IP Library Granted Patent US 10,462,162
Granted Patent B2
US 10,462,162 · App. 15/657,317 · Granted Oct 29, 2019

Detecting malicious processes based on process location

Inventors: Roy Hodgman (Cambridge, MA); Oliver Keyes (Seattle, WA); Wah-Kwan Lin (Melrose, MA); Michael Scutt (Alexandria, VA); Timothy Stiller (White Post, VA)
Assignee: Rapid7, Inc.
H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,462,162
App. No.
15/657,317
Granted
Oct 29, 2019
Kind
B2
Abstract

Methods and systems for detecting malicious processes. Methods described herein gather data regarding process locations and calculate one or more inequality indicators related to the process paths based on economic principles. Instances of inequality with respect to process paths may indicate a path is uncommon and therefore the associated binary is used for malicious purposes.

Claims (30)

1. A method for identifying malicious processes, the method comprising:

receiving, using an interface, at least one path indicating where a process was launched;

determining, using an analysis module executing instructions stored on a memory, a number of times the process was launched;

determining a number of different paths the process was launched from;

computing, using the analysis module, at least one inequality indicator for the at least one path based on the number of times the process was launched and the number of different paths the process was launched from to determine whether the process is malicious, wherein the inequality indicator is based on a pattern across multiple paths that is identified autonomously and not previously defined; and

isolating the process upon determining the process is malicious, wherein isolating the malicious process includes relocating the malicious process to a quarantine module for analysis.

2. The method of claim 1 wherein the at least one inequality indicator is at least one of a Herfindahl index and a Gini coefficient.

3. The method of claim 2 , wherein an inequality indicator exceeding a predetermined threshold indicates an instance of inequality and therefore indicates a process is uncommon and potentially malicious.

4. The method of claim 1 , further comprising:

parsing, using the analysis module, the at least one path into at least one individual component; and

removing, using the analysis module, at least one individual component from the at least one path.

5. The method of claim 4 , wherein removing the at least one individual component comprises removing at least one individual component that is present less than a predetermined number of times in the at least one path.

6. The method of claim 4 , wherein the removed at least one individual component is a username or a string specific to an instance of a computing environment.

7. The method of claim 1 , wherein isolating the malicious process includes elevating the malicious process for examination.

8. A system for identifying malicious processes, the system comprising:

an interface configured to receive at least one path indicating where a process was launched;

a memory; and

an analysis module configured to execute instructions stored on the memory to:

determine a number of times the process was launched;

determine a number of different paths the process was launched from;

compute at least one inequality indicator for the at least one path based on the number of times the process was launched and the number of different paths the process was launched from to determine whether the process is malicious, wherein the inequality indicator is based on a pattern across multiple paths that is identified autonomously and not previously defined; and

isolate a process upon determining the process is malicious, wherein isolating the malicious process includes relocating the malicious process to a quarantine module for analysis.

9. The system of claim 8 , wherein the at least one inequality indicator is at least one of a Herfindahl index and a Gini coefficient.

10. The system of claim 9 , wherein an inequality indicator exceeding a predetermined threshold indicates an instance of inequality and therefore indicates a process is uncommon and potentially malicious.

11. The system of claim 8 , wherein the analysis module is further configured to:

parse the at least one path into at least one individual component; and

remove at least one individual component from the at least one path.

12. The system of claim 11 , wherein the analysis module removes at least one individual component that is present less than a predetermined number of times in the at least one path.

13. The system of claim 11 , wherein the removed at least one individual component is a username or a string specific to an instance of a computing environment.

14. The system of claim 8 , isolating the malicious process includes elevating the malicious process for manual examination.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2018
From: HODGMAN, ROY; KEYES, OLIVER; LIN, WAH-KWAN; SCUTT, MICHAEL; STILLER, TIMOTHY
To: RAPID7, INC.
Reel/Frame 045030/0652 →
Continuity (1)
Related Publication 20190028491A1 · Jan 24, 2019