IP Library Granted Patent US 11,632,392
Granted Patent B1
US 11,632,392 · App. 16/840,584 · Granted Apr 18, 2023

Distributed malware detection system and submission workflow thereof

Inventor: Alexander Otvagin (Campbell, CA)
Assignee: FireEye Security Holdings US LLC
H04L63/145G06F9/45558H04L63/1416H04L63/1425H04L63/18G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,632,392
App. No.
16/840,584
Granted
Apr 18, 2023
Kind
B1
Abstract

As described, a cloud-based enrollment service is configured to advertise features and capabilities of clusters performing malware analyses within a cloud-based malware detection system. Upon receiving an enrollment request message, including tenant credentials associated with a sensor having an object to be analyzed for malware, the cloud-based enrollment service is configured to use the tenant credentials to authenticate the sensor and determine a type of subscription assigned to the sensor. Thereafter, the cloud-based enrollment service is further configured to transmit an enrollment response message including a portion of the advertised features and capabilities of a selected cluster of the cloud-based malware detection system. The advertised features and capabilities includes information to enable the sensor to establish direct communications with the selected cluster.

Claims (46)

1. A computerized method performed by a distributed malware detection system, the method comprising:

performing a preliminary analysis of an object to determine whether content included within the object is static or content included within the object is dynamic by including variable content;

performing a first analysis to determine whether the object has been previously analyzed when the content of the object is static;

halting further analysis of the object when the object has been previously analyzed by the sensor, or otherwise performing a second analysis of the object to determine a likelihood of the object being associated with malware;

obtaining tenant credentials associated with a sensor conducting at least the preliminary analysis or the first analysis, the tenant credentials include subscription information that identifies an active subscription by the sensor to services offered by a cloud-based malware detection system; and

submitting the object to the cloud-based malware detection system for further analysis when the likelihood of the object being associated with malware determined during the second analysis satisfied a prescribed threshold.

2. The method of claim 1 , wherein prior to performing of the preliminary analysis of the object, the method further comprises monitoring data traffic propagating over a transmission medium and extracting the object from the data traffic.

3. The method of claim 1 , wherein prior to submitting the object to the cloud-based malware detection system and after obtaining the tenant credentials, the method further comprising:

transmitting an enrollment request message including the tenant credentials to a cloud-based enrollment service to authenticate the sensor and determine a type of subscription assigned to the sensor, wherein the cloud-based enrollment service advertises features and capabilities of clusters performing malware analyses within the cloud-based malware detection system.

4. The method of claim 3 , wherein each of the clusters is a scalable architecture that includes one or more computing nodes each configured to detect malware residing within the object.

5. The method of claim 3 , responsive to transmitting the enrollment request message, receiving an enrollment response message including a portion of the advertised features and capabilities of a selected cluster for the sensor to establish direct communications with the selected cluster.

6. The method of claim 5 , wherein the advertised features and capabilities of the selected cluster include any or all of (i) an Internet Protocol (IP) address to a computing node of the selected cluster, (ii) a name of the computing node, or (iii) authentication information associated with the computing node.

7. The method of claim 5 , wherein the submitting of at least the object comprises submitting metadata associated with the object to determine from the metadata whether the object has been previously analyzed by the selected cluster.

8. A computerized method performed by a distributed malware detection system, the method comprising:

performing a preliminary analysis of an object to determine whether content included within the object is static or content included within the object is dynamic by including variable content

performing a first analysis to determine whether the object has been previously analyzed when the content of the object is static;

halting further analysis of the object when the object has been previously analyzed by the sensor, or otherwise performing a second analysis of the object to determine a likelihood of the object being associated with malware;

submitting the object to a cloud-based malware detection system for further analysis when the likelihood of the object being associated with malware determined during the second analysis satisfied a prescribed threshold; and

transmitting a status request message from a sensor conducting at least the preliminary analysis or the first analysis, the status request message being directed to a management system to confirm that the sensor is in communication with the cloud-based malware detection system and being used for rebalancing allocation of resources within the cloud-based detection system.

9. A non-transitory storage medium deployed within a sensor and including software that, upon execution, perform operations comprising:

determining, during a preliminary analysis of incoming information including at least an object and metadata associated with the object, whether content included within the object is static or whether content included within the object is dynamic;

performing a first analysis to determine whether the object has been previously analyzed when the content of the object is static;

halting further analysis of the object when the object has been previously analyzed by the sensor, or otherwise performing a second analysis of the object to determine a likelihood of the object being associated with malware;

obtaining tenant credentials associated with the sensor, the tenant credentials include subscription information that identifies an active subscription by the sensor to services offered by the cloud-based malware detection system; and

submitting the object to a cloud-based malware detection system for further analysis when the likelihood of the object being associated with malware determined during the second analysis satisfied a prescribed threshold.

10. The non-transitory storage medium of claim 9 , wherein the software, upon execution, further perform operations comprising:

prior to performing the preliminary analysis of the object, monitoring data traffic propagating over a transmission medium and extracting the object from the data traffic.

11. The non-transitory storage medium of claim 9 , wherein, prior to submitting the object to the cloud-based malware detection system and after obtaining the tenant credentials, the software upon execution, further perform operations comprising:

transmitting an enrollment request message including the tenant credentials to a cloud-based enrollment service to authenticate the sensor and determine a type of subscription assigned to the sensor, wherein the cloud-based enrollment service advertises features and capabilities of clusters performing malware analyses within the cloud-based malware detection system.

12. The non-transitory storage medium of claim 9 , wherein each of the clusters is a scalable architecture that includes one or more computing nodes where each of the one or more computing nodes is configured to detect malware residing within the object.

13. The non-transitory storage medium of claim 9 , wherein, responsive to transmitting the enrollment request message, the software, upon execution, further perform operations comprising:

receiving an enrollment response message including a portion of the advertised features and capabilities of a selected cluster for the sensor to establish direct communications with the selected cluster.

14. The non-transitory storage medium of claim 13 , wherein the advertised features and capabilities of the selected cluster include any or all of (i) an Internet Protocol (IP) address to a computing node of the selected cluster, (ii) a name of the computing node, or (iii) authentication information associated with the computing node.

15. The non-transitory storage medium of claim 13 , wherein the software, upon execution, further performs an operations of submitting the metadata associated with the object to determine from the metadata whether the object has been previously analyzed by the selected cluster.

16. The non-transitory storage medium of claim 9 , wherein the software, upon execution, further perform an operation comprising:

transmitting a status request message from the sensor to a management system to confirm that the sensor is in communication with the cloud-based malware detection system, the status request message being used for rebalancing allocation of resources within the cloud-based detection system.

17. The method of claim 8 , wherein prior to submitting the object to the cloud-based malware detection system and after obtaining the tenant credentials, the method further comprising:

transmitting an enrollment request message including the tenant credentials to a cloud-based enrollment service to authenticate the sensor and determine a type of subscription assigned to the sensor, wherein the cloud-based enrollment service advertises features and capabilities of clusters performing malware analyses within the cloud-based malware detection system.

18. The method of claim 17 , wherein each of the clusters is a scalable architecture that includes one or more computing nodes each configured to detect malware residing within the object.

19. The method of claim 17 , responsive to transmitting the enrollment request message, receiving an enrollment response message including a portion of the advertised features and capabilities of a selected cluster for the sensor to establish direct communications with the selected cluster.

20. The method of claim 19 , wherein the advertised features and capabilities of the selected cluster include any or all of (i) an Internet Protocol (IP) address to a computing node of the selected cluster, (ii) a name of the computing node, or (iii) authentication information associated with the computing node.

21. The method of claim 19 , wherein the submitting of at least the object comprises submitting the metadata associated with the object to determine from the metadata whether the object has been previously analyzed by the selected cluster.

22. The method of claim 1 further comprising:

refraining from submitting the object to the cloud-based malware detection system when the tenant credentials fail to identify the active subscription by the sensor to services offered by the cloud-based malware detection system.

23. The non-transitory storage medium of claim 9 further comprising:

refraining from submitting the object to the cloud-based malware detection system when the tenant credentials fail to identify the active subscription by the sensor to services offered by the cloud-based malware detection system.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: OTVAGIN, ALEXANDER
To: FIREEYE, INC.
Reel/Frame 058701/0106 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
Continuity (2)
Continuation 15283206 · Sep 30, 2016
Provisional Application 62313643 · Mar 25, 2016
Cited By (1)
US 12,445,481