IP Library Granted Patent US 12,039,038
Granted Patent B2
US 12,039,038 · App. 18/302,885 · Granted Jul 16, 2024

Behavioral threat detection definition and compilation

Inventors: Eric Klonowski (Broomfield, CO); Fred Krenson (Denver, CO)
Assignee: OPEN TEXT INC.
G06F21/552G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,039,038
App. No.
18/302,885
Granted
Jul 16, 2024
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for behavioral threat detection definition. In an example, a behavior rule comprising a set of rule instructions is used to define one or more events indicative of a behavior. For example, a set of events from which one event must be matched may be defined or a set of events from which all events must be matched may be defined. In some examples, events are matched based on an event name or type, or may be matched based on one or more parameters. Exact and/or inexact matching may be used. The set of rule instructions ultimately specifies one or more halt instructions, thereby indicating that a determination as to the presence of the behavior has been made. Example determinations include, but are not limited to, a match determination, a non-match determination, or an indication that additional monitoring should be performed.

Claims (71)

1. A security service system comprising:

a processor;

a data store storing behavior rules, each behavior rule specifying an event associated with a respective behavior; and

a non-transitory computer readable medium, comprising instructions for:

providing the stored behavior rules to one or more computing devices, wherein each computing device is configured for:

encountering a first instruction of a first executing behavior rule specifying an event, wherein the event is associated with a respective behavior;

pausing execution of the first executing behavior rule;

determining that a first occurrence of the event specified by the first instruction has occurred;

resuming execution of the first executing behavior rule;

evaluating first information associated with the first occurrence of the event based on a second instruction of the first executing behavior rule;

making a first determination as to the respective behavior based on the second instruction of the first executing behavior rule and the evaluation of the first information associated with the first occurrence of the event; and

performing, by the respective computing device, a first action based on the first determination as to the respective behavior.

2. The security service system of claim 1 , wherein the first executing behavior rule is related to a first context.

3. The security service system of claim 2 , wherein the first occurrence of the event is associated with the first context and the first action is associated with the first context.

4. The security service system of claim 3 , wherein the execution of the first executing behavior rule was initiated by the occurrence of a third event.

5. The security service system of claim 4 , wherein the third event is associated with the first context.

6. The security service system of claim 3 , wherein each computing device is further configured for:

encountering the first instruction of a second executing behavior rule specifying the event, wherein the event is associated with the respective behavior, the second executing behavior rule related to a second context;

pausing execution of the second executing behavior rule;

determining that a second occurrence of the event specified by the first instruction has occurred in association with the second context;

resuming execution of the second executing behavior rule;

evaluating second information associated with the second occurrence of the event based on the second instruction of the second executing behavior rule,

making a second determination as to the respective behavior based on the second instruction of the second executing behavior rule and the evaluation of the second information associated with the second occurrence of the event; and

performing, by the respective computing device, a second action based on the second determination as to the respective behavior.

7. The security service system of claim 4 , wherein the first executing behavior rule is executed by a first rule virtual machine and the second executing behavior rule is executed by a second rule virtual machine.

8. A security service method, comprising:

storing a plurality of behavior rules in a data store, each behavior rule specifying an event associated with a respective behavior; and

providing the plurality of stored behavior rules to one or more computing devices, wherein each computing device is configured for:

encountering a first instruction of a first executing behavior rule specifying an event, wherein the event is associated with a respective behavior;

pausing execution of the first executing behavior rule;

determining that a first occurrence of the event specified by the first instruction has occurred;

resuming execution of the first executing behavior rule;

evaluating first information associated with the first occurrence of the event based on a second instruction of the first executing behavior rule;

making a first determination as to the respective behavior based on the second instruction of the first executing behavior rule and the evaluation of the first information associated with the first occurrence of the event; and

performing, by the respective computing device, a first action based on the first determination as to the respective behavior.

9. The method of claim 8 , wherein the first executing behavior rule is related to a first context.

10. The method of claim 9 , wherein the first occurrence of the event is associated with the first context and the first action is associated with the first context.

11. The method of claim 10 , wherein the execution of the first executing behavior rule was initiated by the occurrence of a third event.

12. The method of claim 11 , wherein the third event is associated with the first context.

13. The method of claim 10 , wherein each computing device is further configured for:

encountering the first instruction of a second executing behavior rule specifying the event, wherein the event is associated with the respective behavior, the second executing behavior rule related to a second context;

pausing execution of the second executing behavior rule;

determining that a second occurrence of the event specified by the first instruction has occurred in association with the second context;

resuming execution of the second executing behavior rule;

evaluating second information associated with the second occurrence of the event based on the second instruction of the second executing behavior rule;

making a second determination as to the respective behavior based on the second instruction of the second executing behavior rule and the evaluation of the second information associated with the second occurrence of the event; and

performing, by the respective computing device, a second action based on the second determination as to the respective behavior.

14. The method of claim 13 , wherein the first executing behavior rule is executed by a first rule virtual machine and the second executing behavior rule is executed by a second rule virtual machine.

15. A non-transitory computer readable medium, comprising instructions for:

storing a plurality of behavior rules in a data store, each behavior rule specifying an event associated with a respective behavior; and

providing the plurality of stored behavior rules to one or more computing devices, wherein each computing device is configured for:

encountering a first instruction of a first executing behavior rule specifying an event, wherein the event is associated with a respective behavior;

pausing execution of the first executing behavior rule;

determining that a first occurrence of the event specified by the first instruction has occurred;

resuming execution of the first executing behavior rule;

evaluating first information associated with the first occurrence of the event based on a second instruction of the first executing behavior rule;

making a first determination as to the respective behavior based on the second instruction of the first executing behavior rule and the evaluation of the first information associated with the first occurrence of the event; and

performing, by the respective computing device, a first action based on the first determination as to the respective behavior.

16. The non-transitory computer readable medium of claim 15 , wherein the first executing behavior rule is related to a first context.

17. The non-transitory computer readable medium of claim 16 , wherein the first occurrence of the event is associated with the first context and the first action is associated with the first context.

18. The non-transitory computer readable medium of claim 17 , wherein the execution of the first executing behavior rule was initiated by the occurrence of a third event.

19. The non-transitory computer readable medium of claim 18 , wherein the third event is associated with the first context.

20. The non-transitory computer readable medium of claim 17 , wherein each computing device is further configured for:

encountering the first instruction of a second executing behavior rule specifying the event, wherein the event is associated with the respective behavior, the second executing behavior rule related to a second context;

pausing execution of the second executing behavior rule;

determining that a second occurrence of the event specified by the first instruction has occurred in association with the second context;

resuming execution of the second executing behavior rule;

evaluating second information associated with the second occurrence of the event based on the second instruction of the second executing behavior rule;

making a second determination as to the respective behavior based on the second instruction of the second executing behavior rule and the evaluation of the second information associated with the second occurrence of the event; and

performing, by the respective computing device, a second action based on the second determination as to the respective behavior.

21. The non-transitory computer readable medium of claim 20 , wherein the first executing behavior rule is executed by a first rule virtual machine and the second executing behavior rule is executed by a second rule virtual machine.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2023
From: KLONOWSKI, ERIC; KRENSON, FRED
To: WEBROOT INC.
Reel/Frame 063503/0983 →
Continuity (3)
Continuation 17362112 · Jun 29, 2021
Continuation 16366040 · Mar 27, 2019
Related Publication 20230252135A1 · Aug 10, 2023
Cited By (2)
US 12,235,960 US 12,292,968