IP Library Granted Patent US 10,846,405
Granted Patent B1
US 10,846,405 · App. 16/011,962 · Granted Nov 24, 2020

Systems and methods for detecting and protecting against malicious software

Inventors: Mircea Ciubotariu (Culver City, CA); Dumitru Stama (Marina Del Rey, CA)
Assignee: NORTONLIFELOCK INC.
G06F21/566G06F9/455G06F21/53G06F21/554G06F21/565
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,846,405
App. No.
16/011,962
Granted
Nov 24, 2020
Kind
B1
Abstract

The disclosed computer-implemented method for detecting and protecting against malicious software may include loading an untrusted application having a defined entry point into an emulated computing environment, executing a first instance of the untrusted application in the emulated computing environment beginning at the defined entry point, executing a second instance of the untrusted application beginning at a second entry point downstream from the defined entry point so as to bypass at least a portion of the untrusted application executed in the first instance, identifying the untrusted application as a potential threat based on information extracted from the second instance of the untrusted application, and performing a security action to protect against the untrusted application identified as a threat. Various other methods, systems, and computer-readable media are also disclosed.

Claims (46)

1. A computer-implemented method for detecting and protecting against malicious software, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

loading an untrusted application into an emulated computing environment, the untrusted application having a defined entry point;

executing a first instance of the untrusted application in the emulated computing environment beginning at the defined entry point;

identifying, by analyzing a plurality of additional entry points of the untrusted application, an additional entry point that is likely to trigger a payload;

prioritizing the additional entry point over other additional entry points for execution as a second entry point;

executing a second instance of the untrusted application beginning at the second entry point that is downstream from the defined entry point so as to bypass at least a portion of the untrusted application executed in the first instance;

identifying the untrusted application as a threat based on information extracted from the second instance of the untrusted application; and

performing a security action to protect against the untrusted application identified as a threat.

2. The computer-implemented method of claim 1 , further comprising:

analyzing the untrusted application for heuristic hints to identify the second entry point.

3. The computer-implemented method of claim 2 , wherein the heuristic hints comprise at least one of string concatenations, strings composed from hexadecimal codes, abnormal code constructs, and variable name entropy.

4. The computer-implemented method of claim 1 , further comprising:

prioritizing one of the other additional entry points for execution as a third entry point;

executing a third instance of the untrusted application at the third entry point downstream from the defined entry point and upstream of the second entry point, wherein, based on priority, the third instance is executed at the third entry point subsequent to execution of the second instance at the second entry point.

5. The computer-implemented method of claim 1 , wherein the first instance of the untrusted application terminates prior to running a payload and the second instance of the untrusted application runs the payload.

6. The computer-implemented method of claim 1 , wherein identifying the untrusted application as a threat comprises at least one of identifying suspicious behavior of the untrusted application, identifying unpacking of malicious code, identifying the generation of autorun files, and identifying attempts to alter system files.

7. The computer-implemented method of claim 1 , wherein the untrusted application is a script comprising statements, wherein the second entry point comprises the beginning of a statement.

8. The computer-implemented method of claim 1 , wherein the second entry point comprises an application programming interface import location in a portable executable.

9. A system for detecting malicious software, the system comprising:

at least one physical processor;

physical memory comprising computer-executable instructions that, when executed by the physical processor, cause the at least one physical processor to:

load an untrusted application into an emulated computing environment, the untrusted application having a defined entry point;

execute a first instance of the untrusted application in the emulated computing environment beginning at the defined entry point;

identify, by analyzing a plurality of additional entry points of the untrusted application, an additional entry point that is likely to trigger a payload;

prioritize the additional entry point over other additional entry points for execution as a second entry point;

execute a second instance of the untrusted application beginning at the second entry point that is downstream from the defined entry point so as to bypass at least a portion of the untrusted application executed in the first instance; and

identify the untrusted application as a threat based on information extracted from the second instance of the untrusted application.

10. The system of claim 9 , wherein the computer executable instructions further cause the at least one physical processor to analyze the untrusted application for heuristic hints to determine the second entry point.

11. The system of claim 10 , wherein the heuristic hints comprise at least one of string concatenations, strings composed from hexadecimal codes, abnormal code constructs, and variable name entropy.

12. The system of claim 9 , wherein the computer executable instructions further cause the at least one physical processor to load a script comprising statements, wherein a statement is used as the second entry point to the script.

13. The system of claim 9 , wherein the computer executable instructions further cause the at least one physical processor to load a portable executable beginning at a second entry point comprising an application programming interface import location.

14. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

load an untrusted application into an emulated computing environment, the untrusted application having a defined entry point;

execute a first instance of the untrusted application in the emulated computing environment beginning at the defined entry point;

identify, by analyzing a plurality of additional entry points of the untrusted application, an additional entry point that is likely to trigger a payload;

prioritize the additional entry point over other additional entry points for execution as a second entry point;

execute a second instance of the untrusted application beginning at the second entry point downstream from the defined entry points as to bypass at least a portion of the untrusted application executed in the first instance; and

identify the untrusted application as a threat based on information extracted from the second instance of the untrusted application.

15. The non-transitory computer-readable medium of claim 14 , wherein the computer-executable instructions further cause the computing device to:

analyze the untrusted application for heuristic hints to determine the second entry point.

16. The non-transitory computer-readable medium of claim 15 , wherein the heuristic hints are selected from the group consisting of string concatenations, strings composed from hexadecimal codes, abnormal code constructs, and variable name entropy.

17. The non-transitory computer-readable medium of claim 14 , wherein the computer-executable instructions further cause the computing device to:

execute a third instance of the untrusted application at a third entry point downstream from the defined entry point and the second entry point.

18. The non-transitory computer-readable medium of claim 14 , wherein the first instance of the untrusted application terminates prior to running a payload and the second instance of the untrusted application runs the payload.

19. The non-transitory computer-readable medium of claim 14 , wherein the untrusted application is a script comprising statements, wherein a statement is used as the second entry point.

20. The non-transitory computer-readable medium of claim 14 , wherein the second entry point comprises an application programming interface import location in a portable executable.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2018
From: CIUBOTARIU, MIRCEA; STAMA, DUMITRU
To: SYMANTEC CORPORATION
Reel/Frame 046128/0969 →
Cited By (2)
US 12,483,570 US 12,518,003