IP Library Granted Patent US 10,462,173
Granted Patent B1
US 10,462,173 · App. 15/633,226 · Granted Oct 29, 2019

Malware detection verification and enhancement by coordinating endpoint and malware detection systems

Inventors: Ashar Aziz (Coral Gables, FL); Osman Abdoul Ismael (Palo Alto, CA)
Assignee: FireEye, Inc.
H04L63/1433H04L63/145H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,462,173
App. No.
15/633,226
Granted
Oct 29, 2019
Kind
B1
Abstract

Computerized techniques to determine and verify maliciousness of an object are described. An endpoint device, during normal processing of an object, identifies the object as suspicious in response to detected features of the object and coordinates further analysis with a malware detection system. The malware detection system processes the object, collects features related to processing, and analyzes the features of the suspicious object to classify as malicious or benign. Correlation of the features captured by the endpoint device and the malware detection system may verify a classification by the malware detection system of maliciousness of the content. The malware detection system may communicate with the one or more endpoint devices to influence detection and reporting of behaviors by those device(s).

Claims (44)

1. A system to determine maliciousness of an object, comprising:

a first endpoint, including at least one processor, configured with a first software profile, further configured to detect one or more features exhibited by an object during processing by the first endpoint and determine if the features detected are suspicious;

a malware detection system, including at least one processor, communicatively coupled directly or indirectly to the first endpoint over a network, the malware detection system configured to process a received object in a virtual machine of one or more virtual machines that operate within the malware detection system to detect one or more features in response to the first endpoint determining the features of the object are suspicious, the virtual machine being provisioned with the first software profile;

a security logic engine configured to (i) receive information associated with features detected, during processing of the object, by the first endpoint and by the virtual machine of the malware detection system, (ii) correlate the received information associated with the received features, (iii) generate a first determination of maliciousness of the object, and (iv) in response to the generation of the first determination of maliciousness of the object, issue an alert,

wherein the security logic engine is further configured to direct the malware detection system to process the object within a second virtual machine of the one or more virtual machines that is provisioned with a second software profile, in response to receipt of information associated with features from a second endpoint with the second software profile.

2. The system of claim 1 , wherein the malware detection system is further configured to:

determine the second software profile based on the object; and

provision the virtual machine with the second software profile.

3. The system of claim 2 , wherein the security logic engine is further configured to:

receive information associated with the features detected by the second endpoint configured with the second software profile;

combine the features detected by the second endpoint with the features detected by the first endpoint and the virtual machine of the malware detection system; and

correlate and classify the combined features and generate a second determination of maliciousness of the object.

4. The system of claim 3 , wherein the security logic engine verifies the maliciousness of the object if the first determination of maliciousness and second determination of maliciousness correspond.

5. The system of claim 1 , wherein the malware detection system receives an identifier related to the object and obtains the object identified by the identifier from a network object store coupled to the malware detection system via a network connection.

6. The system of claim 1 , wherein the malware detection system receives the object to be processed by the malware detection system from the first endpoint.

7. The system of claim 1 , wherein the security logic engine determines the first software profile as vulnerable in response to the first determination of maliciousness of the object as malicious.

8. The system of claim 1 , wherein the security logic engine identifies a software profile for each of a plurality of endpoints on the network and in response to the first determination of maliciousness, identifies a subset of the plurality of endpoints as vulnerable to the object based on the software profile of each endpoint of the plurality of endpoints, and includes the information regarding the subset of the plurality of endpoints in the alert.

9. The system of claim 1 , wherein the second software profile is different than the first software profile.

10. The system of claim 1 , wherein the first endpoint comprises an agent configured to detect one or more features related to the object exhibited during processing of the object by the first endpoint.

11. A computerized method to determine maliciousness of an object, comprising:

conducting an analysis of the object determined to be suspicious based on a first set of features associated with the object, by a first virtual machine of a malware detection system, in response to a first endpoint of a plurality of endpoints determining the object is suspicious, the analysis comprising (i) receiving the object by the malware detection system, and (ii) identifying a second set of features associated with the object during analysis by the malware detection system, the first virtual machine being provisioned with a first software profile;

receiving information associated with the first set of features and information associated with the second set of features by a security logic engine;

generating a first determination of maliciousness of the object, by correlating the received information associated with the first set of features and the second set of features with features of known malicious and benign objects and classifying the object in response to the correlation of the received information, by the security logic engine;

generating a first alert to report the first determination of maliciousness; and

conducting an analysis of the object by a second virtual machine of the malware detection system in response to the security logic engine identifying a threat vector associated with at least a second endpoint of the plurality of endpoints different than the first endpoint, the second virtual machine being provisioned with a second software profile different than the first software profile.

12. The computerized method of claim 11 , wherein the second set of features comprise behaviors exhibited during processing of the object in the first virtual machine of the malware detection system.

13. The computerized method of claim 11 , wherein the security logic engine is a component of the malware detection system.

14. The computerized method of claim 11 , further comprising:

receiving, by the security logic engine, information associated with a third set of features, detected while processing the object by the second endpoint;

generating a second determination of maliciousness, by the security logic engine, of the object by correlating the received information associated with the first, second, and third set of features with features of known malicious and benign objects and classifying the object based on the second determination of maliciousness; and

generating a second alert to report the second determination of maliciousness.

15. The computerized method of claim 11 , wherein the second alert generated by the security logic engine further comprises information to prevent the processing of the object by each of the plurality of endpoints.

16. The computerized method of claim 11 , further comprises:

identifying the second software profile associated with the second endpoint, by the security logic engine;

configuring the second virtual machine of the malware detection system with the second software profile;

generating a second determination of maliciousness in response to correlating information associated with an identified third set of features with known malicious and benign objects; and

determining, by the security logic engine, the second endpoint software profile is vulnerable to the object in response to the second determination of maliciousness.

17. The computerized method of claim 16 , wherein the security logic engine further comprises:

associating, by the security logic engine, each endpoint, communicatively coupled with the security logic engine, with a software profile; and

determining, by the security logic engine the vulnerability of each endpoint of the plurality of endpoints in response to correlating between the vulnerable software profile and the software profiles of each endpoint.

18. The computerized method of claim 11 , further comprising receiving, by the security logic engine, information related to communication between one or more endpoints and the first endpoint having processed the object; and determining, by the security logic engine, one or more endpoints of the plurality of endpoints are at risk of being affected by the object.

19. The computerized method of claim 11 , wherein prior to conducting the analysis of the object by the first virtual machine of the malware detection system, the method further comprising:

identifying the first set of features associated with the object during processing the object by the first endpoint of the plurality of endpoints; and

determining, by the first endpoint, the object is suspicious based on the first set of features associated with the object.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0707 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0702 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2017
From: AZIZ, ASHAR; ISMAEL, OSMAN ABDOUL
To: FIREEYE, INC.
Reel/Frame 043840/0957 →
Continuity (1)
Provisional Application 62357119 · Jun 30, 2016
Cited By (16)
US 12,189,774 US 12,200,013 US 12,225,037 US 12,244,637 US 12,248,563 US 12,363,145 US 12,373,576 US 12,445,458 US 12,505,207 US 12,572,651 US 12,587,547 US 12,591,677 US 12,596,804 US 12,647,460 US 12,651,057 US 12,651,061