IP Library Granted Patent US 11,550,909
Granted Patent B2
US 11,550,909 · App. 17/039,350 · Granted Jan 10, 2023

Tracking malicious software movement with an event graph

Inventors: Beata Ladnai (Cheshire, GB); Mark David Harris (Oxon, GB); Andrew J. Thomas (Oxfordshire, GB); Andrew G. P. Smith (Oxford, GB); Russell Humphries (Surrey, GB)
Assignee: Sophos Limited
G06F21/56G06F21/554G06F8/65G06F2221/034G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,909
App. No.
17/039,350
Granted
Jan 10, 2023
Kind
B2
Abstract

A multi-endpoint event graph is used to detect malware based on malicious software moving through a network.

Claims (36)

1. A computer program product for malware detection comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

instrumenting a first endpoint and a second endpoint to monitor a number of causal relationships among a number of computing objects at a plurality of logical locations within a computing environment;

selecting a set of logical locations for monitoring from the plurality of logical locations, the set of logical locations including a first logical location at the first endpoint and a second logical location at the second endpoint;

recording a sequence of events causally relating the number of computing objects at the set of logical locations, wherein the sequence of events spans multiple devices including at least the first endpoint and the second endpoint;

creating an event graph spanning multiple devices based on the sequence of events;

applying a malware detection rule for tracking malicious software movement through a network to the event graph;

evaluating a security state of the first endpoint based on the event graph and the malware detection rule; and

initiating remediation of the first endpoint in response to a change in the security state indicating a presence of malware on the first endpoint.

2. The computer program product of claim 1 wherein the second endpoint resides on a cloud computing resource.

3. The computer program product of claim 1 wherein the first endpoint resides on a cloud computing resource.

4. A method for malware detection comprising:

instrumenting a first endpoint and a second endpoint to monitor a number of causal relationships among a number of computing objects at a plurality of logical locations within a computing environment;

selecting a set of logical locations for monitoring from the plurality of logical locations, the set of logical locations including a first logical location at the first endpoint and a second logical location at the second endpoint;

recording a sequence of events causally relating the number of computing objects at the set of logical locations, wherein the sequence of events spans multiple devices including at least the first endpoint and the second endpoint;

creating an event graph spanning at least the first endpoint and the second endpoint based on the sequence of events;

evaluating a security state of the first endpoint based on the event graph; and

responding to a change in the security state.

5. The method of claim 4 wherein responding to the change in the security state includes remediating the first endpoint when the security state indicates that the first endpoint is compromised.

6. The method of claim 4 wherein responding to the change in the security state includes generating an alert based on the change.

7. The method of claim 4 further comprising adjusting the set of logical locations for monitoring in response to a change in a security risk for the first endpoint.

8. The method of claim 4 wherein the second endpoint includes one or more of a web site, a file server, or a mail server.

9. The method of claim 4 wherein the second endpoint resides on a cloud computing resource.

10. The method of claim 4 further comprising filtering one or more events in the sequence of events based on reputation.

11. The method of claim 4 wherein the set of logical locations includes at least one programming interface to a human interface device.

12. The method of claim 4 wherein the number of causal relationships includes at least one of a data flow, a control flow, and a network flow.

13. The method of claim 4 wherein the one or more computing objects include one or more of a data file, a process, an application, a registry entry, a network address, and a peripheral device.

14. The method of claim 4 wherein a number of events within the sequence of events are preserved for a predetermined time window, and further wherein the predetermined time window has a different duration for at least two different types of computing objects.

15. The method of claim 4 wherein the first endpoint and the second endpoint are within an enterprise network.

16. The method of claim 4 wherein recording the sequence of events includes recording the sequence of events in a data log stored on the first endpoint.

17. The method of claim 4 wherein recording the sequence of events includes recording the sequence of events in a data log hosted at a threat management facility.

18. The method of claim 4 wherein the event graph tracks a movement of malicious software through a network from one device to another.

19. A system comprising:

a first endpoint having a first network interface, a first memory, and a first processor;

a second endpoint having a second network interface, a second memory, and a second processor; and

computer executable code stored in the first memory and the second memory that configures the first processor and the second processor to perform the steps of instrumenting the first endpoint and the second endpoint to monitor a number of causal relationships among a number of computing objects at a plurality of logical locations within a computing environment, selecting a set of logical locations for monitoring from the plurality of logical locations, the set of logical locations including a first logical location at the first endpoint and a second logical location at the second endpoint, recording a sequence of events causally relating the number of computing objects at the set of logical locations, wherein the sequence of events spans multiple devices including at least the first endpoint and the second endpoint, creating an event graph spanning multiple devices based on the sequence of events, evaluating a security state of the first endpoint based on the event graph, and responding to a change in the security state.

20. The system of claim 19 wherein at least one of the first processor and the second processor resides on a cloud computing resource.

Assignments (3)
SECURITY INTEREST Recorded Mar 15, 2021
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 055593/0624 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2020
From: LADNAI, BEATA; HARRIS, MARK DAVID; THOMAS, ANDREW J.; SMITH, ANDREW G. P.; HUMPHRIES, RUSSELL
To: SOPHOS LIMITED
Reel/Frame 054060/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2020
From: LADNAI, BEATA; HARRIS, MARK DAVID; THOMAS, ANDREW J.; SMITH, ANDREW G. P.; HUMPHRIES, RUSSELL
To: SOPHOS LIMITED
Reel/Frame 054060/0278 →
Priority Claims (2)
GB 1610609 · Jun 17, 2016 · national
GB 1611301 · Jun 29, 2016 · national
Continuity (7)
Continuation 16401565 · May 2, 2019
Continuation 15924460 · Mar 19, 2018
Continuation 15924449 · Mar 19, 2018
Continuation 15484830 · Apr 11, 2017
Continuation 15484830 · Apr 11, 2017
Continuation In Part 15130244 · Apr 15, 2016
Related Publication 20210012005A1 · Jan 14, 2021
Cited By (3)
US 12,463,998 US 12,536,280 US 12,591,423