IP Library Granted Patent US 10,671,725
Granted Patent B2
US 10,671,725 · App. 15/926,352 · Granted Jun 2, 2020

Malicious process tracking

Inventor: Yinhong Chang (Milpitas, CA)
Assignee: DiDi Research America, LLC
G06F21/56G06F11/3466G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,671,725
App. No.
15/926,352
Granted
Jun 2, 2020
Kind
B2
Abstract

Malicious processes may be tracked by obtaining process history information of a computing device and obtaining an identification of a malicious software on the computing device. An associated process of the malicious software and actions of the associated process may be identified based on the process history information. Related processes of the associated process and actions of the related processes may be iteratively identified based on the process history information. Tracking information for the malicious software may be generated based on the associated process, the actions of the associated process, the related processes, and the actions of the related processes.

Claims (43)

1. A system for tracking malicious processes, the system comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, cause the system to perform:

obtaining process history information of a computing device;

obtaining an identification of a malicious software on the computing device;

identifying an associated process of the malicious software based on the process history information and the identification of the malicious software on the computing device, wherein the associated process creates a file or registry;

identifying actions of the associated process based on the process history information;

iteratively identifying one or more related processes that have interacted with the file or registry created by the associated process and actions of the one or more related processes based on the process history information;

generating tracking information for the malicious software based on the associated process, the actions of the associated process, the one or more related processes, and the actions of the one or more related processes, wherein the tracking information is represented in a graph comprising nodes for the actions of the associated process, the one or more related processes, and the actions of the one or more related processes; and

filtering the graph based on expected operations of the computing device.

2. The system of claim 1 , wherein generating the tracking information for the malicious software includes filtering the graph based on identification of non-malicious operations.

3. The system of claim 1 , wherein the instructions further cause the system to perform providing a trace of the malicious software based on the tracking information.

4. The system of claim 1 , wherein the instructions further cause the system to perform removing the malicious software from the computing device based on the tracking information.

5. The system of claim 1 , wherein:

the one or more processors are included within a server of a network and the computing device is a node of the network; and

the process history information is periodically generated by the computing device and provided to the server over the network.

6. The system of claim 1 , wherein iteratively identifying one or more related processes includes, for a network communication made by an identified process, searching for processes that have made similar network communications.

7. The system of claim 1 , wherein iteratively identifying one or more related processes includes, for an identified process which is a service, searching for processes that wrote one or more registry keys associated with the service.

8. A method for tracking malicious processes, the method implemented by a computing system including one or more processors and non-transitory storage media storing machine-readable instructions, the method comprising:

obtaining process history information of a computing device;

obtaining an identification of a malicious software on the computing device;

identifying an associated process of the malicious software based on the process history information and the identification of the malicious software on the computing device, wherein the associated process creates a file or registry;

identifying actions of the associated process based on the process history information;

iteratively identifying one or more related processes that have interacted with the file or registry created by the associated process and actions of the one or more related processes based on the process history information;

generating tracking information for the malicious software based on the associated process, the actions of the associated process, the one or more related processes, and the actions of the one or more related processes, wherein the tracking information is represented in a graph comprising nodes for the actions of the associated process, the one or more related processes, and the actions of the one or more related processes; and

filtering the graph based on expected operations of the computing device.

9. The method of claim 8 , wherein generating the tracking information for the malicious software includes filtering the graph based on identification of non-malicious operations.

10. The method of claim 8 , further comprising providing a trace of the malicious software based on the tracking information.

11. The method of claim 8 , further comprising removing the malicious software from the computing device based on the tracking information.

12. The method of claim 8 , wherein:

the one or more processors are included within a server of a network and the computing device is a node of the network; and

the process history information is periodically generated by the computing device and provided to the server over the network.

13. The method of claim 8 , wherein iteratively identifying one or more related processes includes:

for a network communication made by an identified process, searching for processes that have made similar network communications; and

for an identified process which is a service, searching for processes that wrote one or more registry keys associated with the service.

14. A non-transitory computer readable medium for tracking malicious processes, the non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform:

obtaining process history information of a computing device;

obtaining an identification of a malicious software on the computing device;

identifying an associated process of the malicious software based on the process history information and the identification of the malicious software on the computing device, wherein the associated process creates a file or registry;

identifying actions of the associated process based on the process history information;

iteratively identifying one or more related processes that have interacted with the file or registry created by the associated process and actions of the one or more related processes based on the process history information;

generating tracking information for the malicious software based on the associated process, the actions of the associated process, the one or more related processes, and the actions of the one or more related processes, wherein the tracking information is represented in a graph comprising nodes for the actions of the associated process, the one or more related processes, and the actions of the one or more related processes; and

filtering the graph based on expected operations of the computing device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2020
From: DIDI (HK) SCIENCE AND TECHNOLOGY LIMITED
To: BEIJING DIDI INFINITY TECHNOLOGY AND DEVELOPMENT CO., LTD.
Reel/Frame 053180/0456 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2020
From: DIDI RESEARCH AMERICA, LLC
To: DIDI (HK) SCIENCE AND TECHNOLOGY LIMITED
Reel/Frame 053081/0934 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2018
From: CHANG, YINHONG
To: DIDI RESEARCH AMERICA, LLC
Reel/Frame 045289/0518 →
Continuity (1)
Related Publication 20190294788A1 · Sep 26, 2019