IP Library Granted Patent US 11,936,666
Granted Patent B1
US 11,936,666 · App. 17/146,417 · Granted Mar 19, 2024

Risk analyzer for ascertaining a risk of harm to a network and generating alerts regarding the ascertained risk

Inventors: Ashar Aziz (Coral Gables, FL); Osman Abdoul Ismael (Palo Alto, CA)
Assignee: Musarubra US LLC
H04L63/1416G06F21/53H04L63/14H04L63/145H04W12/128
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,936,666
App. No.
17/146,417
Granted
Mar 19, 2024
Kind
B1
Abstract

Computerized techniques to determine and verify maliciousness of an object are described. A malware detection system intercepts in-bound network traffic at a periphery of a network to capture and analyze behaviors of content of network traffic monitored during execution in a virtual machine. One or more endpoint devices on the network also monitor for behaviors during normal processing. Correlation of the behaviors captured by the malware detection system and the one or more endpoint devices may verify a classification by the malware detection system of maliciousness of the content. The malware detection system may communicate with the one or more endpoint devices to influence detection and reporting of behaviors by those device(s).

Claims (30)

1. A security logic engine, including a memory and a processor, to determine whether a network, including a plurality of endpoint devices, is undergoing a cyber-attack, the security logic engine comprising:

correlation logic stored in the memory for execution by the processor, the correlation logic is configured to generate correlation results based on (i) a combination of monitored features including a first set of features associated with a first object included as part of inbound network traffic detected at a periphery of the network and generated based on analytics of the first object by a malware detection system and a second set of features generated based on analytics of the first object by one or more endpoint devices and (ii) a third set of features exhibited by a known malware or a known malware family;

a classification engine stored in the memory for execution by the processor, the classification engine is configured to generate classification results by determining, at least basal on the correlation results provided by the correlation logic, whether the first object is classified as a malicious object being part of the cyber-attack;

a risk analyzer stored in the memory for execution by the processor, the risk analyzer is configured to (i) receive the classification results when the first object is classified by the classification engine as a malicious object and (ii) correlate the combination of monitored features with information associated with properties associated with each of the plurality of endpoint devices, different than the malware detection system, to generate at least a risk profile for each of the plurality of endpoint devices,

wherein each risk profile identifies whether a corresponding endpoint device is vulnerable to the cyber-attack.

2. The security logic engine of claim 1 , wherein the risk analyzer is configured to restrict access by the corresponding endpoint device to resources of the network in response to the risk profile of the corresponding endpoint device identifying at least a prescribed vulnerability risk.

3. The security logic engine of claim 1 further comprising:

a reporting engine communicatively coupled to the risk analyzer, the reporting engine being configured to generate a first type of alert that identifies to (i) a user of the corresponding endpoint device, or (ii) a network administrator, or (iii) an expert network analyst, a likelihood of the cyber-attack being directed to the corresponding endpoint device.

4. The security logic engine of claim 3 , wherein the risk analyzer is further configured to issue an alert to at least the corresponding endpoint device to restrict access by the corresponding endpoint device to resources of the network in response to the risk profile identifying at least a prescribed vulnerability risk.

5. The security logic engine of claim 1 further comprising:

a scorer to generate a score based on each correlation of a feature of the combination of monitored features associated with the first object with known behaviors and characteristics of benign and malicious objects, and

the classification engine to generate the classification results based on the correlation results and the scores generated for the combination of monitored features.

6. The security logic engine of claim 5 , wherein the score is based on (i) a location from where the first object originated or (ii) the first object spawned a new process.

7. The security logic engine of claim 1 , wherein the risk analyzer is configured to determine a risk to the network using experiential knowledge to correlate the combination of monitored features with the information for the properties associated with each of the plurality of endpoint devices.

8. The security logic engine of claim 1 , wherein the risk analyzer is configured to communicate with the malware detection system to conduct a further analysis of the first object if the risk analyzer is unable to determine if the first object will operate as a malicious object when processed by an endpoint device of the plurality of endpoint devices.

9. A non-transitory computer-readable medium to determine whether a network, including a plurality of endpoint devices, is undergoing a cyber-attack, the non-transitory computer-readable medium including instructions that, when executed, cause execution of software components comprising:

correlation logic configured to generate correlation results based on (i) a combination of monitored features including a first set of features associated with a first object included as part of inbound network traffic detected at a periphery of the network and generated based on analytics of the first object by a malware detection system and a second set of features generated based on analytics of the first object by one or more endpoint devices and (ii) a third set of features exhibited by a known malware or a known malware family;

a classification engine configured to generate classification results by determining, at least based on the correlation results provided by the correlation logic, whether the first object is classified as a malicious object being part of the cyber-attack; and

a risk analyzer configured to receive the classification results when the first object is classified by the classification engine as a malicious object and correlate the combination of monitored features with information associated with properties associated with each of the plurality of endpoint devices, different than the malware detection system, to generate at least a risk profile for each of the plurality of endpoint devices,

wherein each risk profile identifies whether a corresponding endpoint device is vulnerable to the cyber-attack.

10. The non-transitory computer-readable medium of claim 9 , wherein the risk analyzer is configured to restrict access by the corresponding endpoint device to resources of the network in response to the risk profile of the corresponding endpoint device identifying at least a prescribed vulnerability risk.

11. The non-transitory computer-readable medium of claim 9 further comprising:

a reporting engine communicatively coupled to the risk analyzer, the reporting engine being configured to generate a first type of alert that identifies to (i) a user of the corresponding endpoint device, (ii) a network administrator or (iii) an expert network analyst, a likelihood of the cyber-attack being directed to the corresponding endpoint device.

12. The non-transitory computer-readable medium of claim 11 , wherein the risk analyzer is further configured to issue an alert to at least the corresponding endpoint device to restrict access by the corresponding endpoint device to resources of the network in response to the risk profile identifying at least a prescribed vulnerability risk.

13. The non-transitory computer-readable medium of claim 9 further comprising:

a scorer to generate a score based on each correlation of a feature of the combination of monitored features associated with the first object with known behaviors and characteristics of benign and malicious objects, and

the classification engine to generate the classification results based on the correlation results and the scores generated for the combination of monitored features.

14. The non-transitory computer-readable medium of claim 13 , wherein the score is based on (i) a location from where the first object originated or (ii) the first object spawned a new process.

15. The non-transitory computer-readable medium of claim 9 , wherein the risk analyzer is configured to determine a risk to the network using experiential knowledge to correlate the combination of monitored features with the information for the properties associated with each of the plurality of endpoint devices.

16. The non-transitory computer-readable medium of claim 9 , wherein the risk analyzer is configured to communicate with the malware detection system to conduct a further analysis of the first object if the risk analyzer is unable to determine if the first object will operate as a malicious object when processed by an endpoint device of the plurality of endpoint devices.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
Cited By (1)
US 12,683,994