IP Library Granted Patent US 8,307,437
Granted Patent B2
US 8,307,437 · App. 12/944,567 · Granted Nov 6, 2012

Classification of software on networked systems

Assignee: McAfee, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,307,437
App. No.
12/944,567
Granted
Nov 6, 2012
Kind
B2
Abstract

A method and system for the classification of software in networked systems, includes: determining a software received by a sensor is attempting to execute on a computer system of the sensor; classifying the software as authorized or unauthorized to execute, and gathering information on the software by the sensor if the software is classified as unauthorized to execute. The sensor sends the information on the software to one or more actuators, which determine whether or not to act on one or more targets based on the information. If so, then the actuator sends a directive to the target(s). The target(s) updates its responses according to the directive. The classification of the software is definitive and is not based on heuristics or rules or policies and without any need to rely on any a priori information about the software.

Claims (59)

1. A method, comprising:

receiving information from a sensor, wherein the information relates to a software classified by the sensor as unauthorized to execute on a computing system of the sensor;

evaluating one or more pieces of data that includes the information, wherein the evaluating includes collating the one or more pieces of data;

determining if any subset of the data can represent an identifier of the unauthorized software, wherein the subset is recognizable by a target type comprising a functionality of a target to update a response according to a directive specifying an action based on the subset;

identifying the target type;

generating the directive for the identified target type; and

communicating the directive to one or more targets of the identified target type.

2. The method of claim 1 , wherein the information comprises at least one of:

network packets which encoded the unauthorized software;

source and destination IP addresses and ports indicating a network connection of the network packets which encoded the unauthorized software;

a packet payload signature and/or a packet header signature; and

a checksum of the unauthorized software.

3. The method of claim 1 , wherein the directive includes the identifier of the unauthorized software to be compared to a corresponding identifier of other software on at least one of the one or more targets, wherein if the identifier of the unauthorized software matches the corresponding identifier of the other software then an action indicated by the directive is performed.

4. The method of claim 1 , wherein the one or more targets comprise a network-node, wherein the directive comprises instructions to restrict network traffic.

5. The method of claim 1 , wherein the one or more targets comprise a computer, wherein the directive comprises information identifying software to be blocked from execution on the computer.

6. The method of claim 1 , wherein the one or more targets comprise a manager, wherein the directive comprises information for adjusting a behavior of a network-node coupled to the manager, such that the network-node restricts network traffic.

7. The method of claim 1 , wherein the one or more targets comprise a manager, wherein the directive comprises information for adjusting a behavior of a computer coupled to the manager, such that the computer identifies software to be blocked from execution.

8. A method, comprising:

receiving a directive from an actuator, wherein the directive comprises a result of an analysis of an attempted execution by a software on a computing system of a sensor, wherein the software was classified by the sensor as unauthorized to execute on the computing system of the sensor, wherein the analysis comprises:

evaluating one or more pieces of data that includes information related to the attempted execution, wherein the evaluating comprises collating the one or more pieces of data;

determining if any subset of the data can represent an identifier of the unauthorized software, wherein the subset is recognizable by a target type comprising a functionality of a target to update a response according to the directive, wherein the directive specifies an action based on the subset;

identifying the target type;

generating the directive for the identified target type; and

performing an action on one or more targets of the identified target type based on the directive.

9. The method of claim 8 , wherein the directive includes the identifier of the unauthorized software to be compared to a corresponding identifier of other software on the target, wherein the action is performed if the identifier of the unauthorized software matches the corresponding identifier of the other software.

10. The method of claim 8 , wherein the action comprises restricting network traffic.

11. The method of claim 8 , wherein the action comprises blocking subsequent attempted executions of the unauthorized software.

12. An apparatus, comprising:

at least one actuator coupled to a network system, wherein the at least one actuator:

receives information from a sensor, wherein the information relates to a software unauthorized to execute on a computer system of the sensor;

evaluates one or more pieces of data that includes the information, including by collating the one or more pieces of data;

determines if any subset of the data can represent an identifier of the unauthorized software, wherein the subset is recognizable by a target type comprising a functionality of a target to update a response according to a directive, wherein the directive specifies an action based on the subset;

identifying the target type;

generating the directive for the identified target type; and

distributes the directive to one or more targets of the identified target type.

13. The apparatus of claim 12 , wherein the directive includes the identifier of the unauthorized software to be compared to a corresponding identifier of other software on at least one of the one or more targets, wherein if the identifier of the unauthorized software matches the corresponding identifier of the other software then an action indicated by the directive is performed.

14. The apparatus of claim 12 , wherein the one or more targets comprise a network-node, wherein the directive comprises instructions to restrict network traffic.

15. The apparatus of claim 12 , wherein the one or more targets comprise a computer, wherein the directive comprises information identifying software to be blocked from execution.

16. The apparatus of claim 12 , wherein the one or more targets comprise a manager, wherein the directive comprises information for adjusting a behavior of a network-node coupled to the manager, such that the network-node restricts network traffic.

17. The apparatus of claim 12 , wherein the one or more targets comprise a manager, wherein the directive comprises information for adjusting a behavior of a computer coupled to the manager, such that the computer identifies software to be blocked from execution.

18. Logic encoded in a computer that includes code for execution and when executed by a processor is operable to perform operations comprising:

receiving information from a sensor on a software, wherein the software was classified by the sensor as unauthorized to execute on a computing system of the sensor, wherein the information is related to an attempted execution of the software on the computing system;

evaluating one or more pieces of data that includes the information, wherein the evaluating comprises collating the one or more pieces of data;

determining if any subset of the data can represent an identifier of the unauthorized software, wherein the subset is recognizable by a target type comprising a functionality of a target to update a response according to the directive, wherein a directive specifies an action based on the subset;

identifying the target type;

generating the directive for the identified target type; and

communicating the directive to one or more targets of the identified target type.

19. Logic encoded in a computer that includes code for execution and when executed by a processor is operable to perform operations comprising:

receiving a directive from an actuator, wherein the directive comprises a result of an analysis of an attempted execution by a software on a computing system of a sensor, wherein the software was classified as unauthorized to execute on the computing system of the sensor, wherein the analysis comprises:

evaluating one or more pieces of data that includes information related to the attempted execution, wherein the evaluating comprises collating the one or more pieces of data;

determining if any subset of the data can represent an identifier of the unauthorized software, wherein the subset is recognizable by a target type comprising a functionality of a target to update a response according to the directive, wherein the directive specifies an action based on the subset;

identifying the target type;

generating the directive for the identified target type; and

performing an action on a target of the identified target type based on the directive.

20. The logic of claim 18 , wherein the information comprises at least one of:

network packets which encoded the unauthorized software;

source and destination IP addresses and ports indicating a network connection of the network packets which encoded the unauthorized software;

a packet payload signature and/or a packet header signature; and

a checksum of the unauthorized software.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Nov 11, 2010
From: SOLIDCORE SYSTEMS, INC.
To: MCAFEE, INC.
Reel/Frame 025353/0711 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2010
From: SEBES, E. JOHN; BHARGAVA, RISHI
To: SOLIDCORE SYSTEMS, INC.
Reel/Frame 025353/0688 →
Continuity (2)
Division 11182320 · Jul 14, 2005
Related Publication 20110119760A1 · May 19, 2011