IP Library Granted Patent US 10,623,434
Granted Patent B1
US 10,623,434 · App. 15/912,452 · Granted Apr 14, 2020

System and method for virtual analysis of network data

Inventors: Ashar Aziz (Fremont, CA); Ramesh Radhakrishnan (Saratoga, CA); Osman Ismael (Palo Alto, CA)
Assignee: FireEye, Inc.
H04L63/1433G06F9/45533
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,623,434
App. No.
15/912,452
Granted
Apr 14, 2020
Kind
B1
Abstract

A system is provided with one or more virtual machines and a replayer. The virtual machine(s) are configured to mimic operations of a first device. The replayer is configured to mimic operations of a second device. Herein, the replayer receives a portion of network data under analysis, dynamically modifies the portion of the network data, and transmits the modified portion of the network data to at least one virtual machine of the one or more virtual machines in accordance with a protocol sequence utilized between the first device and the second device.

Claims (36)

1. A system comprising:

one or more virtual machines configured to mimic operations of a first device; and

a replayer configured to mimic operations of a second device, the replayer to receive a portion of network data under analysis, dynamically modify the portion of the network data, and control transmission of the modified portion of the network data to at least one virtual machine of the one or more virtual machines to be conducted in accordance with communications that would be utilized between the first device and the second device,

wherein the replayer is configured to mimic operations of the second device by at least dynamically modifying one or more session variables in one or more packets within the portion of the network data to emulate network communications.

2. The system of claim 1 , wherein the replayer is configured to replay the communications being a network communication session associated with a protocol sequence.

3. The system of claim 1 , wherein network data includes a data flow.

4. The system of claim 3 , wherein the one or more session variables include a session identifier to identify a communication session associated with the network data.

5. The system of claim 3 further comprising a heuristic module that is configured to determine whether network data analyzed by the heuristic module is suspicious and to provide to the replayer the portion of the network data being a part of the data flow that is determined to be suspicious.

6. The system of claim 1 , wherein the one or more virtual machines is configured to mimic operations of the first device representing a first computing system processing a browser application that issues requests to access information from a web server.

7. The system of claim 6 , wherein the replayer mimics operations of the second device representing a second computing system operating as the web server.

8. The system of claim 1 , wherein the replayer is configured to dynamically modify information within a response to a request initiated from a virtual machine of the one or more virtual machines to maintain the communications between the replayer and the virtual machine.

9. The system of claim 8 , wherein the information dynamically modified by the replayer includes a destination address.

10. The system of claim 1 further comprising a virtual switch that simulates a communication network between the replayer and the one or more virtual machines and routes data packets associated with the network data to predetermined ports of the one or more virtual machines.

11. The system of claim 1 , wherein the session variables include one or more variables dynamic to each protocol session.

12. The system of claim 11 , wherein the session variables include at least a dynamically assigned port.

13. The system of claim 11 , wherein the session variables include at least a transaction identifier.

14. The system of claim 3 , wherein a configuration of a virtual machine of the one or more virtual machines is based on an analysis of a packet format of the data flow being data that is transmitted from the first device to the second device.

15. The system of claim 3 , wherein a configuration of a virtual machine of the one or more virtual machines is based on an analysis of a packet format of the data flow being data that is transmitted from the second device to the first device.

16. The system of claim 1 , wherein a configuration of a virtual machine of the one or more virtual machines corresponds to one or more features of the second device that are affected by the network data.

17. The system of claim 16 , wherein the features of the second device include at least one of (i) ports that are to receive the network data or (ii) one or more device drivers that are to respond to the network data.

18. The system of claim 1 , wherein operations of the one or more virtual machines that virtually process the modified portion of the network data are monitored for unauthorized activity.

19. The system of claim 18 , wherein the unauthorized activity is detected by comparing a sequence of activities conducted by the one or more virtual machines against a predetermined sequence of activities.

20. The system of claim 19 , wherein the unauthorized activity is detected when the sequence of activities conducted by the one or more virtual machines includes one or more packets in addition to a sequence of packets expected to be generated by the one or more virtual machines.

21. A system comprising:

a virtual machine configured to mimic operations of a first device; and

a replayer configured to mimic operations of a second device, the replayer to receive a portion of network data under analysis, dynamically modify the portion of the network data, and control transmission of the modified portion of the network data to the virtual machine to be conducted in accordance with communications utilized between the first device and the second device,

wherein the replayer is configured to mimic operations of the second device by at least dynamically modifying one or more session variables within one or more packets of the network data to emulate network communications between the replayer and the virtual machine.

22. The system of claim 21 , wherein the one or more session variables include a session identifier to identify a communication session associated with the portion of the network data.

23. The system of claim 21 , wherein the one or more session variables include one or more variables dynamic for each communication session associated with the portion of the network data.

24. The system of claim 21 , wherein the one or more session variables include at least a dynamically assigned port.

25. The system of claim 21 , wherein the one or more session variables include at least a transaction identifier.

26. The system of claim 21 further comprising a heuristic module that is configured to determine whether network data analyzed by the heuristic module is suspicious and to provide to the replayer the portion of the network data that is determined to be suspicious.

27. The system of claim 21 , wherein the virtual machine is configured to mimic operations of the first device representing a first computing system processing a browser application that issues requests to access information from a web server.

28. The system of claim 27 , wherein the replayer mimics operations of the second device representing a second computing system operating as the web server.

29. The system of claim 21 , wherein the replayer is configured to dynamically modify information within a response to a request initiated from the virtual machine to maintain the communications between the replayer and the virtual machine.

30. The system of claim 29 , wherein the information dynamically modified by the replayer includes a destination address.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063113/0150 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0140 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2020
From: AZIZ, ASHAR; RADHAKRISHNAN, RAMESH; ISMAEL, OSMAN
To: FIREEYE, INC.
Reel/Frame 051968/0330 →
Cited By (2)
US 12,363,145 US 12,445,458