IP Library Granted Patent US 10,783,241
Granted Patent B2
US 10,783,241 · App. 15/887,496 · Granted Sep 22, 2020

System and methods for sandboxed malware analysis and automated patch development, deployment and validation

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX, INC.
G06F21/53G06F8/65G06F9/455G06F21/566G06F21/577G06Q40/08H04L63/1425H04L63/1433G06F2221/033G06F2221/2149G06N20/00G06Q50/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,783,241
App. No.
15/887,496
Granted
Sep 22, 2020
Kind
B2
Abstract

A system and methods for sandboxed malware analysis and automated patch development, deployment and validation, that uses a business operating system, vulnerability scoring engine, binary translation engine, sandbox simulation engine, at least one network endpoint, at least one database, a network, and a combination of machine learning and vulnerability probing techniques, to analyze software, locate any vulnerabilities or malicious behavior, and attempt to patch and prevent undesired behavior from occurring, autonomously.

Claims (31)

1. A system for sandboxed malware analysis and automated vulnerability protection, comprising:

a computing device comprising a memory and a processor;

a business operating system comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

intercept a file at a network device endpoint;

determining whether the file is executable machine code;

for files comprising executable machine code, identify a type of device on which the executable machine code will operate;

for files not comprising executable machine code, determine whether the file comprises programming code for an executable application:

identify a programming code language and a type of device for which the programming code was written; and

compile the programming code into executable machine code;

transfer the executable machine code to a device-specific sandbox environment, the device-specific sandbox environment comprising a safe environment that emulates functionality of the identified type of device where malware is unable to affect systems outside of the device-specific sandbox environment;

receive an identified vulnerability from the sandbox environment related to the identified type of device; and

change the system behavior of the real device to prevent exploitation of the identified vulnerability through either address space layout randomization or data execution prevention;

and

a device-specific sandbox environment comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the executable machine code from the business operating system;

execute the executable machine code on an emulator of the type of device;

identify an irregularity in the execution of the executable machine code on the emulator, the irregularity comprising one or more of the following activities performed in suspicious ways not normally performed by benign software: memory scanning, deletion of the file containing the executable machine code from storage media, access of system files, access of permissions, access of security settings, and access of network adapters;

identify a vulnerability of the identified type of device being targeted by the identified irregularity in the execution of the executable machine code; and

send the identified vulnerability to the business operating system.

2. A method for sandboxed malware analysis and automated vulnerability protection, comprising the steps of:

intercepting a file at a network device endpoint;

determining whether the file is executable machine code;

for files comprising executable machine code, identifying a type of device on which the executable machine code will execute;

for files not comprising executable machine code, determining whether the file comprises programming code for an executable application:

identifying a programming code language and a type of device for which the programming code was written; and

compiling the programming code into executable machine code;

transferring the executable machine code to a device-specific sandbox environment, the device-specific sandbox environment comprising a safe environment that emulates functionality of the identified type of device where malware is unable to affect systems outside of the device-specific sandbox environment;

executing the executable machine code on an emulator for the type of device within the device-specific sandbox environment;

identifying an irregularity in the execution of the executable machine code within the device-specific sandbox environment, the irregularity comprising one or more of the following activities performed in suspicious ways not normally performed by benign software: memory scanning, deletion of the file containing the executable machine code from storage media, access of system files, access of permissions, access of security settings, and access of network adapters;

identifying a vulnerability of the identified type of device being targeted by the identified irregularity in the execution of the executable machine code; and

changing the system behavior of the real device to prevent exploitation of the identified vulnerability through either address space layout randomization or data execution prevention.

Assignments (9)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF ADDRESS Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0683 →
CHANGE OF NAME Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2018
From: SELLERS, ANDREW; CRABTREE, JASON
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 044835/0434 →
Continuity (23)
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15887496
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568307 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Related Publication 20180276372A1 · Sep 27, 2018