IP Library Granted Patent US 10,250,623
Granted Patent B1
US 10,250,623 · App. 15/838,285 · Granted Apr 2, 2019

Generating analytical data from detection events of malicious objects

Inventors: Mark William Patton (San Jose, CA); Darren Kazuo Chinen (Fremont, CA); Braydon Michael Davis (Danville, CA); Ragesh Damodaran (Santa Clara, CA); Manikandan Vellore Muneeswaran (Santa Clara, CA); Vijay Arumugam Velayutham (San Jose, CA)
Assignee: Malwarebytes, Inc.
H04L63/1416H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,250,623
App. No.
15/838,285
Granted
Apr 2, 2019
Kind
B1
Abstract

A security server tracks malicious objects detected by malware detection applications that scan for malicious objects on clients. The security server also receives client information from the clients indicating client states. The client state describes one or more protection applications executing on the client that seek to identify and prevent malicious objects from taking malicious actions based on real-time monitoring. Thus, the security server may identify when the protection application fails to detect a malicious object. In addition, the security server maps detection events of malicious objects with corresponding client states to generate aggregate detection information for a population of clients. Analytical data can be derived from the aggregate detection information to identify trends useful for evaluating different types of protection applications. Furthermore, the security server may initiate automated actions based on the identified trends to improve detection and remediation of the malicious objects on the clients.

Claims (65)

1. A method for detecting malicious objects, the method comprising:

receiving, from a malware detection application executing on a client, client information indicating a client state describing at least one protection application executing on the client and a geolocation associated with the client;

receiving, from the malware detection application, a new detection event describing a malicious object on the client that went undetected by the at least one protection application and was subsequently detected by the malware detection application when the client is in the client state, the new detection event further including a time associated with the new detection event;

mapping the new detection event to the client state when the malicious object was detected for storage in a detections database;

generating aggregate detection information by aggregating the new detection event with historical detection events stored in the detections database for a plurality of clients executing instances of the malware detection application and instances of the at least one protection application, the aggregate detection information indicating a count of detection events on the plurality of clients in which the malicious object went undetected by the respective instances of the at least one protection application and was subsequently detected by the instances of the malware detection application;

generating a user interface displaying the count of detection events and including a control for generating a playback of the aggregate detection information, wherein in response to selection of the control, the user interface displays a sequence of indicators at coordinates of a map corresponding to respective geolocations of the historical detection events, the indicators being displayed according to the respective times associated with the historical detection events to indicate geographic spread of the malicious object on the plurality of clients; and

providing the user interface to an administrative client for presentation.

2. The method of claim 1 , further comprising:

providing feedback generated using the aggregate detection information to the client for presentation.

3. The method of claim 1 , further comprising:

responsive to determining an updated threat for malicious objects using the aggregate detection information, modifying a priority of updates provided to the plurality of clients executing instances of the malware detection application.

4. The method of claim 1 , further comprising:

classifying malicious objects detected by the instances of the malware detection application executing on the plurality of clients into a plurality of categories for storage in the detections database;

generating, across one of the plurality of categories, an additional count of detection events for malicious objects occurring from the clients executing the at least one protection application; and

sending an alert to each of the clients responsive to determining that the additional count is greater than a threshold value, the alert indicating performance specific to the at least one protection application.

5. The method of claim 4 , further comprising:

sending a notification to a creator or administrator of the at least one protection application regarding the lack of detection responsive to determining that the additional count is greater than the threshold value.

6. The method of claim 4 , further comprising:

responsive to determining that the additional count is greater than the threshold value, sending a notification to each of the clients executing the at least one protection application to adjust a scanning frequency of malware detection applications.

7. The method of claim 1 , wherein mapping the detection event to the client state comprises:

determining the geolocation associated with the client based on a client identifier indicated by the client information; and

storing, in the detections database, an association between the new detection event and the geolocation.

8. The method of claim 1 , further comprising:

responsive to determining that the count of detection events for the malicious object is greater than a threshold value, sending an updated definition of the malicious object to the clients executing the at least one protection application.

9. The method of claim 7 , wherein the geolocation is determined using an IP address of the client as the client identifier, the new detection event is stored along with the geolocation in the detections database, and the historical detection events are aggregated based at least on associated geolocations.

10. A non-transitory computer-readable storage medium storing instructions for detecting malicious objects, the instructions when executed by a processor causing the processor to perform steps including:

receiving, from a malware detection application executing on a client, client information indicating a client state describing at least one protection application executing on the client and a geolocation associated with the client;

receiving, from the malware detection application, a new detection event describing a malicious object on the client that went undetected by the at least one protection application and was subsequently detected by the malware detection application when the client is in the client state, the new detection event further including a time associated with the new detection event;

mapping the new detection event to the client state when the malicious object was detected for storage in a detections database;

generating aggregate detection information by aggregating the new detection event with historical detection events stored in the detections database for a plurality of clients executing instances of the malware detection application and instances of the at least one protection application, the aggregate detection information indicating a count of detection events on the plurality of clients in which the malicious object went undetected by the respective instances of the at least one protection application and was subsequently detected by the instances of the malware detection application;

generating a user interface displaying the count of detection events and including a control for generating a playback of the aggregate detection information, wherein in response to selection of the control, the user interface displays a sequence of indicators at coordinates of a map corresponding to respective geolocations of the historical detection events, the indicators being displayed according to the respective times associated with the historical detection events to indicate geographic spread of the malicious object on the plurality of clients; and

providing the user interface to an administrative client for presentation.

11. The computer-readable storage medium of claim 10 , comprising further instructions that when executed by the processor cause the processor to perform steps including:

responsive to determining an updated threat for malicious objects using the aggregate detection information, modifying a priority of updates provided to the plurality of clients executing instances of the malware detection application.

12. The computer-readable storage medium of claim 10 , comprising further instructions that when executed by the processor cause the processor to perform steps including:

classifying malicious objects detected by the instances of the malware detection application executing on the plurality of clients into a plurality of categories for storage in the detections database;

generating, across one of the plurality of categories, an additional count of detection events for malicious objects occurring from the clients executing the at least one protection application; and

sending an alert to each of the clients responsive to determining that the additional count is greater than a threshold value, the alert indicating performance specific to the at least one protection application.

13. The computer-readable storage medium of claim 12 , comprising further instructions that when executed by the processor cause the processor to perform steps including:

responsive to determining that the additional count is greater than the threshold value, sending a notification to each of the clients executing the at least one protection application to adjust a scanning frequency of malware detection applications.

14. The computer-readable storage medium of claim 10 , wherein mapping the detection event to the client state comprises:

determining the geolocation associated with the client based on a client identifier indicated by the client information; and

storing, in the detections database, an association between the new detection event and the geolocation.

15. The computer-readable storage medium of claim 10 , comprising further instructions that when executed by the processor cause the processor to perform steps including:

responsive to determining that the count of detection events for the malicious object is greater than a threshold value, sending an updated definition of the malicious object to the clients executing the at least one protection application.

16. A computing system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions for detecting malicious objects, the instructions when executed by the processor causing the processor to perform steps including:

receiving, from a malware detection application executing on a client, client information indicating a client state describing at least one protection application executing on the client and a geolocation associated with the client;

receiving, from the malware detection application, a new detection event describing a malicious object on the client that went undetected by the at least one protection application and was subsequently detected by the malware detection application when the client is in the client state, the new detection event further including a time associated with the new detection event;

mapping the new detection event to the client state when the malicious object was detected for storage in a detections database;

generating aggregate detection information by aggregating the new detection event with historical detection events stored in the detections database for a plurality of clients executing instances of the malware detection application and instances of the at least one protection application, the aggregate detection information indicating a count of detection events on the plurality of clients in which the malicious object went undetected by the respective instances of the at least one protection application and was subsequently detected by the instances of the malware detection application;

generating a user interface displaying the count of detection events and including a control for generating a playback of the aggregate detection information, wherein in response to selection of the control, the user interface displays a sequence of indicators at coordinates of a map corresponding to respective geolocations of the historical detection events, the indicators being displayed according to the respective times associated with the historical detection events to indicate geographic spread of the malicious object on the plurality of clients; and

providing the user interface to an administrative client for presentation.

17. The computing system of claim 16 , wherein the computer-readable storage medium comprises further instructions that when executed by the processor cause the processor to perform steps including:

responsive to determining an updated threat for malicious objects using the aggregate detection information, modifying a priority of updates provided to the plurality of clients executing instances of the malware detection application.

18. The computing system of claim 16 , wherein the computer-readable storage medium comprises further instructions that when executed by the processor cause the processor to perform steps including:

classifying malicious objects detected by the instances of the malware detection application executing on the plurality of clients into a plurality of categories for storage in the detections database;

generating, across one of the plurality of categories, an additional count of detection events for malicious objects occurring from the clients executing the at least one protection application; and

sending an alert to each of the clients responsive to determining that the additional count is greater than a threshold value, the alert indicating performance specific to the at least one protection application.

19. The computing system of claim 18 , wherein the computer-readable storage medium comprises further instructions that when executed by the processor cause the processor to perform steps including:

responsive to determining that the additional count is greater than the threshold value, sending a notification to each of the clients executing the at least one protection application to adjust a scanning frequency of malware detection applications.

20. The computing system of claim 16 , wherein mapping the detection event to the client state comprises:

determining the geolocation associated with the client based on a client identifier indicated by the client information; and

storing, in the detections database, an association between the new detection event and the geolocation.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES INC.
Reel/Frame 069193/0505 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 069193/0563 →
SECURITY INTEREST Recorded Oct 18, 2024
From: MALWAREBYTES INC.; MALWAREBYTES CORPORATE HOLDCO INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 068943/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: MALWAREBYTES INC.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 066900/0386 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 26, 2024
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066373/0912 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 1, 2023
From: MALWAREBYTES INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062599/0069 →
SECURITY INTEREST Recorded Oct 10, 2019
From: MALWAREBYTES INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 050681/0271 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2017
From: PATTON, MARK WILLIAM; CHINEN, DARREN KAZUO; DAVIS, BRAYDON MICHAEL; DAMODARAN, RAGESH; MUNEESWARAN, MANIKANDAN VELLORE; VELAYUTHAM, VIJAY ARUMUGAM
To: MALWAREBYTES INC.
Reel/Frame 044458/0555 →
Cited By (7)
US 12,267,350 US 12,278,835 US 12,346,447 US 12,388,842 US 12,445,344 US 12,579,259 US 12,712,887