IP Library Granted Patent US 11,108,790
Granted Patent B1
US 11,108,790 · App. 16/398,503 · Granted Aug 31, 2021

Attack signature generation

Inventors: Paul Deardorff (Durham, NC); Dustin Myers (Alexandria, VA)
Assignee: Rapid7, Inc.
H04L63/1416G06F9/451G06F21/53H04L43/08H04L63/1425G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,790
App. No.
16/398,503
Granted
Aug 31, 2021
Kind
B1
Abstract

Methods and systems for detecting malicious activity on a network. The methods described herein involve gathering data regarding a first state of a computing environment, executing an attack tool to simulate malicious activity in the computing environment, and then gathering data regarding a second state of the computing environment. The methods described herein may then involve generating a signature based on changes between the first and second states, and then using the generated signature to detect malicious activity in a target network.

Claims (35)

1. A method for detecting malicious activity on a network, the method comprising:

gathering data regarding a first state of a computing environment;

executing at least one attack tool in the computing environment to simulate malicious activity;

gathering data regarding a second state of the computing environment after the at least one attack tool is executed;

detecting at least one trace of the malicious activity from the data regarding the second state of the computing environment by comparing the data regarding the second state of the environment to the data regarding the first state of the computing environment; and

autonomously generating at least one signature for detecting future malicious activity, wherein the at least one generated signature is based on the at least one detected trace.

2. The method of claim 1 wherein the computing environment is a sandbox environment.

3. The method of claim 1 further comprising detecting at least one difference between the first state of the computing environment and the second state of the computing environment based on the comparison, the at least one difference being the at least one trace of the malicious activity.

4. The method of claim 1 further comprising monitoring future network activity to detect activity matching the at least one generated signature, wherein activity matching the at least one generated signature indicates malicious activity.

5. The method of claim 4 further comprising issuing an alert using a user interface upon detecting activity matching the at least one generated signature.

6. The method of claim 1 wherein the signature is defined by at least one signature parameter, and the method further includes receiving a recommendation to adjust at least one signature parameter to adjust the number of generated alerts regarding detected malicious activity.

7. The method of claim 1 wherein the attack tool is defined by at least one attack parameter, and the method further includes autonomously adjusting the at least one attack parameter to generate a variance in the at least one trace of malicious activity and in the at least one generated signature.

8. The method of claim 1 wherein the at least one trace includes at least one of a modified registry key, a modified file system access permission, a modified write access permission, a modified process, a modified file, and a dropped file.

9. The method of claim 1 further comprising validating the generated signature against a historical dataset of signatures to determine whether the generated signature is associated with an anomalous amount of malicious activity compared to the historical dataset.

10. A system for detecting malicious activity on a network, the system comprising:

at least one attack tool configured to simulate malicious activity; and

a virtual security appliance configured to execute instructions stored on memory to:

gather data regarding a first state of a computing environment before the attack tool simulates the malicious activity,

gather data regarding a second state of the computing environment after the attack tool simulates the malicious activity;

detect at least one trace of the malicious activity from the data regarding the second state of the computing environment by comparing the data regarding the second state of the environment to the data regarding the first state of the computing environment, and

autonomously generate at least one signature for detecting future malicious activity, wherein the at least one generated signature is based on the at least one detected trace.

11. The system of claim 10 wherein the computing environment is a sandbox environment.

12. The system of claim 10 wherein the virtual security appliance detects the at least one difference between the first state of the computing environment and the second state of the computing environment based on the comparison, the at least one difference being the at least one trace of the malicious activity.

13. The system of claim 10 wherein the virtual security appliance is further configured to monitor future network activity to detect activity matching the at least one generated signature, wherein activity matching the at least one generated signature indicates malicious activity.

14. The system of claim 13 further comprising a user interface configured to issue an alert upon the virtual security appliance matching the at least one generated signature.

15. The system of claim 10 wherein the signature is defined by at least one signature parameter, and the virtual security appliance is configured to receive a recommendation to adjust at least one signature parameter to adjust the number of generated alerts regarding detected malicious activity.

16. The system 10 wherein the attack tool is defined by at least one attack parameter, and the virtual security appliance is further configured to autonomously adjust the at least one attack parameter to generate a variance in the at least one trace of malicious activity and in the at least one generated signature.

17. The system of claim 10 wherein the at least one trace includes at least one of a modified registry key, a modified file system access permission, a modified write access permission, a modified process, a modified file, and a dropped file.

18. The system of claim 10 wherein the virtual security appliance is further configured to validate the generated signature against a historical dataset of signatures to determine whether the generated signature is associated with an anomalous amount of malicious activity compared to the historical dataset.

19. A non-transitory computer readable medium containing computer-executable instructions for performing a method for detecting malicious activity on a network, the computer readable medium comprising:

computer-executable instructions for gathering data regarding a first state of a computing environment;

computer-executable instructions for executing at least one attack tool in the computing environment to simulate malicious activity;

computer-executable instructions for gathering data regarding a second state of the computing environment after the at least one attack tool is executed;

computer-executable instructions for detecting at least one trace of the malicious activity from the data regarding the second state of the computing environment by comparing the data regarding the second state of the environment to the data regarding the first state of the computing environment; and

computer-executable instructions for autonomously generating at least one signature for detecting future malicious activity, wherein the at least one generated signature is based on the at least one detected trace.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2019
From: DEARDORFF, PAUL; MYERS, DUSTIN
To: RAPID7, INC.
Reel/Frame 049181/0036 →
Cited By (1)
US 12,596,812