IP Library Granted Patent US 7,941,853
Granted Patent B2
US 7,941,853 · App. 12/125,263 · Granted May 10, 2011

Distributed system and method for the detection of eThreats

Assignee: Deutsche Telekom AG
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,941,853
App. No.
12/125,263
Granted
May 10, 2011
Kind
B2
Abstract

The invention relates to a distributed system for detecting eThreats that propagate in a network, which comprises: (a) graphs database storing at least one propagation graph, each graph describing the typical propagation over time of one eThreat class or a legitimate executable class within the network; (b) plurality of agents that are distributed in corresponding plurality of hosts within the network, each of said agents continuously monitoring the corresponding host and reporting to a Central Decision Maker (CDM) the identity of any new suspected executable, and the time in which said suspected executable has been first detected by said agent; (c) a CDM for: (c.1) receiving all said reports from said plurality of agents; (c.2) creating from said reports for each suspected executable a corresponding propagation graph which reflects the propagation characteristics over time of said suspected executable within the network, and (c.3) comparing each of said created graphs with said stored at least one propagation graph; (c.4) upon finding a similarity above a predefined threshold between a created graph and one of the stored graphs, concluding respectively that said executable belongs to the class as defined by said stored graph; and (c.5) conveying said conclusion to said agents, for optionally taking an appropriate action.

Claims (14)

1. A distributed computer implemented system for detecting eThreats that propagate in a network, which comprises:

graphs database within a Central Decision Maker module (CDM) storing in digital form at least one propagation graph, each propagation graph describing the typical propagation over time of one eThreat class or a legitimate executable class within the network;

plurality of agents that are distributed in corresponding plurality of host computers within the network, each of said agents continuously monitoring a corresponding host computer and reporting to said Central Decision Maker module the identity of any new suspected executable, and the time in which said suspected executable has been first detected by said agent;

said CDM module which comprises:

(i) a graph creation unit for receiving all said reports from said plurality of agents, creating from said reports for each suspected executable a corresponding propagation graph which reflects the propagation characteristics over time of said suspected executable within the network,

(ii) a comparator for (a) comparing each of said created graphs with said stored at least one propagation graph, (b) upon finding a similarity above a predefined threshold between a created graph and one of the stored graphs, concluding respectively that said executable belongs to the class as defined by said stored graph, and (c) conveying said conclusion to said agents, for optionally taking an appropriate action at the host computers respectively; and

wherein, one of the graphs in said database which relates to a worm-type eThreat class has a value of α as a function of time which is constant within a predefined time interval and larger than zero during an initial propagation phase of said executable, and the CDM concludes that the executable is a worm when a similarity above a predefined threshold is found between said created graph and said stored graph which relates to a worm, and wherein α=(number of infected host computers at time t)/(number of infected host computers at time t−1).

2. The system according to claim 1 , wherein the report by the agents also comprises the identity of the report issuing agent.

3. The system according to claim 1 , wherein the comparison by the CDM module is repeated plurality of times for each executable until a final conclusion is reached.

4. The system according to claim 1 , wherein each of the agents further performs analysis at the host computer location, for at least reaching a temporary conclusion regarding the type of the executable in question, and further sends said temporary conclusion to said CDM module.

5. The system according to claim 1 , wherein further:

the database comprises null graphs; and

the CDM module calculates from the created graph the value of α as a function of time, and if the value of α is found to be approximately constant within predefined limits and larger than zero during an initial propagation phase of said executable, the CDM module concludes that the executable is a worm.

6. The system according to claim 1 , wherein the propagation is defined as the number of host computers that include an executable respectively as a function of time.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2008
From: ROZENBERG, BORIS; GUDES, EHUD; ELOVICI, YUVAL
To: BEN-GURION UNIVERSITY OF THE NEGEV RESEARCH & DEVELOPMENT AUTHORITY
Reel/Frame 021016/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2008
From: BEN-GURION UNIVERSITY OF THE NEGEV RESEARCH & DEVELOPMENT AUTHORITY
To: DEUTSCHE TELEKOM AG
Reel/Frame 021016/0099 →
Priority Claims (1)
IL 183390 · May 24, 2007 · national
Continuity (1)
Related Publication 20080313734A1 · Dec 18, 2008