IP Library Granted Patent US 11,916,934
Granted Patent B2
US 11,916,934 · App. 17/745,366 · Granted Feb 27, 2024

Identifying malware-suspect end points through entropy changes in consolidated logs

Inventors: Peter Thayer (Santa Clara, CA); Gabriel G. Infante-Lopez (Cordoba, AR); Leandro J. Ferrado (Cordoba, AR); Alejandro Houspanossian (Cordoba, AR)
Assignee: MUSARUBRA US LLC
H04L63/1416G06N20/00H04L63/145H04L63/1425G06N7/01G06N20/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,934
App. No.
17/745,366
Granted
Feb 27, 2024
Kind
B2
Abstract

Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.

Claims (35)

1. At least one machine readable medium implemented by at least one of a solid-state device or a storage disk, the at least one machine readable medium comprising instructions, to cause one or more processors to at least:

process monitored log entries associated with a plurality of monitored devices to determine measurements associated with the monitored devices, the measurements including ones of a first type of entropy value and ones of a second type of entropy value associated respectively with the monitored devices, the ones of the first type of entropy value based on respective numbers of unique event identifiers included in respective groups of the monitored log entries associated respectively with the monitored devices, a first one of the second type of entropy value based on (i) a number of unique event identifiers included in a first one of the groups of the monitored log entries associated with a first one of the monitored devices and (ii) a total number of log entries included in the first one of the groups of the monitored log entries associated with the first one of the monitored devices;

determine, based on the measurements and a machine learning algorithm, whether the first one of the monitored devices is compromised; and

quarantine the first one of the monitored devices in response to a determination that the first one of the monitored devices is compromised.

2. The at least one machine readable medium of claim 1 , wherein the instructions are to cause the one or more processors to execute the machine learning algorithm to classify the first one of the monitored devices as compromised or uncompromised based on the measurements.

3. The at least one machine readable medium of claim 1 , wherein the instructions are to cause the one or more processors to:

execute the machine learning algorithm to determine a threshold based on the monitored log entries; and

compare a first one of the first type of entropy value to the threshold to determine whether the first one of the monitored devices is compromised, the first one of the first type of entropy value associated with the first one of the monitored devices.

4. The at least one machine readable medium of claim 1 , wherein the measurements include first confidence values based on the ones of the first type of entropy value and second confidence values based on the ones of the second type of entropy value.

5. The at least one machine readable medium of claim 1 , wherein the groups of the monitored log entries are associated with a time window.

6. The at least one machine readable medium of claim 1 , wherein the instructions are to cause the one or more processors to train the machine learning algorithm based on historical log data.

7. An apparatus comprising:

at least one memory;

computer readable instructions; and

processor circuitry to execute the computer readable instructions to at least:

process monitored log entries associated with a plurality of monitored devices to determine measurements associated with the monitored devices, the measurements including ones of a first type of entropy value and ones of a second type of entropy value associated respectively with the monitored devices, the ones of the first type of entropy value based on respective numbers of unique event identifiers included in respective groups of the monitored log entries associated respectively with the monitored devices, a first one of the second type of entropy value based on (i) a number of unique event identifiers included in a first one of the groups of the monitored log entries associated with a first one of the monitored devices and (ii) a total number of log entries included in the first one of the groups of the monitored log entries associated with the first one of the monitored devices;

determine, based on the measurements and a machine learning algorithm, whether the first one of the monitored devices is compromised; and

quarantine the first one of the monitored devices in response to a determination that the first one of the monitored devices is compromised.

8. The apparatus of claim 7 , wherein the processor circuitry is to execute the machine learning algorithm to classify the first one of the monitored devices as compromised or uncompromised based on the measurements.

9. The apparatus of claim 7 , wherein the processor circuitry is to:

execute the machine learning algorithm to determine a threshold based on the monitored log entries; and

compare a first one of the first type of entropy value to the threshold to determine whether the first one of the monitored devices is compromised, the first one of the first type of entropy value associated with the first one of the monitored devices.

10. The apparatus of claim 7 , wherein the measurements include first confidence values based on the ones of the first type of entropy value and second confidence values based on the ones of the second type of entropy value.

11. The apparatus of claim 7 , wherein the groups of the monitored log entries are associated with a time window.

12. The apparatus of claim 7 , the processor circuitry is to train the machine learning algorithm based on historical log data.

13. A method comprising:

processing, by executing an instructions with at least one processor, monitored log entries associated with a plurality of monitored devices to determine measurements associated with the monitored devices, the measurements including ones of a first type of entropy value and ones of a second type of entropy value associated respectively with the monitored devices, the ones of the first type of entropy value based on respective numbers of unique event identifiers included in respective groups of the monitored log entries associated respectively with the monitored devices, a first one of the second type of entropy value based on (i) a number of unique event identifiers included in a first one of the groups of the monitored log entries associated with a first one of the monitored devices and (ii) a total number of log entries included in the first one of the groups of the monitored log entries associated with the first one of the monitored devices;

determining, based on the measurements and a machine learning algorithm, whether the first one of the monitored devices is compromised; and

quarantining the first one of the monitored devices in response to a determination that the first one of the monitored devices is compromised.

14. The method of claim 13 , further including executing the machine learning algorithm to classify the first one of the monitored devices as compromised or uncompromised based on the measurements.

15. The method of claim 13 , further including:

executing the machine learning algorithm to determine a threshold based on the monitored log entries; and

comparing a first one of the first type of entropy value to the threshold to determine whether the first one of the monitored devices is compromised, the first one of the first type of entropy value associated with the first one of the monitored devices.

16. The method of claim 13 , wherein the measurements include first confidence values based on the ones of the first type of entropy value and second confidence values based on the ones of the second type of entropy value.

17. The method of claim 13 , wherein the groups of the monitored log entries are associated with a time window.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061815/0035 →
CHANGE OF NAME Recorded Jul 19, 2022
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 060715/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2022
From: THAYER, PETER; INFANTE-LOPEZ, GABRIEL G.; FERRADO, LEANDRO J.; HOUSPANOSSIAN, ALEJANDRO
To: MCAFEE, INC.
Reel/Frame 060540/0201 →