IP Library Granted Patent US 11,552,962
Granted Patent B2
US 11,552,962 · App. 16/128,953 · Granted Jan 10, 2023

Computer assisted identification of intermediate level threats

Inventors: Joshua Daniel Saxe (Washington, DC); Andrew J. Thomas (Oxfordshire, GB); Russell Humphries (Horley, GB); Simon Neil Reed (Wokingham, GB); Kenneth D. Ray (Seattle, WA); Joseph H. Levy (Farmington, UT)
Assignee: Sophos Limited
H04L63/1416G06F9/542G06F11/079G06F16/955G06F17/18G06F21/554G06F21/56G06F21/562G06F21/565G06K9/6223G06K9/6256G06K9/6263G06K9/6274G06N5/003G06N5/022G06N5/04G06N5/046G06N7/00G06N20/00G06N20/20G06Q10/0635G06Q10/06395G06V10/457G06V20/52H04L63/0227H04L63/0263H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,962
App. No.
16/128,953
Filed
Sep 12, 2018
Granted
Jan 10, 2023
Kind
B2
Art Unit
2124
USPC
706/12
Abstract

An ensemble of detection techniques are used to identify code that presents intermediate levels of threat. For example, an ensemble of machine learning techniques may be used to evaluate suspiciousness based on binaries, file paths, behaviors, reputations, and so forth, and code may be sorted into safe, unsafe, intermediate, or any similar categories. By filtering and prioritizing intermediate threats with these tools, human threat intervention can advantageously be directed toward code samples and associated contexts most appropriate for non-automated responses.

Claims (33)

1. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

providing a training set including threat samples that are known to be safe and known to be malicious;

tagging each one of the threat samples with one or more tags that identify corresponding, observed behavior;

training a first machine learning model to identify malicious code in the training set based on the one or more tags;

training a second machine learning model to identify malicious code in the training set based on a corresponding file path for each of the threat samples;

training a third machine learning model to identify malicious code in the training set based on one or more Uniform Resource Locators contained in each of the threat samples;

creating an integrative model that evaluates a probability that an unknown threat sample is malicious based on a combination of the first machine learning model, the second machine learning model and the third machine learning model; and

conditionally presenting a new threat sample for human intervention when the probability calculated by the integrative model identifies the new threat sample as an intermediate threat that fails to fall within a first predetermined threshold of likely safe or within a second predetermined threshold of likely malicious.

2. The computer program product of claim 1 further comprising code that performs the step of displaying a plurality of intermediate threats, each failing to fall within the first predetermined threshold and the second predetermined threshold, in a user interface, the plurality of intermediate threats ranked according to likelihood of threat.

3. The computer program product of claim 2 wherein the plurality of intermediate threats are ranked according to a combination of likelihood of threat and estimated business value.

4. The computer program product of claim 2 wherein the user interface includes one or more controls for receiving a manual threat evaluation for one of the plurality of intermediate threats from a user.

5. A method comprising:

creating an integrative model that evaluates a potential threat by a threat sample based on a combination of a first model configured to identify malicious code based on behavioral tags, a second model configured to identify malicious code based on an executable file path, and a third model configured to identify malicious code based on a Uniform Resource Locator within the threat sample;

configuring a threat management facility to identify a new threat sample as an intermediate threat when the new threat sample is not within a predetermined confidence level of safe code or malicious code according to the integrative model; and

providing a user interface for presenting the new threat sample with the intermediate threat for human evaluation.

6. The method of claim 5 wherein the user interface presents the new threat sample in a list of a number of intermediate threats detected on an endpoint ranked according to a likelihood of threat.

7. The method of claim 5 wherein the user interface presents the new threat sample in a list of a number of intermediate threats detected in an enterprise network ranked according to a likelihood of threat.

8. The method of claim 7 wherein the list is ranked according to a combination of a likelihood of threat and an estimated business value of one or more files associated with each one of the intermediate threats.

9. The method of claim 5 wherein the first model includes a machine learning model trained to identify code with malicious behavior using a training set including threat samples that are known to be safe and known to be malicious.

10. The method of claim 5 wherein the second model includes a machine learning model trained to identify potentially malicious code based on a file path using a training set including threat samples that are known to be safe and known to be malicious.

11. The method of claim 5 wherein the third model includes a machine learning model trained to identify potentially malicious code based on a Uniform Resource Locator associated with the threat sample using a training set including threat samples that are known to be safe and known to be malicious.

12. The method of claim 5 wherein the integrative model evaluates the potential threat based at least in part on a context for the threat sample.

13. The method of claim 12 wherein the context includes a reputation for the threat sample.

14. The method of claim 12 wherein the context includes a user executing a process associated with the threat sample.

15. The method of claim 12 wherein the context includes one or more files accessed by the threat sample.

16. The method of claim 5 wherein the user interface includes one or more tools for remediating a threat associated with the threat sample.

17. The method of claim 5 wherein the user interface includes one or more tools for receiving a user evaluation of the threat sample.

18. A system comprising:

a memory storing an integrative model configured to evaluate a potential threat by a threat sample based on a combination of a first model configured to identify malicious code based on behavioral tags, a second model configured to identify malicious code based on an executable file path, and a third model configured to identify malicious code based on a Uniform Resource Locator within the threat sample;

a threat management facility configured to apply the integrative model to a new threat sample and to identify a new threat sample as an intermediate threat; and

a web server configured to display the intermediate threat in a user interface on an endpoint for evaluation.

19. The system of claim 18 wherein the web server is configured to present additional contextual information for the intermediate threat to a user through the user interface.

20. The system of claim 18 wherein the web server is configured to receive an evaluation of the intermediate threat from a user through the user interface.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2019
From: SAXE, JOSHUA DANIEL; THOMAS, ANDREW J.; HUMPHRIES, RUSSELL; REED, SIMON NEIL; RAY, KENNETH D.; LEVY, JOSEPH H.
To: SOPHOS LIMITED
Reel/Frame 048265/0243 →
Continuity (2)
Provisional Application 62726174 · Aug 31, 2018
Related Publication 20200074336A1 · Mar 5, 2020