IP Library › Granted Patent US 10,440,051
Granted Patent B2
US 10,440,051 · App. 15/448,888 · Granted Oct 8, 2019

Enhanced detection of polymorphic malicious content within an entity

Inventors: Eric Eugene Sifford (Charlotte, NC); William August Stahlhut (The Colony, TX)
Assignee: Bank of America Corporation
H04L63/145G06F16/22H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,440,051
App. No.
15/448,888
Granted
Oct 8, 2019
Kind
B2
Abstract

Embodiments of the invention are directed to systems, methods and computer program products for enhanced detection of polymorphic malicious content within an entity. In this regard, the present invention receives information associated with an incidence of an electronic file; receives an first hash value of the electronic file from a first network device and a second hash value of the electronic file from a second network device; compares the first hash value with the second hash value; determines that the electronic file is polymorphic based on at least the match; initiates an execution of a quantum optimization algorithm using a quantum optimizer to determine one or more hash value states associated with the electronic file for a third network device; and initiates a control signal configured to store the one or more hash value states in a database associated with the third network device.

Claims (76)

1. A system for enhanced detection of polymorphic malicious content within an entity, the system comprising:

at least one non-transitory storage device;

at least one processor; and

at least one module stored in said storage device and comprising instruction code that is executable by the at least one processor and configured to cause said at least one processor to:

receive information associated with an incidence of an electronic file in a distributed network comprising one or more network devices;

receive a first hash value of the electronic file from a first network device and a second hash value of the electronic file from a second network device, wherein the first network device and the second network device is associated with the one or more network devices;

compare the first hash value with the second hash value to determine a match between the two hash values for the electronic file received from the first and second network devices;

determine that the electronic file is polymorphic based on at least determining that the first hash value at the first network device does not match the second hash value at the second network device;

initiate an execution of a quantum optimization algorithm using a quantum optimizer to determine one or more hash value states associated with the electronic file for a third network device based on at least the first hash value, the second hash value, and information associated with the one or more network devices in the distributed network;

initiate a control signal configured to store the one or more hash value states in a database associated with the third network device;

receive information associated with an incidence of the electronic file at the third network device, wherein the third network device is associated with the one or more network devices;

receive a third hash value of the electronic file from the third network device;

compare the third hash value with the one or more hash value states in the database to determine a match;

determine a partial match between the third hash value and the one or more hash value states in the database; and

initiate a file quarantine process configured to temporarily restrict the electronic file access to the third network device.

2. The system of claim 1 , wherein the module is further configured to:

receive information associated with an incidence of the electronic file at the third network device, wherein the third network device is associated with the one or more network devices;

receive a third hash value of the electronic file from the third network device;

compare the third hash value with the one or more hash value states in the database to determine a match; and

determine that the electronic file is malware based on at least determining a match between the third hash value and at least one of the one or more hash value states in the database.

3. The system of claim 2 , wherein the module is further configured to:

initiate an intrusion detection protocol configured to deny the electronic file access to the third network device based on at least determining that the electronic file is malware.

4. The system of claim 1 , wherein the module is further configured to initiate an alert on a user computing device indicating the initiation of the file quarantine process, and the restriction of the electronic file access.

5. The system of claim 4 , wherein the module is further configured to:

receive an indication from the user computing device indicating that the electronic file is malware;

initiate an intrusion detection protocol configured to deny the electronic file access to the third network device based on at least receiving the indication that the electronic file is malware; and

initiate a control signal configured to cause the third hash value to be added to the database.

6. The system of claim 1 , wherein the module is further configured to be communicatively coupled to a quantum optimizer, thereby enabling the transmission and reception of information.

7. A computerized method for enhanced detection of polymorphic malicious content within an entity, the method comprising:

receiving, using a processing device, information associated with an incidence of an electronic file in a distributed network comprising one or more network devices;

receiving, using a processing device, an first hash value of the electronic file from a first network device and a second hash value of the electronic file from a second network device, wherein the first network device and the second network device is associated with the one or more network devices;

comparing, using a processing device, the first hash value with the second hash value to determine a match between the two hash values for the electronic file received from the first and second network devices;

determining, using a processing device, that the electronic file is polymorphic based on at least determining that the first hash value at the first network device does not match the second hash value at the second network device;

initiating, using a processing device, an execution of a quantum optimization algorithm using a quantum optimizer to determine one or more hash value states associated with the electronic file for a third network device based on at least the first hash value, the second hash value, and information associated with the one or more network devices in the distributed network;

initiating, using a processing device, a control signal configured to store the one or more hash value states in a database associated with the third network device;

receiving, using a processing device, information associated with an incidence of the electronic file at the third network device, wherein the third network device is associated with the one or more network devices;

receiving, using a processing device, a third hash value of the electronic file from the third network device;

comparing, using a processing device, the third hash value with the one or more hash value states in the database to determine a match;

determining, using a processing device, a partial match between the third hash value and the one or more hash value states in the database; and

initiating, using a processing device, a file quarantine process configured to temporarily restrict the electronic file access to the third network device.

8. The computerized method of claim 7 , wherein the method further comprises:

receiving information associated with an incidence of the electronic file at the third network device, wherein the third network device is associated with the one or more network devices;

receiving a third hash value of the electronic file from the third network device;

comparing the third hash value with the one or more hash value states in the database to determine a match; and

determining that the electronic file is malware based on at least determining a match between the third hash value and at least one of the one or more hash value states in the database.

9. The computerized method of claim 8 , wherein the method further comprises initiating an intrusion detection protocol configured to deny the electronic file access to the third network device based on at least determining that the electronic file is malware.

10. The computerized method of claim 7 , wherein the method further comprises initiating an alert on a user computing device indicating the initiation of the file quarantine process, and the restriction of the electronic file access.

11. The computerized method of claim 10 , wherein the method further comprises:

receiving an indication from the user computing device indicating that the electronic file is malware;

initiating an intrusion detection protocol configured to deny the electronic file access to the third network device based on at least receiving the indication that the electronic file is malware; and

initiating a control signal configured to cause the third hash value to be added to the database.

12. A computer program product for enhanced detection of polymorphic malicious content within an entity, the computer program product comprising a non-transitory computer-readable medium comprising code causing a first apparatus to:

receive information associated with an incidence of an electronic file in a distributed network comprising one or more network devices;

receive an first hash value of the electronic file from a first network device and a second hash value of the electronic file from a second network device, wherein the first network device and the second network device is associated with the one or more network devices;

compare the first hash value with the second hash value to determine a match between the two hash values for the electronic file received from the first and second network devices;

determine that the electronic file is polymorphic based on at least determining that the first hash value at the first network device does not match the second hash value at the second network device;

initiate an execution of a quantum optimization algorithm using a quantum optimizer to determine one or more hash value states associated with the electronic file for a third network device based on at least the first hash value, the second hash value, and information associated with the one or more network devices in the distributed network;

initiate a control signal configured to store the one or more hash value states in a database associated with the third network device;

receive information associated with an incidence of the electronic file at the third network device, wherein the third network device is associated with the one or more network devices;

receive a third hash value of the electronic file from the third network device;

compare the third hash value with the one or more hash value states in the database to determine a match;

determine a partial match between the third hash value and the one or more hash value states in the database; and

initiate a file quarantine process configured to temporarily restrict the electronic file access to the third network device.

13. The computer program product of claim 12 , wherein the first apparatus is further configured to:

receive information associated with an incidence of the electronic file at the third network device, wherein the third network device is associated with the one or more network devices;

receive a third hash value of the electronic file from the third network device;

compare the third hash value with the one or more hash value states in the database to determine a match; and

determine that the electronic file is malware based on at least determining a match between the third hash value and at least one of the one or more hash value states in the database.

14. The computer program product of claim 13 , wherein the first apparatus is further configured to:

initiate an intrusion detection protocol configured to deny the electronic file access to the third network device based on at least determining that the electronic file is malware.

15. The computer program product of claim 12 , wherein the first apparatus is further configured to initiate an alert on a user computing device indicating the initiation of the file quarantine process, and the restriction of the electronic file access.

16. The computer program product of claim 15 , wherein the first apparatus is further configured to:

receive an indication from the user computing device indicating that the electronic file is malware;

initiate an intrusion detection protocol configured to deny the electronic file access to the third network device based on at least receiving the indication that the electronic file is malware; and

initiate a control signal configured to cause the third hash value to be added to the database.

17. The computer program product of claim 12 , wherein the first apparatus is further configured to be communicatively coupled to a quantum optimizer, thereby enabling the transmission and reception of information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2017
From: SIFFORD, ERIC EUGENE; STAHLHUT, WILLIAM AUGUST
To: BANK OF AMERICA CORPORATION
Reel/Frame 041458/0878 →
Continuity (1)
Related Publication 20180255073A1 · Sep 6, 2018