IP Library Granted Patent US 11,368,475
Granted Patent B1
US 11,368,475 · App. 16/231,074 · Granted Jun 21, 2022

System and method for scanning remote services to locate stored objects with malware

Inventor: Sai Vashisht (Morgan Hill, CA)
Assignee: FireEye Security Holdings US LLC
H04L63/1425G06F16/9535H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,368,475
App. No.
16/231,074
Granted
Jun 21, 2022
Kind
B1
Abstract

A system and method for retrieval and analysis of stored objects for malware is described. The method involves receiving a scan request message from a customer to conduct analytics on one or more objects stored within a third-party controlled service. In response to receipt of the scan request message, the system generates a redirect message. The redirect message redirects the customer to an authentication portal of the third-party controlled service operating as a logon page and configures receipt by the system of access credentials for the third-party controlled service upon verification of the customer. Using the access credentials, the system is able to retrieve the one or more objects using the access credentials and performing analytics on each object of the one or more objects to classify each object as malicious or benign.

Claims (27)

1. A system for detecting objects stored at a remote service, comprising:

a processor; and

a memory communicatively coupled to the processor, the memory includes

content fulfillment logic to (i) receive a scan request message directed to conducting analytics on content within the remote service by at least obtaining credentials for retrieval of a plurality of objects from the remote service and (ii) generate a redirect message in response to the scan request message, the redirect message (a) redirecting communications from a customer to an authentication portal of a third-party controlled service operating as a logon page and (b) configuring receipt of access credentials for the third-party controlled service upon verification of the customer; and

back-end logic to (i) retrieve one or more objects of the plurality of objects using the access credentials, and (ii) perform analytics on each object of the one or more objects to classify each object as malicious or benign by at least (a) analyzing a first object to determine whether the first object includes characteristics that lead to further analyses in order to classify the first object as malicious or benign, (b) selecting one or more analytic engines based on meta-information associated with the first object, wherein each of the one or more analytic engines separately analyzes the first object for malware to produce an analytic result, (c) collecting the analytic results from the one or more analytic engines, and (iv) classifying the first object as malicious or benign based on the collected analytic results.

2. The system of claim 1 , wherein the content fulfillment logic to gain access to the content being a plurality of electronic mail (email) messages stored within the remote service operating as an cloud-based email service.

3. The system of claim 1 , wherein the content fulfillment logic to gain access to the content being a plurality of files stored within a cloud-based file data store.

4. The system of claim 1 , wherein the content fulfillment logic to (i) receive as input a scan request message, (ii) return as output a redirect message to an authorization portal controlling access to the remote service, and (iii) receive a credential token permitting the system access to the remote service.

5. The system of claim 1 , wherein the analytic result produced by each of the one or more analytic engines includes meta-information resulting from analysis of the first object within a first analytics engine of the one or more analytic engines.

6. The system of claim 1 , wherein the content fulfillment logic to further perform a preliminary analysis of the plurality of objects to eliminate objects unlikely to be malicious to create a subset of the plurality of objects.

7. The system of claim 1 , wherein the memory further comprises down filtering logic to reduce a number of objects, including the first object, prior to submission of at least the first object to the back-end logic and analysis by the one or more analytic engines selected based on meta-information accompanying the first object.

8. The system of claim 7 , wherein the memory further comprises reporting logic communicatively coupled to classification logic within the back-end logic to classify the first object as either malicious or benign based on the collected analytic results, the reporting logic to generate a report including at least a portion of the meta-information associated with the first object.

9. A computerized method for retrieval and analysis of stored objects for malware, the method comprising:

receiving a scan request message from a customer to conduct analytics on one or more objects stored within a third-party controlled service;

generating a redirect message in response to the scan request message, the redirect message (i) redirecting communications from the customer to an authentication portal of the third-party controlled service operating as a logon page and (ii) configuring receipt of access credentials for the third-party controlled service upon verification of the customer;

retrieving the one or more objects using the access credentials; and

performing analytics on each object of the one or more objects to classify each object as malicious or benign by at least (i) analyzing a first object to determine whether the first object includes characteristics that lead to further analyses in order to classify the first object as malicious or benign, (ii) selecting one or more analytic engines based on meta-information associated with the first object, wherein each of the one or more analytic engines separately analyzes the first object for malware to produce an analytic result, (iii) collecting the analytic results from the one or more analytic engines, and (iv) classifying the first object as malicious or benign based on the collected analytic results.

10. The computerized method of claim 9 , wherein the redirect message includes (i) a Uniform Resource Locator (URL) link that, upon selection, redirects communications to the authentication portal of the third-party controlled service and (ii) address information used by the third-party controlled service to return a credential token operating as the access credentials upon verification of the customer.

11. The computerized method of claim 10 , wherein the third-party controlled service corresponds to an cloud-based email service and the one or more objects corresponding to one or more email messages stored within the cloud-based email service.

12. The computerized method of claim 10 , wherein the authentication portal of the third-party controlled service operates as the logon page for a trusted third-party web service account.

13. The computerized method of claim 9 , wherein at least one of the characteristics includes a presence of a Uniform Resource Locator (URL) link in a body portion of an email message being the first object.

14. The computerized method of claim 9 , wherein at least one of the characteristics for the first object being an email message includes a presence of an attachment to the email message being less than a prescribed memory size.

15. The computerized method of claim 9 , wherein the selecting of the one or more analytic engines based on the meta-information that is collected during the analyzing of characteristics of the first object and during retrieval of the first object from the third-party controlled service.

16. The computerized method of claim 9 , wherein the collecting of the analytic results from the one or more analytic engines includes aggregating the analytics results in accordance with a first prescribed format based on an identifier representing a first customer type and aggregating the analytics results in accordance with a second prescribed format based on an identifier representing a second customer type, wherein the first prescribed format differs from the second prescribed format.

17. The computerized method of claim 16 , wherein the aggregating of the analytics results in accordance with the first prescribed format being more comprehensive than the aggregating of the analytics results in accordance with the second prescribed format when the first customer type corresponds to an incident response provider being different than the second customer type.

18. The computerized method of claim 11 further comprising:

generating a malware detection report including one or more entries for each object of the one or more objects being classified as malicious, the one or more entries include at least an identifier of the customer and an identifier of a source of each email message of the one or more email messages.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063272/0743 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0029 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2019
From: VASHISHT, SAI
To: FIREEYE, INC.
Reel/Frame 047935/0425 →
Cited By (3)
US 12,294,611 US 12,375,475 US 12,689,603