IP Library Granted Patent US 11,165,797
Granted Patent B2
US 11,165,797 · App. 15/479,650 · Granted Nov 2, 2021

Detecting endpoint compromise based on network usage history

Inventors: Karl Ackerman (Topsfield, MA); Mark David Harris (Oxon, GB); Kenneth D. Ray (Seattle, WA); Andrew J. Thomas (Oxfordshire, GB); Daniel Stutz (Karlsruhe, DE)
Assignee: Sophos Limited
H04L63/1425H04L63/1458G06F21/33H04L63/0245H04L63/1408H04L63/1416H04L63/1491H04L2463/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,797
App. No.
15/479,650
Granted
Nov 2, 2021
Kind
B2
Abstract

In the context of network activity by an endpoint in an enterprise network, malware detection is improved by using a combination of reputation information for a network address that is accessed by the endpoint with reputation information for an application on the endpoint that is accessing the network address. This information, when combined with a network usage history for the application, provides improved differentiation between malicious network activity and legitimate, user-initiated network activity.

Claims (36)

1. A computer program product for protecting against malicious network activity in an enterprise network, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on a processor of an endpoint operated by an end user in the enterprise network, performs the steps of:

detecting a connection initiated from an application executing on the endpoint in the enterprise network to a network address outside the enterprise network;

receiving a reputation of the application that is based on a first reputation lookup at a threat management facility for the enterprise network;

receiving a reputation of the network address that is based on a second reputation lookup at the threat management facility;

determining a network usage history for the application using a log of network activity maintained on the endpoint, the network usage history providing a general pattern of usage associated with the application on the endpoint, the general pattern of usage including a list of URLs associated with historic usage for the application on the endpoint;

evaluating the endpoint for a compromised condition based on the reputation of the application, the reputation of the network address, and the network usage history for the application, including at least a determination by the processor of whether the network address in the connection initiated from the application is outside historic usage for the application on the endpoint based on whether the network address is included on the list of URLs for resources outside the enterprise network that are associated with the historic usage for the application on the endpoint; and

initiating remediation action on the endpoint when the compromised condition is detected.

2. The computer program product of claim 1 , wherein the reputation of the application is at least one of known malicious, suspect, unknown, or known good.

3. The computer program product of claim 1 , wherein the reputation of the network address is at least one of known malicious, suspect, unknown, or known good.

4. The computer program product of claim 1 , wherein the reputation of the network address is based on crowd-sourced information about the network address.

5. The computer program product of claim 1 , further comprising code that performs the step of monitoring network activity by the application and storing the network usage history for the application in the log of network activity maintained on the endpoint.

6. The computer program product of claim 1 , further comprising code that performs the step of associating a network communication to the network address by a service executing on the endpoint with the application when the application controls the network communication, and adding the network communication to the network usage history for the application.

7. A method performed by computing circuitry of an endpoint user device, the method comprising:

detecting a connection initiated from an application executing on an endpoint in an enterprise network to a network address;

receiving, by using the computing circuitry of the endpoint user device, a reputation of the application using the connection, wherein the reputation of the application is requested from a threat management facility for the enterprise network;

receiving a reputation of the network address, wherein the reputation of the network address is requested from a threat management facility for the enterprise network;

determining a network usage history for the application using a log of network activity maintained on the endpoint user device, the network usage history providing a general pattern of usage associated with the application on the endpoint, the general pattern of usage including a list of URLs associated with historic usage for the application on the endpoint;

evaluating the endpoint for a compromised condition based on the reputation of the application, the reputation of the network address, and the network usage history for the application, including at least a determination by the computing circuitry of whether the network address in the connection initiated from the application is outside historic usage for the application on the endpoint based on whether the network address is included on the list of URLs for resources outside the enterprise network that are associated with the historic usage for the application on the endpoint; and

initiating remediation action on the endpoint when the compromised condition is detected.

8. The method of claim 7 , wherein the reputation of the application is at least one of known malicious, suspect, unknown, or known good.

9. The method of claim 7 , wherein the reputation of the network address is at least one of known malicious, suspect, unknown, or known good.

10. The method of claim 7 , wherein the reputation of the network address is based on crowd-sourced information about the network address.

11. The method of claim 7 , further comprising monitoring network activity by the application and storing the network usage history for the application in a log on the endpoint.

12. The method of claim 11 , further comprising associating a network communication to the network address by a service executing on the endpoint with the application when the application controls the network communication, and adding the network communication to the network usage history for the application.

13. A threat management system comprising:

a network interface for coupling the threat management system to an enterprise network;

a memory;

a processor configured by computer executable code stored in the memory to protect against malicious network activity in the enterprise network by performing the steps of:

detecting a connection initiated from an application executing on an end user endpoint in the enterprise network to a network address,

determining a reputation of the application using the connection,

determining a reputation of the network address; and

a local security agent of the end user endpoint configured by computer executable code stored in a second memory to perform the steps of:

determining a network usage history for the application using a log of network activity maintained on the end user endpoint, the network usage history providing a general pattern of usage associated with the application on the end user endpoint, the general pattern of usage including a list of URLs associated with historic usage for the application on the end user endpoint,

evaluating the end user endpoint for a compromised condition based on the reputation of the application, the reputation of the network address, and the network usage history for the application, including at least a determination of whether the network address in the connection initiated from the application is outside historic usage for the application on the end user endpoint based on whether the network address is included on the list of URLs for resources outside the enterprise network that are associated with the historic usage for the application on the end user endpoint, and

initiating remediation action on the end user endpoint when the compromised condition is detected.

14. The threat management system of claim 13 , wherein the reputation of the application is at least one of known malicious, suspect, unknown, or known good and wherein the reputation of the network address is at least one of known malicious, suspect, unknown, or known good.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2018
From: ACKERMAN, KARL; HARRIS, MARK DAVID; RAY, KENNETH D.; THOMAS, ANDREW J.; STUTZ, DANIEL
To: SOPHOS LIMITED
Reel/Frame 045115/0847 →
Continuity (4)
Continuation PCTUS2016040094 · Jun 29, 2016
Continuation In Part 15136762 · Apr 22, 2016
Continuation In Part 15136687 · Apr 22, 2016
Related Publication 20170310692A1 · Oct 26, 2017
Cited By (6)
US 12,205,059 US 12,289,343 US 12,316,643 US 12,418,561 US 12,470,575 US 12,609,937