based on statistical similarities;

creating at least one training vector, wherein the at least one training vector is created by:

computing various statistical values for at least one group of the honeypot NX domain names, and

collecting the various statistical values for the at least one group of the honeypot NX domain names in at least one vector;

creating, using the real network NX domain names, a plurality of testing vectors, wherein the plurality of testing vectors are created by:

computing various statistical values for at least one group of the real network NX domain names, and

collecting the various statistical values for the at least one group of the real network NX domain names in the plurality of testing vectors;

classifying each of the testing vectors as benign vectors or malicious vectors based on the at least one training vector; and

classifying the at least one asset in the at least one real network as infected if at least one of the plurality of testing vectors is classified as a malicious vector.

2. The method of claim 1 , further comprising classifying previously unclassified malware from the honeypot NX domain names.

3. The method of claim 1 , wherein only domain name system (DNS) NX domain name information is utilized to classify the at least one asset as infected.

4. The method of claim 1 , wherein only NX domain traffic is utilized.

5. The method of claim 1 , wherein a meta-classifier is utilized to classify the testing vectors as benign vectors or malicious vectors.

6. The method of claim 5 , wherein the meta-classifier provides intelligence for identifying new malware.

7. The method of claim 1 , wherein the classifying of the testing vectors is done using at least one meta-classifier, the at least one meta-classifier comprising at least one generic classifier.

8. The method of claim 1 , further comprising classifying previously classified malware from the honeypot NX domain names.

9. The method of claim 1 , wherein the honeypot NX domain names collected from the at least one known infected asset and the real network NX domain names collected from the at least one asset are grouped into sets of 10 using absolute timing sequence information.

10. A system of analysis, comprising:

at least one computer connected to at least one network;

at least one application executing in the at least one computer, the at least one application configured for:

collecting, using at least one decoy virtual machine, honeypot NX domain names from at least one known infected asset in at least one real network, the honeypot NX domain names being domain names that are not registered;

collecting, using the at least one decoy virtual machine, real network NX domain names from at least one asset in the at least one real network;

grouping the honeypot NX domain names and the real network NX domain names based on statistical similarities;

creating at least one training vector, wherein the at least one training vector is created by:

computing various statistical values for at least one group of the honeypot NX domain names, and

collecting the various statistical values for the at least one group of the honeypot NX domain names in at least one vector;

creating, using the real network NX domain names, a plurality of testing vectors, wherein the plurality of testing vectors are created by:

computing various statistical values for at least one group of the real network NX domain names, and

collecting the various statistical values for the at least one group of the real network NX domain names in the plurality of testing vectors;

classifying each of the testing vectors as benign vectors or malicious vectors based on the at least one training vector; and

classifying the at least one asset in the at least one real network as infected if at least one of the plurality of testing vectors is classified as a malicious vector.

11. The system of claim 10 , wherein the at least one application is further configured for classifying previously unclassified malware from the honeypot NX domain names.

12. The system of claim 10 , wherein only domain name system (DNS) NX domain name information is utilized to classify the at least one asset as infected.

13. The system of claim 10 , wherein only NX domain traffic is utilized.

14. The system of claim 10 , wherein a meta-classifier is utilized to classify the testing vectors as benign vectors or malicious vectors.

15. The system of claim 14 , wherein the meta-classifier provides intelligence for identifying new malware.

16. The system of claim 10 , wherein the classifying of the testing vectors is done using at least one meta-classifier, the at least one meta-classifier comprising at least one generic classifier.

17. The system of claim 10 , wherein the at least one application is further configured for classifying previously classified malware from the honeypot NX domain names.

18. The system of claim 10 , wherein the honeypot NX domain names collected from the at least one known infected asset and the real network NX domain names collected from the at least one asset are grouped into sets of 10 using absolute timing sequence information.

Assignments (13)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2019
From: ANTONAKAKIS, EMMANOUIL; PERDISCI, ROBERTO; LEE, WENKE; OLLMANN, GUNTER
To: DAMBALLA, INC.
Reel/Frame 048373/0557 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048372/0348 →
Continuity (5)
Continuation 14041796 · Sep 30, 2013
Continuation 12985140 · Jan 5, 2011
Provisional Application 61295060 · Jan 14, 2010
Provisional Application 61292592 · Jan 6, 2010
Related Publication 20170201536A1 · Jul 13, 2017