IP Library Granted Patent US 10,511,614
Granted Patent B1
US 10,511,614 · App. 15/451,247 · Granted Dec 17, 2019

Subscription based malware detection under management system control

Inventor: Ashar Aziz (Coral Gables, FL)
Assignee: FireEye, Inc.
H04L63/1416G06Q20/10H04L63/145H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,511,614
App. No.
15/451,247
Granted
Dec 17, 2019
Kind
B1
Abstract

A method establishing communications between a management system and a malware detection system that collectively provide a distributed malware detection scheme. The malware detection system is configured to analyze network traffic to determine whether the network traffic includes malware. The management system is configured to set the malware detection system to a first level of malware detection based on a first subscription level purchased by a subscriber and control operability of the malware detection system.

Claims (36)

1. A method comprising:

establishing communications between a management system and one or more malware detection systems, each of the one or more malware detection systems being configured to analyze network traffic to determine whether the network traffic includes malware;

setting, by the management system, a first malware detection system of the one or more malware detection systems to a first level of malware detection based on a first subscription level purchased by a subscriber, wherein the first level of malware detection includes one or more services that, when in operation, analyze the network traffic for a presence of malware and the first subscription level being one of a plurality of subscription levels each corresponding to a different level of malware detection;

generating a signature that identifies malware detected in the network traffic by the malware detection system; and

distributing the signature to a second malware detection system, wherein a timing of the generating or distributing of the signature is based, at least in part, on the first subscription level and a level of subscription fee payment associated with the first subscription level.

2. The method of claim 1 , wherein the first level of malware detection differs in an amount of services provided by a second level of malware detection.

3. The method of claim 2 , wherein the analyzing of the network traffic by the malware detection system includes (i) analyzing content within the network traffic and (ii) analyzing behaviors of a network of computing systems each includes a virtual machine that is configured to process a portion of information within the network traffic to determine whether the network traffic includes malware.

4. The method of claim 1 , wherein each of the plurality of subscription levels is based on a different level of payment of a subscription fee.

5. The method of claim 1 further comprising:

controlling operability of the malware detection system based on a level of payment of a subscription fee associated with the first subscription level by the subscriber.

6. The method of claim 5 , wherein the controlling of the operability of the malware detection system comprises deactivating the malware detection system in response to a lack of payment of the subscription fee.

7. The method of claim 5 , wherein the controlling of the operability of the malware detection system comprises activating the malware detection system in response to payment of the subscription fee.

8. The method of claim 1 , wherein the malware detection system includes a computer worm sensor.

9. The method of claim 3 , wherein the analyzing of the content within the network traffic includes comparing data in the network traffic to one or more signatures locally stored within the malware detection system and determining a presence of malware included as part of the network traffic based on a level of correlation between the data in the network traffic and at least one signature of the one or more signatures exceeds a threshold, each of the one or more signatures identifies characteristics of malware.

10. The method of claim 9 , wherein the characteristics of malware include information that characterizes an anomalous behavior of the malware.

11. The method of claim 9 further comprising:

updating a plurality of signatures including the one or more signatures locally stored within the malware detection system in accordance with a periodicity that is based, at least in part, on the first subscription level and a level of subscription fee payment associated with the first subscription level.

12. The method of claim 5 , wherein the management system further controlling operability of a second malware detection system physically distributed from the malware detection system to form a distributed malware detection system to analyze network traffic originating from different enterprises for malware.

13. A method comprising:

establishing communications by a management system to a malware detection system that includes a controller and one or more virtual machines that are communicatively coupled to the controller and are configured to analyze network traffic to determine whether the network traffic includes malware;

setting, by the management system, the malware detection system to provide services associated with a first level of malware detection in response to receipt of a first level of payment, wherein the first level of malware detection includes analyzing the network traffic for a presence of malware;

setting, by the management system, the malware detection system to provide services associated with a second level of malware detection that is more robust than the services associated with the first level of malware detection in response to receipt of a second level of payment greater than the first level of payment;

generating a signature that identifies malware detected in the network traffic by the malware detection system; and

distributing the signature to a second malware detection system, wherein a timing of the generating or distributing of the signature is based, at least in part, on the first subscription level and a level of subscription fee payment associated with the first subscription level.

14. The method of claim 13 , wherein the timing of the generating or distributing of the signature includes distributing the signature in accordance with a periodity that is based, at least in part, on the first subscription level and the level of subscription fee payment.

15. The method of claim 13 , wherein the analyzing of the network traffic by the malware detection system includes (i) analyzing of content within the network traffic and (ii) analyzing behaviors of one or more virtual machines configured to process a portion of information within the network traffic to determine whether the network traffic includes malware.

16. The method of claim 13 further comprising:

controlling operability of the malware detection system that comprises deactivating the malware detection system in response to a lack of payment of a subscription fee.

17. The method of claim 13 , wherein the controlling of the operability of the malware detection system comprises activating of the malware detection system in response to a lack of payment of the subscription fee.

18. The method of claim 13 , wherein the analyzing of the network traffic to determine whether the network traffic includes malware includes comparing data in the network traffic to one or more signatures locally stored within the malware detection system and determining a presence of malware included as part of the network traffic based on a level of correlation between the data in the network traffic and at least one signature of the one or more signatures exceeds a threshold, each of the one or more signatures identifies characteristics of malware.

19. The method of claim 18 , wherein the characteristics of malware include information that characterizes an anomalous behavior of the malware.

20. A system comprising:

means for establishing communications to a malware detection system, the malware detection system including a controller and one or more virtual machines that are communicatively coupled to the controller and are configured to analyze network traffic to determine whether the network traffic includes malware;

means for setting the malware detection system to provide (i) services associated with a first level of malware detection in response to receipt of a first level of payment, and (ii) services associated with a second level of malware detection that is more robust than the services associated with the first level of malware detection in response to receipt of a second level of payment being greater than the first level of payment;

means for generating a signature that identifies malware detected in the network traffic by the malware detection system; and

means for distributing the signature to a second malware detection system, wherein a timing of at least the distributing of the signature is based, at least in part, on the first subscription level and a level of subscription fee payment associated with the first subscription level.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063113/0150 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0140 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2017
From: AZIZ, ASHAR
To: FIREEYE, INC.
Reel/Frame 042484/0028 →
Cited By (13)
US 12,200,013 US 12,248,563 US 12,278,834 US 12,326,932 US 12,348,519 US 12,355,770 US 12,363,145 US 12,423,418 US 12,432,242 US 12,445,458 US 12,603,921 US 12,670,246 US 12,695,793