IP Library Granted Patent US 11,997,111
Granted Patent B1
US 11,997,111 · App. 17/063,648 · Granted May 28, 2024

Attribute-controlled malware detection

Inventors: Mumtaz Siddiqui (Fremont, CA); Manju Radhakrishnan (San Jose, CA); Deepak Agarwal (Bangalore, IN)
Assignee: Musarubra US LLC
H04L63/1416G06F21/56G06F21/577H04L63/08H04L63/145H04L63/20G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,111
App. No.
17/063,648
Granted
May 28, 2024
Kind
B1
Abstract

A cloud-based system is design with multi-tenancy controls for conducting analytics performed on objects submitted by a subscriber. This system features an analysis monitoring service and an analysis selection services. The analysis monitoring service, operating as a first cloud service, includes logic that is configured to collect metadata associated with an operating state for each of a plurality of clusters and generate cluster selection information. The analysis selection service, operating as a second cloud service and communicatively coupled to the analysis monitoring service, is configured to select a cluster of the plurality of clusters to analyze the object for malware based, at least in part, on the cluster selection information provided from the analysis monitoring service.

Claims (28)

1. A cloud-based system with multi-tenancy controls for conducting analytics performed on objects submitted by a subscriber, comprising:

an analysis monitoring service operating as a first cloud service, the analysis monitoring service including logic, operating as software modules stored within a non-transitory storage medium, configured to collect metadata associated with each of a plurality of clusters and generate cluster selection information, wherein the cluster selection information includes at least performance-based information derived from historical operational statistics for each of the plurality of clusters; and

an analysis selection service operating as a second cloud service and communicatively coupled to the analysis monitoring service, the analysis selection service being configured to select a cluster of the plurality of clusters to analyze the object for malware based, at least in part, on the cluster selection information provided from the analysis monitoring service.

2. The cloud-based system of claim 1 , wherein the cluster selection information includes the performance-based information for each of the plurality of clusters and the current status of each of the plurality of clusters.

3. The cloud-based system of claim 1 , wherein the performance-based information includes (i) a rate of analyses or (ii) a number of analyses conducted or guest images utilized by each of the plurality of clusters.

4. The cloud-based system of claim 1 , wherein the analysis monitoring services further collects metadata associated with one or more compute nodes associated with each of the plurality of clusters and the metadata associated with the one or more compute nodes used in generating the cluster selection information.

5. The cloud-based system of claim 1 , wherein the analysis monitoring services is further configured to collect metadata associated with at least one sensor at the subscriber and the metadata associated with the at least one sensor being used in generating the cluster selection information.

6. The cloud-based system of claim 1 , wherein the analysis selection services comprises a rules engine that selects the cluster in accordance with one or more policy and routing rules based on the cluster selection information and data included as part of subscription information provided from the subscriber to the analysis selection service with the object.

7. The cloud-based system of claim 6 , wherein the subscription information includes (i) subscription attributes that identify one or more performance criterion in analyses conducted on an object submitted by the subscriber for analysis as to whether the object is associated with malware and (ii) customer-configured attributes that identify at least geographic location permissions or restrictions for compute nodes or clusters in conducting analyses on the object.

8. The cloud-based system of claim 1 , wherein the analysis selection services comprises a rules engine that selects the cluster provided that operational metadata associated with the selected cluster indicates that the selected cluster is able to satisfy performance or operation criterion set forth by subscription attributes or customer-configured attributes or a combination of the subscription attributes and the customer-configured attributes.

9. The cloud-based system of claim 1 , wherein the cluster of the plurality of clusters corresponds to a scalable architecture including one or more compute nodes, each compute node includes logic that is configured to analyze objects including at least the object submitted to and routed by the analysis selection service to the cluster of the plurality of clusters.

10. The cloud-based system of claim 9 , wherein the cluster is deployed as part of a public cloud network and the analysis selection service is deployed as part of a private cloud network within the public cloud network.

11. A non-transitory storage medium including software, operating as part of a cloud-based system with multi-tenancy controls, conducting analytics performed on objects for malware, comprising:

a first software module configured to operate, upon execution, as a first cloud service, the first software module including logic configured to collect metadata associated with an operating state for each of a plurality of clusters and generate cluster selection information; and

a second software module configured to operate, upon execution, as a second cloud service and communicatively coupled to the first software module, the second software module being configured to select a cluster of the plurality of clusters to analyze the object for malware based, at least in part, on the cluster selection information provided from the first software module, wherein the cluster selection information includes at least performance-based information derived from historical operational statistics.

12. The non-transitory storage medium of claim 11 , wherein the cluster selection information further includes current status of each of the plurality of clusters.

13. The non-transitory storage medium of claim 12 , wherein the performance-based information includes rate of analyses or number of analyses conducted or guest images utilized by each of the plurality of clusters.

14. The non-transitory storage medium of claim 11 , wherein the first software module is further configured to collect metadata associated with one or more compute nodes associated with each of the plurality of clusters and the metadata associated with the one or more compute nodes is used in generating the cluster selection information.

15. The non-transitory storage medium of claim 11 , wherein the first software module is further configured to collect metadata associated with at least one sensor at the subscriber and the metadata associated with the at least one sensor being used in generating the cluster selection information.

16. The non-transitory storage medium of claim 11 , wherein the second software module comprises a rules engine that selects the cluster in accordance with one or more policy and routing rules based on the cluster selection information and data included as part of subscription information provided from the subscriber to the second software module with the object.

17. The non-transitory storage medium of claim 16 , wherein the subscription information includes (i) subscription attributes that identify one or more performance criterion in analyses conducted on an object submitted by the subscriber for analysis as to whether the object is associated with malware and (ii) customer-configured attributes that identify at least geographic location permissions or restrictions for compute nodes or clusters in conducting analyses on the object.

18. The non-transitory storage medium of claim 11 , wherein the second software module comprises a rules engine that selects the cluster provided that operational metadata associated with the selected cluster indicates that the selected cluster is able to satisfy performance or operation criterion set forth by subscription attributes or customer-configured attributes or a combination of the subscription attributes and the customer-configured attributes.

19. A method for, under multi-tenancy controls, conducting analytics performed on objects submitted by a subscriber, comprising:

collecting metadata associated with an operating state for each of a plurality of clusters;

generating cluster selection information based on the collected metadata, wherein the cluster selection information includes performance-based information that comprises at least performance-based information associated with a cluster of the plurality of clusters that includes (i) a rate of analyses associated with the cluster or (ii) a number of analyses conducted by the cluster or (iii) a number of guest images utilized by the cluster; and

selecting the cluster of the plurality of clusters to analyze the object for malware based, at least in part, on the cluster selection information provided from an analysis monitoring service.

20. The method of claim 19 , wherein the cluster selection information includes the performance-based information for the cluster of the plurality of clusters and a current status of each of the plurality of clusters and the performance-based information includes (i) a rate of analyses or (ii) a number of analyses conducted or (iii) a number of guest images utilized by each of the plurality of clusters.

21. The method of claim 19 , wherein the selecting of the cluster of the plurality of clusters is performed by a rules engine and is in accordance with one or more policy and routing rules based on the cluster selection information and data included as part of subscription information provided from the subscriber.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
MERGER Recorded Oct 9, 2023
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 065160/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2022
From: SIDDIQUI, MUMTAZ; RADHAKRISHNAN, MANJU; AGARWAL, DEEPAK
To: FIREEYE, INC.
Reel/Frame 058707/0496 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
Continuity (3)
Continuation 15940307 · Mar 29, 2018
Provisional Application 62523123 · Jun 21, 2017
Provisional Application 62479208 · Mar 30, 2017
Cited By (1)
US 12,561,329