IP Library Granted Patent US 11,238,154
Granted Patent B2
US 11,238,154 · App. 16/503,859 · Granted Feb 1, 2022

Multi-lateral process trees for malware remediation

Inventors: Jonathan L. Edwards (Portland, OR); Saurabh Gautam (Cork, IE); Dhananjay Kumar (Cork, IE); Joel R. Spurlock (Portland, OR)
Assignee: McAfee, LLC
G06F21/554G06F21/568G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,238,154
App. No.
16/503,859
Granted
Feb 1, 2022
Kind
B2
Abstract

There is disclosed in one example a computing apparatus, including: a processor and a memory; and instructions encoded within the memory to instruct the processor to provide a security agent to: identify a malicious process; construct a genealogical process tree of the malicious process, the genealogical process tree including both vertical direct inheritance and horizontal indirect inheritance relationships; and terminate the malicious process and at least some related processes in the genealogical process tree.

Claims (31)

1. A computing apparatus, comprising:

a processor and a memory; and

instructions encoded within the memory to instruct the processor to provide a security agent to:

identify a malicious process;

construct a genealogical process tree of the malicious process, the genealogical process tree including both vertical direct inheritance and horizontal indirect inheritance relationships, wherein horizontal indirect inheritance relationships include a first object or process that was scheduled to run by a different object or process not a direct parent of the first object or process; and

terminate the malicious process and at least some related processes in the genealogical process tree.

2. The computing apparatus of claim 1 , wherein the security agent is to identify horizontal relationships by identifying non-linear relationships, in which a first process indirectly causes a second process to be spawned by a third process.

3. The computing apparatus of claim 1 , wherein terminating at least some related processes comprises terminating all processes that are vertical and horizontal descendants of the malicious process.

4. The computing apparatus of claim 1 , wherein terminating at least some related processes comprises terminating at least one vertical parent of the malicious process.

5. The computing apparatus of claim 1 , wherein the security agent is further to identify and roll back changes made by the malicious process or by a related process.

6. The computing apparatus of claim 5 , wherein rolling back changes comprises identifying sources of persistency for the malware and eliminating the sources of persistency.

7. The computing apparatus of claim 6 , wherein eliminating sources of persistency comprises eliminating autorun or scheduled task entries.

8. The computing apparatus of claim 1 , wherein the security agent is further to trigger an analysis of one or more newly-identified files.

9. The computing apparatus of claim 8 , wherein the security agent is further to identify at least one file or process as suspicious, and to initiate further analysis of the suspicious file or process.

10. The computing apparatus of claim 9 , wherein the security agent is further to insert operating system hooks into the suspicious file or process to assist in constructing the genealogical process tree.

11. The computing apparatus of claim 1 , wherein the security agent is further to trim whitelisted processes from the genealogical process tree.

12. The computing apparatus of claim 1 , wherein the security agent is further configured to select a root process trusted to not be malicious, and to not terminate processes vertically at or above the root process.

13. One or more tangible, non-transitory computer-readable storage media having stored thereon executable instructions to provide a security agent configured to:

determine that a running process is malicious;

construct a process graph of the malicious process, the process graph comprising direct parent-child relationships of directly-spawned processes, indirect parent-child relationships, and non-linear relationships wherein a first process scheduled a second process to be spawned indirectly, creating an indirect parent-child relationship wherein the first process is not a direct parent of the second process; and

terminate the malicious process, direct children of the malicious process, and indirect children of the malicious process.

14. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the security agent is further to terminate at least one direct parent of the malicious process.

15. The one or more tangible, non-transitory computer-readable media of claim 14 , wherein the security agent is further to report the malware to a security server, including providing a story graph.

16. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the security agent is further to trim from the genealogical process tree processes with minimal security implications, and branches lacking malicious activity.

17. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the security agent is further to provide a full monitoring mode, the full monitoring mode to store sufficient data to fully roll back changes made by the malicious process.

18. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the security agent is further to provide a partial monitoring mode, the partial monitoring mode to track newly created files by the malicious process.

19. A computer-implemented method of remedying activity by a malicious process, comprising:

determining observationally and/or heuristically that the malicious process is malware;

constructing a process tree for the malicious process, the process tree comprising both direct vertical parent-child relationships and indirect horizontal parent-child relationships, the horizontal relationships representing a relationship wherein a first process scheduled a second process to be spawned without spawning the second process as a direct parent; and

terminating the malicious process, vertical children of the malicious process, and horizontal children of the malicious process.

20. The method of claim 19 , further comprising identifying horizontal relationships by identifying non-linear relationships, in which a first process indirectly causes a second process to be spawned by a third process.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SIGNATURE DATE FOR THE 3RD INVENTOR, DHANANJAY KUMAR, FROM 01-07-2019 TO 07-01-2019 PREVIOUSLY RECORDED ON REEL 049676 FRAME 0096. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 4, 2020
From: EDWARDS, JONATHAN L.; GAUTAM, SAURABH; KUMAR, DHANANJAY; SPURLOCK, JOEL R.
To: MCAFEE, LLC
Reel/Frame 053743/0119 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2019
From: EDWARDS, JONATHAN L.; GAUTAM, SAURABH; KUMAR, DHANANJAY; SPURLOCK, JOEL R.
To: MCAFEE,LLC
Reel/Frame 049676/0096 →
Continuity (1)
Related Publication 20210004458A1 · Jan 7, 2021