IP Library Granted Patent US 10,417,414
Granted Patent B2
US 10,417,414 · App. 15/386,244 · Granted Sep 17, 2019

Baseline calculation for firewalling

Inventor: Yonatan Striem-Amit (Gedera, IL)
Assignee: CYBEREASON, INC.
G06F21/53G06F21/566H04L63/0263H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,417,414
App. No.
15/386,244
Granted
Sep 17, 2019
Kind
B2
Abstract

A method, computer program product, and apparatus for performing baseline calculations for firewalling in a computer network is disclosed. The method involves defining a reference group for an executed software program, measuring signals in the reference group, measuring signals of the program, computing a distance between the signals of the program and the signals of the reference group, and taking an action if the computed distance deviates from a norm mode. The distance can be computed using a similarity matrix or other method. Measuring the program comprises observing behaviors of the program, collecting and analyzing data, comparing the data to baselines of the reference group, and comparing the behaviors of the program across a previous execution of the program. In cases where a program is known to be malicious, a reference group is not needed and a sandbox can be tailored just by copying the environment of the actual system.

Claims (52)

1. A method for tailoring the operations of a sandbox on a computer or in a network of computers, comprising the steps of:

collecting baseline data including which versions of programs are running on the computer or on different computers in the network of computers;

defining a reference group, the reference group being a collection of software programs identified by the baseline data, wherein the reference group identifies a set of programs that have similar names, locations, dates of installation or dates of running;

collecting a first set of nonsandbox signals from execution of software programs identified within the reference group by executing programs from the collection of software programs that form the reference group, the first set of nonsandbox signals including at least one of: system calls, file operations, network activity, inter-process communication, electronic toll collection, input and output operations, or computation time;

sandboxing the reference group to represent an expected operating environment where programs identified in the reference group will run, the expected operating environment derived from the baseline data;

executing the programs identified in the reference group in the sandbox and collecting a second set of sandbox signals from the sandbox representing execution of said programs identified in the reference group in the expected operating environment;

computing a distance between the second set of sandbox signals from the sandbox and the first set of nonsandbox signals from the reference group; and taking an action if the distance is greater than a predetermined threshold.

2. The method of claim 1 , wherein the collecting steps comprise:

observing behavior of a program, including memory requests, service calls, input-output requests, or network access;

comparing the behavior of the program with those of a previous execution of the program, or with cross executions of other programs in the reference group.

3. The method of claim 1 , wherein the distance is computed using a similarity matrix.

4. The method of claim 1 , wherein the first and second set of signals are collected and analyzed in a distributed peer-to-peer network or on a centralized server.

5. The method of claim 1 , further comprising the steps of:

benchmarking a spread of changes within a network as compared to the spread of contagion within other networks; and

generating a warning if the spread of changes within a network is faster than the spread of contagion within other networks.

6. The method of claim 1 , wherein system knowledge is used to create a dynamic firewall in which rules for allowing or disallowing network activity depends on the activity of other machines in the network.

7. The method of claim 1 , wherein collecting a large amount of data is performed by saving a subset of the data, saving hashes of the data, or creating and saving one or more functions of the data.

8. The method of claim 1 , wherein taking an action is prohibiting an activity.

9. A non-transitory computer program product for tailoring the operations of a sandbox on a computer, comprising: a non-transitory computer readable medium;

a first program instruction for defining a reference group, the reference group being a collection of software programs similar to one another according to a characteristic;

a second program instruction for collecting a first set of nonsandbox signals of the reference group by executing programs from the collection of software programs that form the reference group;

a third program instruction for sandboxing to represent an expected operating environment where the programs of the reference group will run;

a fourth program instruction for executing the programs of the reference group in the sandbox and collecting a second set of sandbox signals from the sandbox representing execution in the expected operating environment;

a fifth program instruction for computing a distance between the second set of sandbox signals from the sandbox and the characteristic signals for the reference group; and

a sixth program instruction for taking an action if the distance is greater than a predetermined threshold;

wherein said first, second, third, fourth, fifth and sixth, program instructions are stored on said non-transitory computer readable medium.

10. The non-transitory computer program product of claim 9 , wherein the collecting program instruction comprises the steps of

observing behavior of a program, including memory requests, service calls, input-output requests, and network access;

comparing the behavior of the program with those of a previous execution of the program, or with cross executions of other programs in the reference group.

11. The non-transitory computer program product of claim 9 , wherein the distance is computed using a similarity matrix.

12. The non-transitory computer program product of claim 9 , wherein the first and second set of signals are collected and analyzed in a distributed peer-to-peer network or on a centralized server.

13. The non-transitory computer program product of claim 9 , wherein the reference group characteristic is one or more of similar names, locations, dates of installation or dates of running.

14. The non-transitory computer program product of claim 9 , further comprising computer instructions for:

benchmarking a spread of changes within a network as compared to the spread of contagion within other networks; and

generating a warning if the spread of changes within a network is faster than the spread of contagion within other networks.

15. The non-transitory computer program product of claim 9 , wherein system knowledge is used to create a dynamic firewall in which rules for allowing or disallowing network activity depends on the activity of other machines in the network.

16. The non-transitory computer program product of claim 9 , wherein collecting a large amount of data is performed by saving a subset of the data, saving hashes of the data, or creating and saving a function of the data.

17. The non-transitory computer program product of claim 9 , wherein taking an action is prohibiting an activity.

18. An apparatus having a processing unit and a storage device, the apparatus comprising:

a defining component for defining a reference group, the reference group being a collection of software programs similar to one another according to a characteristic;

a collecting component for collecting a first set of nonsandbox signals of the reference group by executing programs from the collection of software programs that form the reference group;

a sandboxing component for generating a sandbox to represent an expected operating environment where the programs identified by the reference group will run;

an executing component for executing programs in the sandbox and collecting a second set of sandbox signals from the sandbox representing execution of the target program in the expected operating environment;

a computing component for computing a distance between the second set of sandbox signals from the sandbox and the first set of nonsandbox signals from the reference group; and

an action component for taking an action if the distance is greater than a predetermined threshold.

19. The apparatus of claim 18 , wherein the number and type of files in the sandbox are similar to the number and type of files in the real environment.

20. The apparatus of claim 18 , wherein the types and versions of programs in the sandbox are similar to the types and versions of programs in the real environment.

21. The apparatus of claim 18 , further comprising tailoring operations of the sandbox by:

copying a real system environment in which a target program runs into the sandbox:

measuring signals from the target program in the sandbox and

adjusting the sandbox based on said measuring, wherein the tailored sandbox results in longer running of programs in the sandbox as well as fewer false positives.

22. The apparatus of claim 18 , wherein the sandbox is an actual copy of a production machine.

Assignments (13)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 054517/0199) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0912 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 065316/0551 ) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0852 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
SUPPLEMENT NO. 2 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 23, 2023
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065316/0551 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
RELEASE OF SECURITY INTEREST Recorded Dec 28, 2020
From: SOFTBANK GROUP CORP.
To: CYBEREASON INC.
Reel/Frame 054756/0846 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 25, 2020
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054517/0199 →
SHORT-FORM PATENT SECURITY AGREEMENT Recorded Feb 11, 2019
From: CYBEREASON INC.
To: SOFTBANK GROUP CORP.
Reel/Frame 048303/0501 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2016
From: STRIEM-AMIT, YONATAN
To: CYBEREASON INC.
Reel/Frame 041114/0791 →
Continuity (2)
Provisional Application 62273729 · Dec 31, 2015
Related Publication 20170193222A1 · Jul 6, 2017