IP Library Granted Patent US 10,652,273
Granted Patent B2
US 10,652,273 · App. 15/906,383 · Granted May 12, 2020

Mitigation of anti-sandbox malware techniques

Inventor: Chris Douglas Kraft (Vancouver, CA)
Assignee: Sophos Limited
H04L63/145G06F21/53G06F21/562G06F21/563G06F21/564G06F21/565G06F21/566G06F21/577H04L63/0236H04L63/1416G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,652,273
App. No.
15/906,383
Granted
May 12, 2020
Kind
B2
Abstract

Static analysis is applied to unrecognized software objects in order to identify and address potential anti-sandboxing techniques. Where static analysis suggests the presence of any such corresponding code, the software object may be forwarded to a sandbox for further analysis. In another aspect, multiple types of sandboxes may be provided, with the type being selected according to the type of exploit suggested by the static analysis.

Claims (34)

1. A method for configuring a sandbox for malware testing, the method comprising:

analyzing, at a threat management facility, at least one digital signature of a software object for a target endpoint to detect a known, trusted software object that can be executed without further analysis, the at least one digital signature verifying an origin of the software object;

when the software object is determined to be trusted, proceeding directly to forwarding the software object from the threat management facility to an endpoint; and

when the software object is determined, based on the digital signature, to be other than trusted, performing, at the threat management facility, the steps of:

sending, to a repository of configuration information of an enterprise, a request for configuration information of the target endpoint for the software object;

receiving, in response to the request, the configuration information of the target endpoint for the software object;

configuring the sandbox to match the configuration information of the target endpoint for the software object, the sandbox instrumented to detect a known anti-sandbox malware component and the sandbox configured to disguise virtualization of the sandbox by mimicking at least one environmental variable of the target endpoint; and

forwarding the software object to the sandbox for execution.

2. The method of claim 1 , further comprising monitoring execution of the software object in the sandbox for a presence of a malicious action.

3. The method of claim 1 , wherein the configuration information includes an application configuration.

4. The method of claim 1 , wherein the configuration information includes an operating system configuration.

5. The method of claim 1 , wherein the configuration information includes a hardware configuration.

6. The method of claim 1 , wherein configuring the sandbox includes creating a new virtual machine corresponding to the configuration information of the target endpoint.

7. The method of claim 1 , wherein configuring the sandbox includes installing software on a preexisting virtual machine to match a software configuration of the target endpoint.

8. A computer program product for configuring a sandbox for malware testing, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

analyzing, at a threat management facility, at least one digital signature of a software object for a target endpoint to detect a known, trusted software object that can be executed without further analysis, the at least one digital signature verifying an origin of the software object;

when the software object is determined to be trusted, proceeding directly to forwarding the software object from the threat management facility to an endpoint; and

when the software object is determined, based on the digital signature, to be other than trusted, performing, at the threat management facility, the steps of:

sending, to a repository of configuration information of an enterprise, a request for configuration information of the target endpoint for the software object;

receiving, in response to the request, the configuration information of the target endpoint for the software object;

configuring the sandbox to match the configuration information of the target endpoint for the software object, the sandbox instrumented to detect a known anti-sandbox malware component and the sandbox configured to disguise virtualization of the sandbox by mimicking at least one environmental variable of the target endpoint; and

forwarding the software object to the sandbox for execution.

9. The computer program product of claim 8 , further comprising code that performs the step of monitoring execution of the software object in the sandbox for a presence of a malicious action.

10. The computer program product of claim 8 , wherein the configuration information includes an application configuration.

11. The computer program product of claim 8 , wherein the configuration information includes an operating system configuration.

12. The computer program product of claim 8 , wherein the configuration information includes a hardware configuration.

13. The computer program product of claim 8 , wherein configuring the sandbox includes creating a new virtual machine corresponding to the configuration of the target endpoint.

14. The computer program product of claim 8 , wherein configuring the sandbox includes installing software on a preexisting virtual machine to match the configuration information of the target endpoint.

15. A system comprising:

a computing device coupled to a network, the computing device including a threat management facility;

a processor; and

a memory bearing computer executable code configured to be executed by the processor to cause the computing device to perform the steps of analyzing, at the threat management facility, at least one digital signature of a software object for a target endpoint to detect a known, trusted software object that can be executed without further analysis, the at least one digital signature verifying an origin of the software object, when the software object is determined to be trusted, proceeding directly to forwarding the software object from the threat management facility to an endpoint, and when the software object is determined, based on the digital signature, to be other than trusted, performing, at the threat management facility, the steps of sending, to a repository of configuration information of an enterprise, a request for configuration information of the target endpoint for the software object, receiving, in response to the request, the configuration information of the target endpoint for the software object, configuring a sandbox to match the configuration information of the target endpoint for the software object, the sandbox instrumented to detect a known anti-sandbox malware component and the sandbox configured to disguise virtualization by mimicking at least one environmental variable of the target endpoint, and forwarding the software object to the sandbox for execution.

16. The system of claim 15 , wherein the configuration information includes one or more of an application configuration, an operating system configuration, and a hardware configuration.

17. The system of claim 15 , wherein configuring the sandbox includes creating a new virtual machine corresponding to the configuration information of the target endpoint.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2018
From: KRAFT, CHRIS DOUGLAS
To: SOPHOS LIMITED
Reel/Frame 045090/0216 →