IP Library Granted Patent US 11,798,028
Granted Patent B2
US 11,798,028 · App. 17/711,896 · Granted Oct 24, 2023

Systems and methods for monitoring malicious software engaging in online advertising fraud or other form of deceit

Inventors: Hadi Shiravi Khozani (Fredericton, CA); Ehsan Mokhtari (Fredericton, CA); Sergei Frankoff (Fredericton, CA); Mohammad Ali Shiravi Khozani (Fredericton, CA)
Assignee: The Nielsen Company (US), LLC
G06Q30/0248G06F21/53H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,798,028
App. No.
17/711,896
Granted
Oct 24, 2023
Kind
B2
Abstract

Systems and methods for monitoring malicious software engaging in online advertising fraud or other form of deceit are disclosed herein. An example method includes identifying a communication process used by a compromised computing device to communicate with a control server, the control server providing access to advertising weblinks, the compromised computing device associated with malicious software, directing, by an instruction executed by a processor, the compromised computing device to communicate with an uncompromised computing device by re-routing of packets used for communication between the compromised computing device and the control server, the uncompromised computing device is configured to mimic communications between the compromised computing device and the control server using the communication processes, storing information from one or more packets transmitted from the uncompromised computing device, and creating a profile of the malicious software based on the stored information.

Claims (34)

1. A method comprising:

identifying a communication process used by a compromised computing device to communicate with a control server, the control server providing access to advertising weblinks, the compromised computing device associated with malicious software, wherein the identifying the communication process includes;

storing, via a debugger, instructions executed by the compromised computing device; and

obtaining an algorithm used by the compromised computing device to communicate with the control server based on the stored instructions;

directing, by an instruction executed by a processor, the compromised computing device to communicate with an uncompromised computing device by re-routing first packets communicated between the compromised computing device and the control server, the uncompromised computing device to mimic communications between the compromised computing device and the control server using the communication process, wherein the re-routing the first packets includes spoofing an Internet Protocol address of the control server or a domain name system attribute of the control server;

storing information from one or more second packets transmitted from the uncompromised computing device; and

creating a profile of the malicious software based on the stored information.

2. The method of claim 1 , further including identifying an encryption process used by the compromised computing device, the uncompromised computing device to mimic communications between the compromised computing device and the control server using the encryption process.

3. The method of claim 1 , wherein the profile includes at least one of a characteristic of the malicious software or an action performed by the malicious software.

4. The method of claim 3 , wherein the action includes at least one of writing strings to memory, generating network traffic, conducting application programming interface (API) calls related to network protocols, or conducting API calls related to cryptography.

5. The method of claim 1 , wherein the uncompromised computing device is a provisioned control server, the provisioned control server implemented to issue commands to the compromised computing device.

6. A non-transitory computer readable medium comprising instructions, which when executed, cause a processor to at least:

identify a communication process used by a compromised computing device to communicate with a control server, the control server to provide access to advertising weblinks, the compromised computing device associated with malicious software, wherein the instructions, when executed, caused the processor to identify the communication process by:

storing, via a debugger, instructions executed by the compromised computing device; and

obtaining an algorithm used by the compromised computing device to communicate with the control server based on the stored instructions;

direct, by an instruction executed by the processor, the compromised computing device to communicate with an uncompromised computing device by re-routing first packets communicated between the compromised computing device and the control server, the uncompromised computing device to mimic communications between the compromised computing device and the control server using the communication process wherein the instructions, when executed, caused the processor to re-rout the first packets by spoofing an Internet Protocol address of the control server or an domain name system attribute of the control server;

store information from one or more second packets transmitted from the uncompromised computing device; and

create a profile of the malicious software based on the stored information.

7. The non-transitory computer readable medium of claim 6 , wherein the instructions, when executed, cause the processor to identify an encryption process used by the compromised computing device, the uncompromised computing device to mimic communications between the compromised computing device and the control server using the encryption process.

8. The non-transitory computer readable medium of claim 6 , wherein the profile includes at least one of a characteristic of the malicious software or an action performed by the malicious software.

9. The non-transitory computer readable medium of claim 8 , wherein the action includes at least one of writing strings to memory, generating network traffic, conducting application programming interface (API) calls related to network protocols, or conducting API calls related to cryptography.

10. The non-transitory computer readable medium of claim 6 , wherein the uncompromised computing device is a provisioned control server, the provisioned control server implemented to issue commands to the compromised computing device.

11. An apparatus comprising:

memory including instructions; and

a processor to execute the instructions to:

identify a communication process used by a compromised computing device to communicate with a control server, the control server to provide access to advertising weblinks, the compromised computing device associated with malicious software, wherein the instructions, when executed, caused the processor to identify the communication process by:

storing, via a debugger, instructions executed by the compromised computing device; and

obtaining an algorithm used by the compromised computing device to communicate with the control server based on the stored instructions;

direct, by an instruction executed by the processor, the compromised computing device to communicate with an uncompromised computing device by re-routing first packets communicated between the compromised computing device and the control server, the uncompromised computing device to mimic communications between the compromised computing device and the control server using the communication process, wherein the instructions, when executed, cause the processor to re-route the first packets by spoofing an Internet Protocol address of the control server or a domain name system attribute of the control server;

store information from one or more second packets transmitted from the uncompromised computing device; and

create a profile of the malicious software based on the stored information.

12. The apparatus of claim 11 , wherein the instructions, when executed, cause the processor to identify an encryption process used by the compromised computing device, the uncompromised computing device to mimic communications between the compromised computing device and the control server using the encryption process.

13. The apparatus of claim 12 , wherein the profile includes at least one of a characteristic of the malicious software or an action performed by the malicious software.

14. The apparatus of claim 11 , wherein the uncompromised computing device is a provisioned control server, the provisioned control server implemented to issue commands to the compromised computing device.

Assignments (5)
SECURITY INTEREST Recorded May 8, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: ARES CAPITAL CORPORATION
Reel/Frame 063574/0632 →
SECURITY INTEREST Recorded Apr 28, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: CITIBANK, N.A.
Reel/Frame 063561/0381 →
SECURITY AGREEMENT Recorded Jan 31, 2023
From: GRACENOTE DIGITAL VENTURES, LLC; GRACENOTE MEDIA SERVICES, LLC; GRACENOTE, INC.; TNC (US) HOLDINGS, INC.; THE NIELSEN COMPANY (US), LLC
To: BANK OF AMERICA, N.A.
Reel/Frame 063560/0547 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2022
From: SHIRAVI KHOZANI, HADI; MOKHTARI, EHSAN; FRANKOFF, SERGEI; SHIRAVI KHOZANI, MOHAMMAD ALI
To: SENTRANT SECURITY INC.
Reel/Frame 060600/0589 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2022
From: SENTRANT SECURITY INC.
To: THE NIELSEN COMPANY (US), LLC
Reel/Frame 060600/0597 →
Continuity (4)
Continuation 16847599 · Apr 13, 2020
Continuation 15147503 · May 5, 2016
Provisional Application 62157195 · May 5, 2015
Related Publication 20220222700A1 · Jul 14, 2022