IP Library Granted Patent US 11,755,730
Granted Patent B2
US 11,755,730 · App. 17/944,317 · Granted Sep 12, 2023

Behavioral threat detection engine

Inventors: Eric Klonowski (Broomfield, CO); Fred Krenson (Denver, CO)
Assignee: CARBONITE LLC
G06F21/554G06F9/45558G06F21/56G06F2009/45562G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,730
App. No.
17/944,317
Granted
Sep 12, 2023
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for a behavioral threat detection engine. In examples, the behavioral threat detection engine manages execution of one or more virtual machines, wherein each virtual machine processes a rule in relation to a context. The behavioral threat detection engine uses any of a variety of techniques to identify when events occur. Accordingly, the behavioral threat detection engine provides event indications, in the form of event packets, to one or more virtual machines, such that corresponding rules are able to process the events accordingly. Eventually, a rule may make a determination as to the presence or absence of a behavior. As a result, execution of the associated virtual machine may be halted, thereby indicating to the behavioral threat detection engine that a determination has been made. Thus a behavioral threat detection engine employs a behavior-based approach to detecting malicious or potentially malicious behaviors.

Claims (41)

1. A system comprising:

a processor; and

a non-transitory computer readable medium comprising instructions for:

evaluating a first rule in a rule data store to determine a first event associated with the first rule;

monitoring for an event indication associated with the first event;

when an event indication is detected, identifying the first rule associated with the received event indication;

generating an event packet based on the received event indication, the event packet comprising an identifier for the first event and a parameter relating to the first event;

providing the generated event packet to a rule virtual machine executing the first rule; and

performing an action based on an evaluation of the event by the rule virtual machine.

2. The system of claim 1 , wherein the instructions are further for initializing the rule virtual machine based on a second event associated with a second rule.

3. The system of claim 2 , wherein the second rule is a matching rule associated with multiple events.

4. The system of claim 1 , wherein the first event is a file event, a process event, or an event associated with a registry.

5. The system of claim 1 , wherein the identifier for the first event is an identifier for an event type of the first event.

6. The system of claim 1 , wherein the action comprises one or more of: providing an indication associated with the event, automatically mitigating a behavior associated with the event, or logging the event.

7. The system of claim 1 , wherein monitoring comprises generating a hook on an application programming interface (API).

8. A method, comprising:

evaluating a first rule in a rule data store to determine a first event associated with the first rule;

monitoring for an event indication associated with the first event;

when an event indication is detected, identifying the first rule associated with the received event indication;

generating an event packet based on the received event indication, the event packet comprising an identifier for the first event and a parameter relating to the first event;

providing the generated event packet to a rule virtual machine executing the first rule; and

performing an action based on an evaluation of the event by the rule virtual machine.

9. The method of claim 8 , further comprising initializing the rule virtual machine based on a second event associated with a second rule.

10. The method of claim 9 , wherein the second rule is a matching rule associated with multiple events.

11. The method of claim 8 , wherein the first event is a file event, a process event, or an event associated with a registry.

12. The system of claim 8 , wherein the identifier for the first event is an identifier for an event type of the first event.

13. The method of claim 8 , wherein the action comprises one or more of: providing an indication associated with the event, automatically mitigating a behavior associated with the event, or logging the event.

14. The method of claim 8 , wherein monitoring comprises generating a hook on an application programming interface (API).

15. A non-transitory computer readable medium, comprising instructions for:

evaluating a first rule in a rule data store to determine a first event associated with the first rule;

monitoring for an event indication associated with the first event;

when an event indication is detected, identifying the first rule associated with the received event indication;

generating an event packet based on the received event indication, the event packet comprising an identifier for the first event and a parameter relating to the first event;

providing the generated event packet to a rule virtual machine executing the first rule; and

performing an action based on an evaluation of the event by the rule virtual machine.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions are further for initializing the rule virtual machine based on a second event associated with a second rule.

17. The non-transitory computer readable medium of claim 16 , wherein the second rule is a matching rule associated with multiple events.

18. The non-transitory computer readable medium of claim 15 , wherein the first event is a file event, a process event, or an event associated with a registry.

19. The non-transitory computer readable medium of claim 15 , wherein the identifier for the first event is an identifier for an event type of the first event.

20. The non-transitory computer readable medium of claim 15 , wherein the action comprises one or more of: providing an indication associated with the event, automatically mitigating a behavior associated with the event, or logging the event.

21. The non-transitory computer readable medium of claim 15 , wherein monitoring comprises generating a hook on an application programming interface (API).

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: KLONOWSKI, ERIC; KRENSON, FRED
To: WEBROOT INC.
Reel/Frame 061140/0837 →
Continuity (2)
Continuation 16366065 · Mar 27, 2019
Related Publication 20230004643A1 · Jan 5, 2023
Cited By (1)
US 12,235,960