IP Library Patent Application 16168588
Patent Application
App. No. 16/168,588

IDENTIFICATION PROCESS FOR SUSPICIOUS ACTIVITY PATTERNS BASED ON ANCESTRY RELATIONSHIP

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/168,588
Abstract

A security service system and method for using a process based on ancestry relationship as a pattern for identifying a suspicious activity, such as a possible malicious attack or malware, are described herein. The security service system identifies a trigger command in a process running on a monitored computing device, identifies an ancestry command associated with the trigger command, determines an ancestry level of the ancestry command, and upon determining that the ancestry level of the ancestry command is different from an expected ancestry level of the ancestry command for the trigger command, identify a pattern based on the trigger command, the ancestry command, and the ancestry level of the ancestry command.

Claims (67)

1 . A security service system for identifying a suspicious activity, the security service comprising:

one or more processors; and

memory coupled to the one or more processors, the memory including a plurality of modules communicatively coupled to each other and executable by the one or more processors, the plurality of modules comprising:

a data module configured to store known patterns, the known patterns including known suspicious activity patterns and known indicators of attack (IoAs);

a monitoring module configured to receive monitored data in a process running on a monitored computing device; and

an identification module configured to identify one or more suspicious activity patterns based on a comparison between the received monitored data and the known patterns.

2 . A security service system of claim 1 , wherein:

the plurality of modules further comprises a determination module configured to determine an ancestry level of an ancestry command and to determine whether the ancestry level of the ancestry command is different from an expected ancestry level of the ancestry command for a trigger command,

the identification module is further configured to identify the trigger command in the process running on the monitored computing device and to identify the ancestry command associated with the trigger command, and

the data module is further configured to store information associated with the trigger command, the ancestry command, and the ancestry level of the ancestry command as a new suspicious activity pattern.

3 . A security service system of claim 2 , wherein:

the trigger command is a trigger command of a plurality of preselected trigger commands, and

the ancestry command is an ancestry command of a plurality of preselected ancestry commands associated with the trigger command.

4 . A security service system of claim 3 , wherein the plurality of preselected ancestry commands is associated with the trigger command for the expected ancestry level.

5 . A security service system of claim 4 , wherein the plurality of the preselected ancestry commands is different from a plurality of preselected ancestry commands for a second ancestry level that is associated with the trigger command and that is different from the expected ancestry level.

6 . A security service system of claim 2 , wherein:

the plurality of modules further comprises an administrative status module configured to determine an administrative status of a user associated with the process running on the monitored computing device.

7 . A security service system of claim 6 , wherein the identification module is further configured to identify the one or more suspicious activity patterns based, in part, on a weight factor associated with the administrative status of the user.

8 . A security service system of claim 2 , wherein the plurality of modules further comprises an analysis module configured to:

determine a plurality of process trees in a plurality of connections within a specific environment to which the monitored computing device belongs,

identify a process tree of the plurality of process trees having a number of command lines less than a threshold number as a suspicious activity,

statistically analyze the process tree of the plurality of process trees for frequency of the new suspicious activity pattern; and

identify the process tree as a suspicious activity if the frequency is lower than a threshold frequency.

9 . A method for detecting a suspicious activity, the method comprising, at a security service system:

storing known patterns, the known patterns including known suspicious activity patterns and known indicators of attack (IoAs);

receiving monitored data in a process running on a monitored computing device; and

identifying one or more suspicious activity patterns based on a comparison between the received monitored data and the known patterns.

10 . A method of claim 9 , further comprising:

identifying a trigger command in the process running on the monitored computing device;

identifying an ancestry command associated with the trigger command;

determining an ancestry level of the ancestry command; and

upon determining that the ancestry level of the ancestry command is different from an expected ancestry level of the ancestry command for the trigger command, storing information associated with the trigger command, the ancestry command, and the ancestry level of the ancestry command as a new suspicious activity pattern.

11 . A method of claim 10 ,

wherein the trigger command is a trigger command of a plurality of preselected trigger commands, and

wherein the ancestry command is an ancestry command of a plurality of preselected ancestry commands associated with the trigger command.

12 . A method of claim 11 , wherein the plurality of preselected ancestry commands is associated with the trigger command for the expected ancestry level.

13 . A method of claim 12 , wherein the plurality of the preselected ancestry commands comprises a different set of ancestry commands from a plurality of preselected ancestry commands for a different ancestry level associated with the trigger command.

14 . A method of claim 10 , further comprising:

determining an administrative status of a user associated with the process running on the monitored computing device.

15 . A method of claim 14 , wherein identifying the one or more suspicious activity patterns is based, in part, on a weight factor associated with the administrative status of the user.

16 . A method of claim 10 , further comprising:

determining a plurality of process trees in a plurality of connections within a specific environment to which the monitored computing device belongs; and

identifying a process tree of the plurality of process tress having a number of command lines less than a threshold number as a suspicious activity.

17 . A method of claim 16 , wherein identifying the process tree as the suspicious activity comprises:

statistically analyzing the process tree for frequency of the new suspicious activity pattern; and

identifying the process tree as a suspicious activity if the frequency is lower than a threshold frequency.

18 . Non-transitory computer-readable media having stored thereon a plurality of programming instructions which, when executed by one or more computing devices, cause the one or more computing devices to perform operations comprising:

storing known patterns, the known patterns including known suspicious activity patterns and known indicators of attack (IoAs);

receiving monitored data in a process running on a monitored computing device; and

identifying one or more suspicious activity patterns based on a comparison between the received monitored data and the known patterns.

19 . Non-transitory computer-readable media of claim 18 , wherein the operations further comprise:

identifying a trigger command in the process running on the monitored computing device;

identifying an ancestry command associated with the trigger command;

determining an ancestry level of the ancestry command; and

upon determining that the ancestry level of the ancestry command is different from an expected ancestry level of the ancestry command for the trigger command, storing information associated with the trigger command, the ancestry command, and the ancestry level of the ancestry command as a new suspicious activity pattern.

20 . Non-transitory computer-readable media of claim 19 ,

wherein the trigger command is a trigger command of a plurality of preselected trigger commands, and

wherein the ancestry command is an ancestry command of a plurality of preselected ancestry commands associated with the trigger command.

21 . Non-transitory computer-readable media of claim 19 , wherein the plurality of preselected ancestry commands is associated with the trigger command for the ancestry level and is different from a plurality of preselected ancestry commands for a second ancestry level that is associated with the trigger command and that is different from the expected ancestry level.

22 . Non-transitory computer-readable media of claim 19 , wherein the operations further comprise:

determining an administrative status of a user associated with the process running on the monitored computing device,

wherein identifying the one or more suspicious activity patterns is based, in part, on the administrative status of the user associated with the process running on the monitored computing device, the administrative status having a weight factor.

23 . Non-transitory computer-readable media of claim 19 , wherein the operations further comprise:

determining a plurality of process trees in a plurality of connections within a specific environment to which the monitored computing device belongs;

identifying a process tree of the plurality of process trees having a number of command lines less than a threshold number as a suspicious activity; and

statistically analyzing the process tree for frequency of the new suspicious activity pattern; and

identifying the process tree as a suspicious activity if the frequency is lower than a threshold frequency.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2026
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
Reel/Frame 074202/0710 →
PATENT SECURITY AGREEMENT Recorded Jan 5, 2021
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 054899/0848 →
SECURITY INTEREST Recorded Apr 22, 2019
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.; CROWDSTRIKE SERVICES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 048953/0205 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2018
From: NGUYEN, CORY-KHOI QUANG; NISBET, BRODY; LEE, JOHN
To: CROWDSTRIKE, INC.
Reel/Frame 047283/0313 →