IP Library Granted Patent US 11,057,422
Granted Patent B2
US 11,057,422 · App. 16/748,533 · Granted Jul 6, 2021

System and method for strategic anti-malware monitoring

Inventors: Marcus J. Ranum (Morrisdale, PA); Ron Gula (Marriottsville, MD)
Assignee: Tenable, Inc.
H04L63/145G06F16/903G06F21/564H04L61/1511H04L63/1416H04L63/1433H04L67/02H04L67/10G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,057,422
App. No.
16/748,533
Granted
Jul 6, 2021
Kind
B2
Abstract

The system and method described herein may leverage active network scanning and passive network monitoring to provide strategic anti-malware monitoring in a network. In particular, the system and method described herein may remotely connect to managed hosts in a network to compute hashes or other signatures associated with processes running thereon and suspicious files hosted thereon, wherein the hashes may communicated to a cloud database that aggregates all known virus or malware signatures that various anti-virus vendors have catalogued to detect malware infections without requiring the hosts to have a local or resident anti-virus agent. Furthermore, running processes and file system activity may be monitored in the network to further detect malware infections. Additionally, the network scanning and network monitoring may be used to detect hosts that may potentially be participating in an active botnet or hosting botnet content and audit anti-virus strategies deployed in the network.

Claims (62)

1. A method for detecting botnet participation in a network, comprising:

receiving, via a credentialed scan of a scanning target located in the network or from a local agent executing on the scanning target, information describing a plurality of current connections on the scanning target;

detecting that the scanning target is a participant in a botnet based on the information;

determining a topology associated with one or more compromised hosts including the scanning target that have been recruited into participation in a botnet; and

performing one or more actions to facilitate isolation of the network from botnet traffic attributable to the one or more compromised hosts.

2. The method of claim 1 , wherein the one or more actions comprise:

generating a report that identifies the one or more compromised hosts as being associated with the botnet, or

disabling network connectivity for at least the one or more compromised hosts to isolate the network from the botnet traffic, or a combination thereof.

3. The method of claim 1 , wherein the information comprises netstat information.

4. The method of claim 1 , wherein the detecting includes:

identifying one or more Internet Protocol (IP) addresses associated with each of the plurality of current connections on the scanning target; and

comparing the one or more IP addresses to a list that includes one or more known botnet IP addresses; and

determining that the scanning target is a participant in the botnet in response to at least one of the one or more IP addresses appearing in the list.

5. The method of claim 4 ,

wherein the identifying identifies a source IP address and a destination IP address associated with each of the plurality of current connections on the scanning target,

wherein the comparing compares the source IP address and the destination IP address to the list, and

wherein the botnet determination is based on one or more of the source IP address or the destination IP address appearing in the list.

6. The method recited in claim 1 , wherein the detecting detects that the scanning target is a participant in the botnet in response to information describing traffic associated with at least one connection observed in the network (i) indicating that the at least one connection has a source Internet Protocol (IP) address or a destination IP address that appears in a list that includes one or more known botnet IP addresses, or (ii) indicating that the traffic includes a query to a domain name system (DNS) IP address that appears in the list.

7. The method of claim 6 , further comprising:

determining whether the detected participation in the botnet originated from a malicious external IP address associated with the botnet or an internal host that reached out to the malicious external IP address associated with the botnet based on the information describing the traffic associated with the at least one connection.

8. A system for detecting botnet participation in a network, comprising:

a memory; and

one or more processors coupled to the memory and configured to:

receive, via a credentialed scan of a scanning target located in the network or from a local agent executing on the scanning target, information describing a plurality of current connections on the scanning target;

detect that the scanning target is a participant in a botnet based on the information;

determine a topology associated with one or more compromised hosts including the scanning target that have been recruited into participation in the botnet; and

perform one or more actions to facilitate isolation of the network from botnet traffic attributable to the one or more compromised hosts.

9. The system of claim 8 , wherein the one or more actions comprise:

generating a report that identifies the one or more compromised hosts as being associated with the botnet, or

disabling network connectivity for at least the one or more compromised hosts to isolate the network from the botnet traffic, or

a combination thereof.

10. The system of claim 8 , wherein the information comprises netstat information.

11. The system of claim 8 , wherein the one or more processors are configured to detect that the scanning target is a participant in the botnet by:

identifying one or more Internet Protocol (IP) addresses associated with each of the plurality of current connections on the scanning target; and

comparing the one or more IP addresses to a list that includes one or more known botnet IP addresses; and

determining that the scanning target is a participant in the botnet in response to at least one of the one or more IP addresses appearing in the list.

12. The system of claim 11 ,

wherein the one or more IP addresses comprise a source IP address and a destination IP address associated with each of the plurality of current connections on the scanning target,

wherein the one or more processors are configured to compare the source IP address and the destination IP address to the list, and

wherein the botnet determination is based on one or more of the source IP address or the destination IP address appearing in the list.

13. The system of claim 8 , wherein the one or more processors are configured to detect that the scanning target is a participant in the botnet in response to information describing traffic associated with at least one connection observed in the network (i) indicating that the at least one connection has a source Internet Protocol (IP) address or a destination IP address that appears in a list that includes one or more known botnet IP addresses, or (ii) indicating that the traffic includes a query to a domain name system (DNS) IP address that appears in the list.

14. The system of claim 13 , wherein the one or more processors are further configured to determine whether the detected participation in the botnet originated from a malicious external IP address associated with the botnet or an internal host that reached out to the malicious external IP address associated with the botnet based on the information describing the traffic associated with the at least one connection.

15. A non-transitory computer-readable storage medium having computer-executable instructions stored thereon for detecting botnet participation in a network, wherein executing the computer-executable instructions by one or more processors causes the one or more processors to:

receive, via a credentialed scan of a scanning target located in the network or from a local agent executing on the scanning target, information describing a plurality of current connections on the scanning target;

detect that the scanning target is a participant in a botnet based on the information;

determine a topology associated with one or more compromised hosts including the scanning target that have been recruited into participation in the botnet; and

perform one or more actions to facilitate isolation of the network from botnet traffic attributable to the one or more compromised hosts.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more actions comprise:

generating a report that identifies the one or more compromised hosts as being associated with the botnet, or

disabling network connectivity for at least the one or more compromised hosts to isolate the network from the botnet traffic, or

a combination thereof.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the information comprises netstat information.

18. The non-transitory computer-readable storage medium of claim 15 , wherein executing the computer-executable instructions by the one or more processors further causes the one or more processors to detect that the scanning target is a participant in the botnet by:

identifying one or more Internet Protocol (IP) addresses associated with each of the plurality of current connections on the scanning target; and

comparing the one or more IP addresses to a list that includes one or more known botnet IP addresses; and

determining that the scanning target is a participant in the botnet in response to at least one of the one or more IP addresses appearing in the list.

19. The non-transitory computer-readable storage medium of claim 18 ,

wherein the one or more IP addresses comprise a source IP address and a destination IP address associated with each of the plurality of current connections on the scanning target,

wherein executing the computer-executable instructions by the one or more processors further causes the one or more processors to compare the source IP address and the destination IP address to the list, and

wherein the botnet determination is based on one or more of the source IP address or the destination IP address appearing in the list.

20. The non-transitory computer-readable storage medium of claim 15 , wherein executing the computer-executable instructions by the one or more processors further causes the one or more processors to detect that the scanning target is a participant in the botnet in response to information describing traffic associated with at least one connection observed in the network (i) indicating that the at least one connection has a source Internet Protocol (IP) address or a destination IP address that appears in a list that includes one or more known botnet IP addresses, or (ii) indicating that the traffic includes a query to a domain name system (DNS) IP address that appears in the list.

21. The non-transitory computer-readable storage medium of claim 20 , wherein executing the computer-executable instructions by the one or more processors further causes the one or more processors to determine whether the detected participation in the botnet originated from a malicious external IP address associated with the botnet or an internal host that reached out to the malicious external IP address associated with the botnet based on the information describing the traffic associated with the at least one connection.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Apr 27, 2023
From: TENABLE, INC.; ACCURICS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 063485/0434 →
PATENT SECURITY AGREEMENT Recorded Jul 8, 2021
From: TENABLE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 056807/0546 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2020
From: RANUM, MARCUS J.; GULA, RON
To: TENABLE NETWORK SECURITY, INC.
Reel/Frame 051574/0949 →
CHANGE OF NAME Recorded Jan 21, 2020
From: TENABLE NETWORK SECURITY, INC.
To: TENABLE, INC.
Reel/Frame 051656/0490 →
Continuity (5)
Continuation 16200797 · Nov 27, 2018
Continuation 14738216 · Jun 12, 2015
Continuation 13692200 · Dec 3, 2012
Provisional Application 61668278 · Jul 5, 2012
Related Publication 20200162486A1 · May 21, 2020
Cited By (7)
US 12,197,398 US 12,242,455 US 12,248,434 US 12,248,435 US 12,367,108 US 12,517,874 US 12,627,681