IP Library Granted Patent US 12,238,124
Granted Patent B2
US 12,238,124 · App. 18/209,657 · Granted Feb 25, 2025

Systems and methods of malware detection

Inventors: Jordan S. Webster (Vienna, VA); Christopher S. Stinson (Odenton, MD)
Assignee: IronNet Cybersecurity, Inc.
H04L63/1416G06F17/18G06F21/566G06N20/00H04L43/022H04L43/16H04L63/1466H04L69/322
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,124
App. No.
18/209,657
Filed
Jun 14, 2023
Granted
Feb 25, 2025
Kind
B2
Art Unit
2493
USPC
726/23
Abstract

Systems and methods for detecting suspicious malware by analyzing data such as transfer protocol data or logs from a host within an enterprise is provided. The systems and methods include a database for storing current data and historical data obtained from the network and a detection module and an optional display. The embodiments herein extract information from non-encrypted transfer protocol metadata, determine a plurality of features, utilize an outlier detection model that is based on historical behaviors, calculate a suspiciousness score, and create alerts for analysis by users when the score exceeds a threshold. In doing so, the systems and methods of the present invention improve the ability to identify suspicious outliers or potential malware on an iterative basis over time.

Claims (45)

1. A system for detecting malicious traffic in a network comprising:

at least one sensor, wherein each sensor is configured to:

mirror network traffic for at least one device connected to the network; and

create a set of data consisting of transfer protocol records and associated transfer protocol record metadata by, over a time interval, parsing the mirrored network traffic for transfer protocol records;

a database coupled to the at least one sensor and configured to:

receive and store the set of data from each of the at least one sensor, wherein the data received and stored during the time interval comprise a set of test data;

store a set of historical data previously obtained from the network, wherein the historical data consists of transfer protocol records and associated transfer protocol metadata; and

a computation engine including at least one processor and non-transitory memory, the computation engine including a detection module configured to run on the computation engine and adapted and configured to perform the steps of:

loading the set of test data from the database;

filtering the set of test data to obtain filtered data based on at least one criterion,

wherein the filtered data includes data for at least one transfer protocol record;

saving the filtered data to the database;

determining a value of each of a plurality of features of each transfer protocol record;

loading, for each transfer protocol record, a set of previously computed historical feature values from the database, wherein the historical feature values were computed from the set of historical data; and

computing an output score for each transfer protocol record based on comparing, for each feature of each transfer protocol record, the determined value to the set of previously computed historical feature values for that feature, wherein the output score for each transfer protocol record indicates the likelihood that that transfer protocol record represents malicious network traffic.

2. The system of claim 1 , wherein the at least one criterion is one of a file path information, file name, a content type, a content length, and a file extension type.

3. The system of claim 1 , wherein the transfer protocol is one of hypertext transfer protocol (HTTP), file transfer protocol (FTP), server message block (SMB), and simple mail transfer protocol (SMTP).

4. The system of claim 1 , wherein the detection module is further adapted and configured to perform the step of creating an alert for each output score at or above a predetermined threshold.

5. The system of claim 4 , further comprising a display for displaying the alert received from the detection module.

6. The system of claim 1 , wherein the plurality of features includes at least one of: a count of a number of times downloads are made from an observed protocol host over a time interval, a count of a number of times an observed transfer protocol path is downloaded over a time interval, an amount by which the value of one feature within the plurality of features is abnormal relative to other file downloads with a same extension as the one feature, and a determination of how strongly a downloaded file name correlates with a list of known malware file names.

7. The system of claim 1 , wherein the set of historical data consists of data received from the network during a predetermined period of time preceding the time interval.

8. The system of claim 1 , wherein the at least one criterion for filtering includes removing each transfer protocol record that is empty or does not include a file extension.

9. The system of claim 1 , wherein the set of historical data is stored over a predetermined period of time having a length and a temporal distance prior to the time interval.

10. The system of claim 1 , wherein the comparing the determined value to the set of previously computed historical feature values for that feature further comprises calculating a Z-score or a P-score for each feature.

11. A method for detecting malicious traffic in a network comprising the steps of:

mirroring network traffic for at least one device connected to the network by each of at least one sensor connected to the network;

creating, by each of the at least one sensor, a set of data consisting of transfer protocol records and associated transfer protocol record metadata by, over a time interval, parsing the mirrored network traffic for transfer protocol records;

receiving and storing, by a database coupled to the at least one sensor, the set of data from each of the at least one sensor, wherein the data received and stored during the time interval comprise a set of test data;

storing, by the database, a set of historical data previously obtained from the network, wherein the historical data consists of transfer protocol records and associated transfer protocol metadata;

loading the set of test data from the database;

filtering the set of test data to obtain filtered data based on at least one criterion, wherein the filtered data includes data for at least one transfer protocol record;

saving the filtered data to the database;

determining a value of each of a plurality of features of the filtered data;

loading, for each of the plurality of features of the filtered data, a set of previously computed historical feature values from the database, wherein the historical feature values were computed from the set of historical data;

determining a value of each of a plurality of features of each transfer protocol record;

loading, for each transfer protocol record, a set of previously computed historical feature values from the database, wherein the historical feature values were computed from the set of historical data; and

computing an output score for each transfer protocol record based on comparing, for each feature of each transfer protocol record, the determined value to the set of previously computed historical feature values for that feature, wherein the output score for each transfer protocol record indicates the likelihood that that transfer protocol record represents malicious network traffic.

12. The method of claim 11 , wherein the at least one criterion is one of a file path information, a file name, a content type, a content length, and a file extension type.

13. The method of claim 11 , wherein the transfer protocol is one of hypertext transfer protocol (HTTP), file transfer protocol (FTP), server message block (SMB), and simple mail transfer protocol (SMTP).

14. The method of claim 11 , further comprising the step of creating an alert for each output score at or above a predetermined threshold.

15. The method of claim 14 , further comprising displaying the alert in a display.

16. The method of claim 11 , wherein the plurality of features includes at least one of: a count of a number of times downloads are made from an observed protocol host over a time interval, a count of a number of times an observed transfer protocol path is downloaded over a time interval, an amount by which the value of one feature within the plurality of features is abnormal relative to other file downloads with a same extension, and a determination of how strongly a downloaded file name correlates with a list of known malware file names.

17. The method of claim 11 , wherein the set of historical data consists of data received from the network during a predetermined period of time preceding the time interval.

18. The method of claim 11 , wherein the set of historical data is stored over a predetermined period of time having a length and a temporal distance prior to the time interval.

19. The method of claim 11 , wherein the comparing the determined value to the set of previously computed historical feature values for that feature further comprises calculating a Z-score or a P-score for each feature.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Mar 1, 2024
From: FERROUS INVESTORS LP, AS SECURED PARTY
To: IRONNET CYBERSECURITY, INC.; IRONCAD LLC
Reel/Frame 066759/0501 →
SECURITY INTEREST Recorded Mar 1, 2024
From: IRONNET CYBERSECURITY, INC.; IRONCAD LLC
To: FERROUS INVESTORS LP; ITC GLOBAL ADVISORS, LLC
Reel/Frame 066759/0535 →
SECURITY INTEREST Recorded Oct 12, 2023
From: IRONNET CYBERSECURITY, INC.; IRONCAD LLC
To: FERROUS INVESTORS LP
Reel/Frame 065194/0555 →
Continuity (2)
Continuation 16786101 · Feb 10, 2020
Related Publication 20230328080A1 · Oct 12, 2023
References Cited (33)
US 10530671B2 · Sanders · 2020 [cited by applicant]
US 10567247B2 · Kulshreshtha · 2020 [cited by applicant]
US 10599635B1 · Gunn · 2020 [cited by applicant]
US 10885393B1 · Sirianni · 2021 [cited by examiner]
US 11206276B2 · Nitz · 2021 [cited by examiner]
US 11716337B2 · Webster · 2023 [cited by applicant]
US 20050125195A1 · Brendel · 2005 [cited by examiner]
US 20070226803A1 · Kim · 2007 [cited by examiner]
US 20100281388A1 · Kane · 2010 [cited by examiner]
US 20140047543A1 · Kim · 2014 [cited by examiner]
US 20140325653A1 · Altman · 2014 [cited by examiner]
US 20160191390A1 · Barsumian · 2016 [cited by examiner]
US 20160359701A1 · Pang · 2016 [cited by examiner]
US 20160359889A1 · Yadav · 2016 [cited by applicant]
US 20170011297A1 · Li · 2017 [cited by applicant]
US 20170330123A1 · Deshpande · 2017 [cited by applicant]
US 20180219879A1 · Pierce · 2018 [cited by examiner]
US 20190080260A1 · Acuna Agost · 2019 [cited by applicant]
US 20190132343A1 · Chen · 2019 [cited by applicant]
US 20190182130A1 · Simitsis · 2019 [cited by examiner]
US 20200186600A1 · Dawani · 2020 [cited by examiner]
US 20200228567A1 · Kang · 2020 [cited by applicant]
US 20200302074A1 · Little · 2020 [cited by applicant]
US 20210112091A1 · Compton · 2021 [cited by applicant]
US 20210250364A1 · Webster · 2021 [cited by applicant]
US 20210303682A1 · Mugambi · 2021 [cited by applicant]
Aggarwal et al; Detection of Spatial Outlier by Using Improved ZScore Test; Proceedings of the Third International Conference on Trends in Electronics and Informatics (ICOEI 2019) IEEE; pp. 788-790 (Year: 2019). [cited by applicant]
Li et al; “An active learning based TCM-KNN algorithm for supervised network intrusion detection”; Computers & Security 26 (2007); pp. 459-467; (Year:2007). [cited by applicant]
Rajeswari et al; “A Comparative Evaluation of Supervised and Unsupervised Methods for Detecting Outliers”; Proceedings of the 2nd International Conference on Inventive Communication and Computational Technologies (ICICC… [cited by applicant]
USPTO; Final Office Action issued in U.S. Appl. No. 16/786,101 mailed Sep. 14, 2022. [cited by applicant]
USPTO; Non-Final Office Action issued in U.S. Appl. No. 16/786,101 mailed Apr. 20, 2022. [cited by applicant]
USPTO; Notice of Allowance issued in U.S. Appl. No. 16/786,101 mailed Mar. 14, 2023. [cited by applicant]
Webster et al; U.S. Appl. No. 16/786,101, filed Feb. 10, 2020. [cited by applicant]