IP Library Granted Patent US 12,450,334
Granted Patent B2
US 12,450,334 · App. 18/431,016 · Granted Oct 21, 2025

Malware deterrence using computer environment indicators

Inventors: Nera Pershing Schwartz (Singapore, SG); Harish Tammaji Kulkarni (Singapore, SG); Kumudini Choyal (Tung Chung, HK); Mahesh Ramesh Bane (Mumbai, IN); Vaibhav Shankar Tambe (Dombiwali, IN)
Assignee: Bank of America Corporation
G06F21/53G06F21/566H04L63/1416H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,450,334
App. No.
18/431,016
Granted
Oct 21, 2025
Kind
B2
Abstract

A system for inoculating a computer network against malware is described. Specifically, environmental indicators used by anti-analysis and target filtering mechanisms of a malware program may be determined based on analysis within a virtual or physical sandbox environment. The environmental indicators may be sent to computing devices associated with the computing network. The malware program, based on the environmental indicators, may be spoofed to assume that a computing device is associated with an anti-malware system, and/or is a device that is not to be infected. Based on this assumption, the malware program may not execute within the computing device.

Claims (56)

1. An apparatus comprising at least one hardware processor and a memory storing computer-readable instructions that, when executed by the at least one hardware processor, cause the apparatus to:

determine an environmental indicator used by a target filtering mechanism associated with a malware program to prevent execution in a sandbox environment, wherein the environmental indicator comprises an indication of a file system structure of the sandbox environment;

determine whether the environmental indicator is within a predetermined percentile of environmental indicators, in a malware database, arranged in a priority order from lowest priority to highest priority, wherein the priority order of the environmental indicators is based on respective quantities of malware programs using the environmental indicators; and

based on determining that the environmental indicator is within the predetermined percentile of the environmental indicators:

generate, based on the environmental indicator, an inoculation message for transmission to one or more computing devices in a computing network, wherein the inoculation message comprises the indication of the file system structure; and

send, to the one or more computing devices, the inoculation message, wherein the inoculation message causes the one or more computing devices to integrate the indication of the file system structure into corresponding computing environments of the one or more computing devices.

2. The apparatus of claim 1 , wherein the computer-readable instructions, when executed by the at least one hardware processor, cause the apparatus to determine the environmental indicator by causing:

determining that the malware program has not executed within the sandbox environment, and

determining that the environmental indicator corresponds to the sandbox environment.

3. The apparatus of claim 1 , wherein the inoculation message further comprises at least one of:

a registry entry in the sandbox environment;

hardware information associated with the sandbox environment; or

combinations thereof.

4. The apparatus of claim 1 , wherein the computer-readable instructions, when executed by the at least one hardware processor, cause the apparatus to:

determine a second environmental indicator used by an anti-analysis mechanism associated with the malware program to prevent execution of the malware program,

wherein the inoculation message comprises the second environmental indicator; and

wherein the inoculation message causes the one or more computing devices to integrate the second environmental indicator into corresponding computing environments of the one or more computing devices.

5. The apparatus of claim 1 , wherein the target filtering mechanism prevents execution of the malware program based on detection of a registry entry indicating a specified keyboard language, and wherein the inoculation message further comprises the registry entry.

6. The apparatus of claim 1 , wherein the inoculation message further comprises a registry entry, and wherein the inoculation message causes the one or more computing devices to add the registry entry to respective system registries of the one or more computing devices.

7. The apparatus of claim 1 , wherein the malware database comprises indications of a plurality of malware programs and associated environmental indicators, wherein the determining the environmental indicator is based on the malware database.

8. The apparatus of claim 1 , wherein the computer-readable instructions, when executed by the at least one hardware processor, cause the apparatus to present a user interface configured to receive user input for at least one of:

modifying the malware database;

selecting the one or more computing devices; or

combination thereof.

9. The apparatus of claim 1 , wherein the computer-readable instructions, when executed by the at least one hardware processor, cause the apparatus to:

receive information indicating that at least a second computing device in the computing network is infected with the malware program, wherein the sending the inoculation message is based on receiving the information.

10. A method at a malware security platform in a computing network, the method comprising:

determining an environmental indicator used by a target filtering mechanism associated with a malware program to prevent execution in a sandbox environment, wherein the environmental indicator comprises an indication of a file system structure of the sandbox environment;

determining whether the environmental indicator is within a predetermined percentile of environmental indicators, in a malware database, arranged in a priority order from lowest priority to highest priority, wherein the priority order of the environmental indicators is based on respective quantities of malware programs using the environmental indicators; and

based on determining that the environmental indicator is within the predetermined percentile of the environmental indicators:

generating, based on the environmental indicator, an inoculation message for transmission to one or more computing devices in the computing network, wherein the inoculation message comprises the indication of the file system structure; and

sending, to the one or more computing devices, the inoculation message, wherein the inoculation message causes the one or more computing devices to integrate the indication of the file system structure into corresponding computing environments of the one or more computing devices.

11. The method of claim 10 , wherein the determining the environmental indicator comprises:

determining that the malware program has not executed within the sandbox environment, and

determining that the environmental indicator corresponds to the sandbox environment.

12. The method of claim 10 , wherein the inoculation message further comprises at least one of:

a registry entry in the sandbox environment;

hardware information associated with the sandbox environment; or

combinations thereof.

13. The method of claim 10 , further comprising:

determine a second environmental indicator used by an anti-analysis mechanism associated with the malware program to prevent execution of the malware program,

wherein the inoculation message comprises the second environmental indicator; and

wherein the inoculation message causes the one or more computing devices to integrate the second environmental indicator into corresponding computing environments of the one or more computing devices.

14. The method of claim 10 , wherein the target filtering mechanism prevents execution of the malware program based on detection of a registry entry indicating a specified keyboard language, and wherein the inoculation message further comprises the registry entry.

15. The method of claim 10 , wherein the inoculation message further comprises a registry entry, and wherein the inoculation message causes the one or more computing devices to add the registry entry to respective system registries of the one or more computing devices.

16. The method of claim 10 , wherein the malware database comprises indications of a plurality of malware programs and associated environmental indicators, wherein the determining the environmental indicator is based on the malware database.

17. The method of claim 10 , further comprising presenting a user interface configured to receive user input for at least one of:

modifying the malware database;

selecting the one or more computing devices; or

combination thereof.

18. A non-transitory computer readable medium storing computer executable instructions that, when executed by a processor, cause a malware security platform to perform:

determining an environmental indicator used by a target filtering mechanism associated with a malware program to prevent execution in a sandbox environment, wherein the environmental indicator comprises an indication of a file system structure of the sandbox environment;

determining whether the environmental indicator is within a predetermined percentile of environmental indicators, in a malware database, arranged in a priority order from lowest priority to highest priority, wherein the priority order of the environmental indicators is based on respective quantities of malware programs using the environmental indicators; and

based on determining that the environmental indicator is within the predetermined percentile of the environmental indicators:

generating, based on the environmental indicator, an inoculation message for transmission to one or more computing devices in a computing network, wherein the inoculation message comprises the indication of the file system structure; and

sending, to the one or more computing devices, the inoculation message, wherein the inoculation message causes the one or more computing devices to integrate the indication of the file system structure into corresponding computing environments of the one or more computing devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2024
From: SCHWARTZ, NERA PERSHING; KULKARNI, HARISH TAMMAJI; CHOYAL, KUMUDINI; BANE, MAHESH RAMESH; TAMBE, VAIBHAV SHANKAR
To: BANK OF AMERICA CORPORATION
Reel/Frame 066777/0272 →
Continuity (2)
Continuation 17540778 · Dec 2, 2021
Related Publication 20240202317A1 · Jun 20, 2024
References Cited (17)
US 8201246B1 · Wu et al. · 2012 [cited by applicant]
US 8875289B2 · Mahaffey et al. · 2014 [cited by applicant]
US 9571520B2 · Ramabhatta et al. · 2017 [cited by applicant]
US 9760715B2 · Rothwell · 2017 [cited by applicant]
US 9858416B2 · Niemela et al. · 2018 [cited by applicant]
US 10133863B2 · Bu et al. · 2018 [cited by applicant]
US 10181026B2 · Stolfo et al. · 2019 [cited by applicant]
US 20170132411A1 · Salajegheh et al. · 2017 [cited by applicant]
US 20220060502A1 · Sheedy · 2022 [cited by examiner]
CA 2546720A1 · 2006 [cited by examiner]
KR 20180029047A · 2018 [cited by applicant]
RU 2566329C2 · 2015 [cited by applicant]
WO WO2018004572A1 · 2018 [cited by examiner]
WO 2020006415A1 · 2020 [cited by applicant]
Caltagirone et al., “The Four Types of Threat Detection With Case-Studies in Industrial Control Systems (ICS)”; https://www.dragos.com/wp-content/uploads/The_Four_Types-of_Threat_Detection.pdf; article; 15 pages; Jul. 1… [cited by applicant]
Kelly, “Indicators of Compromise TeslaCrypt Malware”; https://www.giac.org/paper/gcia/11671/indicators-compromise-teslacrypt-malware/149373; Global Information Assurance Certification Paper; 23 pages; Feb. 16, 2017; the… [cited by applicant]
Lindorfer, “Detecting Environment-Sensitive Malware”; https://publik.tuwien.ac.at/files/publik_273621.pdf; Master's Thesis; 76 pages; Apr. 11, 2011; Vienna University of Technology. [cited by applicant]