IP Library Granted Patent US 10,812,507
Granted Patent B2
US 10,812,507 · App. 16/389,132 · Granted Oct 20, 2020

System and methods for efficient combining of malware detection rules

Inventors: Marcio Castilho (Palm Harbor, FL); Alin Irimie (Clearwater, FL); Michael Hanley (Palm Harbor, FL); Daniel Cormier (Clearwater, FL); Raymond Skinner (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,812,507
App. No.
16/389,132
Granted
Oct 20, 2020
Kind
B2
Abstract

System and methods are described which are useful for efficiently combining characteristic detection rules, such as may be done to efficiently and quickly assist in the dispositioning of user reported security threats.

Claims (34)

1. A method for efficiently processing characteristic detection rules in a rule set, the method comprising;

(a) identifying, by a device, a combination rule to be applied against an electronic communication to detect characteristics of the electronic communication, the combination rule comprising a plurality of characteristic detection rules combined via one or more logical operators, each of the plurality of characteristic detection rules comprising a description of a specific characteristic based on one of a textual or binary pattern;

(b) generating, by the device, one or more identifiers for each characteristic detection rule of the plurality of characteristic detection rules to identify any characteristic detection rule of the plurality of characteristic detection rules matching the electronic communication, the identifier comprising a combination rule identifier and an index identifying a position of each characteristic detection rule within a rule set;

(c) compiling, by the device, the rule set into a compiled rule set, the rule set comprising a plurality of characteristic detection rules with the one or more identifiers for each characteristic detection rule of the plurality of characteristic detection rules;

(d) executing, by the device, the compiled rule set against the electronic communication to detect whether the electronic communication comprises a specific characteristic corresponding to the plurality of characteristic detection rules;

(e) receiving, by the device from the execution of the compiled rule set, the index from each of the identifiers for each characteristic detection rule of the plurality of characteristic detection rules that matched against the electronic communication;

(f) applying, by the device, the one or more logical operators of the combination rule based on a result of each characteristic detection rule and the index of each characteristic detection rule that matched against the electronic communication, to determine whether the combination rule matches the electronic communication;

wherein the combination rule is configured with the plurality of characteristic detection rules to detect characteristics in a predetermined portion of the electronic communication.

2. The method of claim 1 , wherein one or more of the plurality of characteristic detection rules comprises a Yet Another Recursive Algorithm (YARA) rule.

3. The method of claim 1 , wherein the identifier of the one or more identifiers comprises one of a predetermined pattern, a predetermined name, or the combination rule identifier with a predetermined tag identifier.

4. The method of claim 1 , wherein the identifier of the one or more identifiers comprises one or more of the index with the combination rule identifier, and metadata associated with the combination rule.

5. The method of claim 1 , wherein the index identifies a specific characteristic detection rule in the combination rule.

6. The method of claim 1 , wherein a first one or more of the plurality of characteristic detection rules of the combination rule is configured to detect characteristics in a first predetermined portion of the electronic communication and wherein a second one or more of the plurality of characteristic detection rules of the combination rule is configured to detect characteristics in a second predetermined portion of the electronic communication.

7. The method of claim 1 , wherein the electronic communication comprises electronic mail.

8. The method of claim 1 , wherein more than one characteristic detection rule is combined together to form a rule set.

9. The method of claim 8 , where the rule set comprises one or more characteristic detection rules that apply to one of a header of an electronic communication, a body of an electronic communication, an attachment of an electronic communication, or metadata of an electronic communication.

10. A system for more efficiently processing characteristic detection rules in a rule set, the system comprising;

a device comprising one or more processors, coupled to memory;

a combination rule accessible and identifiable by the device, the combination rule to be applied against an electronic communication to detect characteristics of the electronic communication, the combination rule comprising a plurality of characteristic detection rules combined via one or more logical operators, each of the characteristic detection comprising a description of a specific characteristic based on one of a textual or binary pattern;

wherein the device is configured to:

generate an identifier for each characteristic detection rule of the plurality of characteristic detection rules to identify any characteristic detection rule of the plurality of characteristic detection rules matching the electronic communication, the identifier comprising a combination rule identifier and a unique identifier for indexing each characteristic detection rule within each combination rule;

compile a rule set comprising the plurality of characteristic detection rules with the identifier for each characteristic detection rule of the plurality of characteristic detection rules;

execute the compiled rule set against the electronic communication to detect whether the electronic communication comprises a specific characteristic corresponding to the plurality of characteristic detection rules;

receive, from the execution of the compiled rule set, the unique identifier from each of the identifiers for each characteristic detection rule of the plurality of characteristic detection rules that matched against the electronic communication; and

apply the one or more logical operators of the combination rule based on a result of each characteristic detection rule and the unique identifier of each characteristic detection rule that matched against the electronic communication, to determine whether the combination rule matches the electronic communication;

wherein the combination rule is configured with the plurality of characteristic detection rules to detect characteristics in a predetermined portion of the electronic communication.

11. The system of claim 10 , wherein one or more of the plurality of characteristic detection rules comprises a Yet Another Recursive Algorithm (YARA) rule.

12. The system of claim 10 , wherein the identifier comprises one of a predetermined pattern, a predetermined name, or the combination rule identifier with a predetermined tag identifier.

13. The system of claim 10 , wherein the identifier comprises one or more of the combination rule identifier with a predetermined tag identifier, and metadata associated with the combination rule.

14. The system of claim 10 , wherein the identifier comprises an index with the combination rule identifier, wherein the index identifies a location of the characteristic detection rule among the plurality of characteristic detection rules in the combination rule.

15. The system of claim 10 , wherein a first one or more of the plurality of characteristic detection rules of the combination rule is configured to detect specific characteristics in a first predetermined portion of the electronic communication and wherein a second one or more of the plurality of characteristic detection rules of the combination rule is configured to detect specific characteristics in a second predetermined portion of the electronic communication.

16. The system of claim 10 , wherein the electronic communication comprises electronic mail.

17. The system of claim 10 , where more than one characteristic detection rule is combined together to form a rule set.

18. The system of claim 17 , wherein the rule set comprises one or more characteristic detection rules that apply to one of a header of the electronic communication, a body of the electronic communication, an attachment of the electronic communication, or metadata of the electronic communication.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2019
From: CASTILHO, MARCIO; IRIMIE, ALIN; HANLEY, MICHAEL; CORMIER, DANIEL; SKINNER, RAYMOND
To: KNOWBE4, INC.
Reel/Frame 048938/0038 →
Continuity (2)
Provisional Application 62780209 · Dec 15, 2018
Related Publication 20200195664A1 · Jun 18, 2020