IP Library Granted Patent US 10,740,463
Granted Patent B2
US 10,740,463 · App. 15/888,532 · Granted Aug 11, 2020

Method and system for proactive detection of malicious shared libraries via a remote reputation system

Inventor: Ahmed Said Sallam (Cupertino, CA)
Assignee: McAfee, LLC
G06F21/56G06F21/562G06F21/567G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,740,463
App. No.
15/888,532
Granted
Aug 11, 2020
Kind
B2
Abstract

A method for proactively detecting shared libraries suspected of association with malware includes the steps of determining one or more shared libraries loaded on an electronic device, determining that one or more of the shared libraries include suspicious shared libraries by determining that the shared library is associated with indications that the shared library may have been maliciously injected, loaded, and/or operating on the electronic device, and identifying the suspicious shared libraries to a reputation server.

Claims (94)

1. A method of evaluating a shared library, comprising:

receiving, at a reputation server, information about a first suspicious shared library on an electronic device;

using a reputation application executing on a hardware processor of the reputation server, comparing historical data of activity of the first suspicious shared library against activity representative of shared libraries associated with malware, the historical data collected from one or more other electronic devices, the first suspicious shared library found in each of the one or more electronic devices, including:

comparing a determined quantity of electronic devices on which the first suspicious shared library has been present against a lower device threshold; and

comparing a determined quantity of different networks on which the electronic devices have resided against an upper network threshold, the electronic devices corresponding to the determined quantity of electronic devices on which the first suspicious shared library has been present; and

determining, with the reputation application, that the first suspicious shared library is malicious based upon:

a determination that the quantity of electronic devices is below the lower device threshold; and

a determination that the quantity of different networks exceeds the upper network threshold.

2. The method of claim 1 , further comprising:

receiving, at a reputation server, information about a second suspicious shared library on the electronic device;

comparing, with the reputation application, historical data of activity of the second suspicious shared library against the activity representative of shared libraries associated with malware; including:

determining whether the second suspicious shared library is identified in a list of trusted modules; and

comparing a determined quantity of different networks on which the second suspicious shared library has been present against a lower network threshold; and

determining that the second suspicious shared library is safe based upon:

a determination that the second suspicious shared library is not identified in the list of trusted modules; and

a determination that the quantity of different networks on which the second suspicious shared library has been present is less than the lower network threshold.

3. The method of claim 2 , further comprising, with the reputation application:

comparing a determined quantity of electronic devices on which the second suspicious shared library has been present against an upper device threshold; and

determining that the second suspicious shared library is safe is further based upon a determination that the quantity of electronic devices on which the second suspicious shared library has been present exceeds the upper device threshold.

4. The method of claim 2 , further comprising:

receiving, at the reputation server, additional information about the second suspicious shared library; and

determining that the second suspicious shared library is safe is further based upon a determination that a scan of the second suspicious shared library indicated no malware, the scan corresponding to the additional information about the second suspicious shared library.

5. The method of claim 1 , further comprising, with the reputation application:

identifying a quantity of different system executable objects that include any hook that points to the first suspicious shared library, the system executable objects reported from a plurality of clients; and

determining that the first suspicious shared library is malicious is further based upon a determination that a plurality of different system executable objects include any hook that points to the first suspicious shared library.

6. The method of claim 1 , further comprising, with the reputation application:

comparing a determined quantity of applications to which the first suspicious shared library has been linked against an upper application threshold; and

determining that the first suspicious shared library is malicious further based upon a determination that the quantity of applications to which the first suspicious shared library has been linked exceeds the upper application threshold.

7. The method of claim 1 , further comprising, with the reputation application:

determining whether the first suspicious shared library has been linked to no application; and

determining that the first suspicious shared library is malicious further based upon a determination that the first suspicious shared library has been linked to no application.

8. At least one non-transitory computer readable medium including a reputation application, the reputation including computer-executable instructions carried on the non-transitory computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for configuring the processor to:

receive information about a first suspicious shared library on an electronic device;

compare historical data of activity of the first suspicious shared library against activity representative of shared libraries associated with malware, the historical data collected from one or more other electronic devices, the first suspicious shared library found in each of the one or more electronic devices, including:

compare a determined quantity of electronic devices on which the first suspicious shared library has been present against a lower device threshold; and

compare a determined quantity of different networks on which the electronic devices have resided against an upper network threshold, the electronic devices corresponding to the determined quantity of electronic devices on which the first suspicious shared library has been present; and

determine that the first suspicious shared library is malicious based upon:

a determination that the quantity of electronic devices is below the lower device threshold; and

a determination that the quantity of different networks exceeds the upper network threshold.

9. The article of claim 8 , wherein the processor is further configured to:

receive information about a second suspicious shared library on the electronic device;

compare historical data of activity of the second suspicious shared library against the activity representative of shared libraries associated with malware; including:

determine whether the second suspicious shared library is identified in a list of trusted modules; and

compare a determined quantity of different networks on which the second suspicious shared library has been present against a lower network threshold; and

determine that the second suspicious shared library is safe based upon:

a determination that the second suspicious shared library is not identified in the list of trusted modules; and

a determination that the quantity of different networks on which the second suspicious shared library has been present is less than the lower network threshold.

10. The article of claim 9 , wherein:

the processor is further configured to compare a determined quantity of electronic devices on which the second suspicious shared library has been present against an upper device threshold; and

the determination that the second suspicious shared library is safe is further based upon a determination that the quantity of electronic devices on which the second suspicious shared library has been present exceeds the upper device threshold.

11. The article of claim 9 , wherein:

the processor is further configured to receive additional information about the second suspicious shared library; and

the determination that the second suspicious shared library is safe is further based upon a determination that a scan indicated no malware, the scan corresponding to the additional information about the second suspicious shared library.

12. The article of claim 8 , wherein:

the processor is further configured to identify a quantity of different system executable objects that include any hook that points to the first suspicious shared library, the system executable objects reported from a plurality of clients; and

the determination that the first suspicious shared library is malicious is further based upon a determination that a plurality of different system executable objects include any hook that points to the first suspicious shared library.

13. The article of claim 8 , wherein:

the processor is further configured to compare a determined quantity of applications to which the first suspicious shared library has been linked against an upper application threshold; and

the determination that the first suspicious shared library is malicious is further based upon a determination that the quantity of applications to which the first suspicious shared library has been linked exceeds the upper application threshold.

14. The article of claim 8 , wherein:

the processor is further configured to determine whether the first suspicious shared library has been linked to no application; and

the determination that the first suspicious shared library is malicious is further based upon a determination that the first suspicious shared library has been linked to no application.

15. A system for evaluation of malware, comprising:

a processor;

a reputation database including historical data of shared libraries;

a reputation server executed by the processor and configured to:

receive information about a first suspicious shared library on an electronic device;

compare historical data of activity of the first suspicious shared library against activity representative of shared libraries associated with malware, the historical data collected from one or more other electronic devices, the first suspicious shared library found in each of the one or more electronic devices, including:

compare a determined quantity of electronic devices on which the first suspicious shared library has been present against a lower device threshold; and

compare a determined quantity of different networks on which the electronic devices have resided against an upper network threshold, the electronic devices corresponding to the determined quantity of electronic devices on which the first suspicious shared library has been present; and

determine that the first suspicious shared library is malicious based upon:

a determination that the quantity of electronic devices is below the lower device threshold; and

a determination that the quantity of different networks exceeds the upper network threshold.

16. The system of claim 15 , wherein:

the reputation server is further configured to:

receive information about a second suspicious shared library on the electronic device;

compare historical data of activity of the second suspicious shared library against the activity representative of shared libraries associated with malware; including:

determine whether the second suspicious shared library is identified in a list of trusted modules; and

compare a determined quantity of different networks on which the second suspicious shared library has been present against a lower network threshold; and

determine that the second suspicious shared library is safe based upon:

a determination that the second suspicious shared library is not identified in the list of trusted modules; and

a determination that the quantity of different networks on which the second suspicious shared library has been present is less than the lower network threshold.

17. The system of claim 16 , wherein:

the reputation server is further configured to compare a determined quantity of electronic devices on which the second suspicious shared library has been present against an upper device threshold; and

the determination that the second suspicious shared library is safe is further based upon a determination that the quantity of electronic devices on which the second suspicious shared library has been present exceeds the upper device threshold.

18. The system of claim 15 , wherein:

the reputation server is further configured to identify a quantity of different system executable objects that include any hook that points to the first suspicious shared library, the system executable objects reported from a plurality of clients; and

the determination that the first suspicious shared library is malicious is further based upon a determination that a plurality of different system executable objects include any hook that points to the first suspicious shared library.

19. The system of claim 15 , wherein:

the reputation server is further configured to compare a determined quantity of applications to which the first suspicious shared library has been linked against an upper application threshold; and

the determination that the first suspicious shared library is malicious is further based upon a determination that the quantity of applications to which the first suspicious shared library has been linked exceeds the upper application threshold.

20. The system of claim 15 , wherein:

the reputation server is further configured to determine whether the first suspicious shared library has been linked to no application; and

the determination that the first suspicious shared library is malicious is further based upon a determination that the first suspicious shared library has been linked to no application.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2018
From: SALLAM, AHMED SAID
To: MCAFEE, INC.
Reel/Frame 044833/0145 →
CHANGE OF NAME Recorded Feb 5, 2018
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 045249/0606 →
Continuity (3)
Continuation 14581124 · Dec 23, 2014
Continuation 12695005 · Jan 27, 2010
Related Publication 20180157836A1 · Jun 7, 2018