IP Library Granted Patent US 9,934,381
Granted Patent B1
US 9,934,381 · App. 15/425,954 · Granted Apr 3, 2018

System and method for detecting malicious activity based on at least one environmental property

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,934,381
App. No.
15/425,954
Granted
Apr 3, 2018
Kind
B1
Abstract

Techniques for detecting exfiltration content are described herein. According to one embodiment, a malicious content suspect is executed and a packet inspection of outbound network traffic is performed by a packet inspector running within the virtual machine. Occurring before the outbound network traffic leaving the virtual machine, the packet inspector determines whether a portion of outbound network traffic matches one or more portions of predetermined network traffic patterns or signatures. If so, a determination is made whether the outbound network traffic includes at least one environmental property of the virtual machine that is unique or almost unique to the virtual machine. If so, migration of the outbound network traffic outside of the virtual machine is precluded and an alert is transmitted. The alert includes the malicious content suspect that is attempting to perform an exfiltration of data.

Claims (39)

1. A computer-implemented method for detecting exfiltration of data, comprising:

executing a malicious content suspect within a virtual machine;

performing a packet inspection on outbound network traffic by a packet inspector running within the virtual machine prior to the outbound network traffic leaving the virtual machine, the packet inspection to determine whether a portion of outbound network traffic matches one or more portions of predetermined network traffic patterns or signatures;

determining whether the outbound network traffic includes at least one environmental property of the virtual machine that is unique to or distinctive of the virtual machine after determining the portion of the outbound network traffic matches the one or more portions of predetermined network traffic patterns or signatures, the at least one environmental property is unique to or distinctive of the virtual machine in that the at least one environmental property pertains to the virtual machine so as to allow the match to indicate that the malicious content suspect is attempting to perform an exfiltration of data;

precluding migration of the outbound network traffic outside of the virtual machine upon determining that the outbound network traffic includes the at least one environmental property of the virtual machine that is unique to or distinctive of the virtual machine; and

transmitting an alert indicating that the malicious content suspect is attempting to perform the exfiltration of data upon determining that the outbound network traffic includes the at least one environmental property of the virtual machine.

2. The method of claim 1 , wherein the determining whether the outbound network traffic includes the at least one environmental property of the virtual machine comprises matching the at least one environmental property to any of a set of patterns associated with the virtual machine selected to process the malicious content suspect.

3. The method of claim 1 , wherein the at least one environmental property of the virtual machine comprises an identifier of an electronic device represented by the virtual machine.

4. The method of claim 1 , wherein the at least one environmental property of the virtual machine comprises information that distinguishes hardware included in an electronic device represented by the virtual machine from other hardware.

5. The method of claim 1 , wherein the alert being transmitted over a network.

6. The method of claim 1 , wherein the malicious content suspect is extracted from the outbound network traffic by a packet capturer of a guest operating system that hosts the virtual machine.

7. The method of claim 6 , wherein the packet capturer being implemented as part of a firewall of the guest operating system.

8. The method of claim 1 , wherein a destination of the outbound network traffic is represented by a virtual network interface presented by the virtual machine, without allowing the outbound network traffic to reach an actual destination outside of a data processing system that hosts the virtual machine.

9. The method of claim 1 , wherein the at least one environmental property includes at least one of (i) a computer name or NetBIOS name, (ii) a serial number of a hardware component, (iii) an identifier of a software application, or (iv) information identifying a user of an electronic device represented by the virtual machine.

10. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for detecting exfiltration, comprising:

executing a malicious content suspect within a virtual machine;

prior to outbound network traffic initiated by the malicious content suspect leaving the virtual machine, performing a packet inspection within the virtual machine on the outbound network traffic by analyzing a portion of the outbound network traffic in comparison to one or more portions of predetermined network traffic patterns or signatures;

determining whether the outbound network traffic includes at least one environmental property of the virtual machine that is unique to or distinctive of the virtual machine after determining the portion of the outbound network traffic matches the one or more portions of predetermined network traffic patterns or signatures, the at least one environmental property is unique to or distinctive of the virtual machine in that the at least one environmental property pertains to the virtual machine so as to allow the match to indicate that the malicious content suspect is attempting to perform an exfiltration of data; and

responsive to determining the outbound network traffic includes the at least one environmental property of the virtual machine that is unique to or distinctive of the virtual machine, precluding migration of the outbound network traffic outside of the virtual machine, and transmitting an alert over a network, the alert indicating that the malicious content suspect is attempting to perform the exfiltration of data.

11. The non-transitory machine-readable medium of claim 10 , wherein the determining whether the outbound network traffic includes the at least one environmental property of the virtual machine comprises matching the at least one environmental property to any of a set of patterns associated with the virtual machine selected to process the malicious content suspect.

12. The non-transitory machine-readable medium of claim 10 , wherein the at least one environmental property of the virtual machine comprises an identifier of an electronic device represented by the virtual machine.

13. The non-transitory machine-readable medium of claim 10 , wherein the performing of the packet inspection comprises performing a search of data that is part of the outbound network traffic based on a predetermined signature that was generated by encoding, using a predetermined encoding algorithm, a text string representing a unique identifier of an electronic device represented by the virtual machine.

14. The non-transitory machine-readable medium of claim 10 , wherein the at least one environmental property of the virtual machine is unique when an encoded or compressed form of data of the at least one environmental property fails to match generic network traffic.

15. The non-transitory machine-readable medium of claim 10 being implemented as part of a firewall.

16. A data processing system, comprising:

a processor; and

a memory coupled to the processor for storing instructions, which when executed from the memory, cause the processor to

execute a malicious content suspect within a virtual machine,

prior to outbound network traffic initiated by the malicious content suspect leaving the virtual machine, perform a packet inspection, by a packet inspector executed by the processor and running within the virtual machine, on the outbound network traffic, the packet inspection to determine whether a portion of the outbound network traffic matches one or more portions of predetermined network traffic patterns or signatures,

determine whether the outbound network traffic includes at least one environmental property of the virtual machine that is unique to or distinctive of the virtual machine after determining that the portion of the outbound network traffic matches the one or more portions of predetermined network traffic patterns or signatures, and

preclude migration of the outbound network traffic outside of the virtual machine and transmitting an alert indicating that the malicious content suspect is attempting to perform an exfiltration of data upon determining that the outbound network traffic includes the at least one environmental property of the virtual machine that is unique to or distinctive of the virtual machine.

17. The system of claim 16 , wherein the determining whether the outbound network traffic includes the at least one environmental property of the virtual machine comprises matching the at least one environmental property to any of a set of patterns associated with the virtual machine selected to process the malicious content suspect.

18. The system of claim 16 , wherein the alert being transmitted to a controller, the controller is implemented as part of a virtual machine monitor (VMM).

19. The system of claim 18 , wherein the controller includes a scheduler that selects a configuration of the virtual machine, the configuration includes a selection of at least a particular version of an operating system includes a selection of a particular version of a particular operating system and one or more of version of application software to operate with the particular version of the operating system.

20. The system of claim 16 , wherein the at least one environmental property of the virtual machine comprises an identifier of an electronic device represented by the virtual machine.

21. The system of claim 16 , wherein the performing of the packet inspection comprises performing a search of data that is part of the outbound network traffic based on a predetermined signature that was generated by encoding, using a predetermined encoding algorithm, a text string representing a unique identifier of an electronic device represented by the virtual machine comprising the at least one environmental property.

22. The system of claim 16 , wherein the at least one environmental property of the virtual machine is unique or distinctive when an encoded or compressed form of data of the at least one environmental property fails to match generic network traffic.

23. The system of claim 16 , wherein the at least one environmental property is unique to or distinctive of the virtual machine in that the at least one environmental property pertains to the virtual machine so as to allow the match to indicate that the malicious content suspect is attempting to perform an exfiltration of data.

24. The system of claim 23 , wherein the at least one environmental property includes at least one of (i) a computer name or NetBIOS name, (ii) a serial number of a hardware component, (iii) an identifier of a software application, or (iv) information identifying a user of an electronic device represented by the virtual machine.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0771 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: FIREEYE, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0776 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2017
From: BENNETT, JAMES
To: FIREEYE, INC.
Reel/Frame 043800/0811 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2017
From: KINDLUND, DARIEN; WOLF, JULIA
To: FIREEYE, INC.
Reel/Frame 042727/0400 →