IP Library Granted Patent US 10,289,846
Granted Patent B2
US 10,289,846 · App. 15/099,993 · Granted May 14, 2019

Systems and methods for detecting and addressing remote access malware

Inventor: Javier Fernando Vargas Gonzalez (Bogota D.C., CO)
Assignee: EASY SOLUTIONS ENTERPRISES CORP.
G06F21/566G06F21/55G06F21/554G06F21/56H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,289,846
App. No.
15/099,993
Granted
May 14, 2019
Kind
B2
Abstract

Systems and methods to detect remote access malware activities, via: detecting, in a computing device, first input events in an operating system of the computing device; detecting, in the computing device, second input events received in an application running in the computing device; detecting, in the computing device, a mismatch between the first input events detected in the operating system and the second input events received in the application running in the computing device; and in response to the mismatch being detected, generating an alert indicating a threat of the application being attached by remote access malware.

Claims (61)

1. A method to detect remote access malware activities, the method comprising:

embedding first software in an operating system of a computing device;

detecting, by the first software running in the computing device, first input events received in the operating system of the computing device;

embedding second software in an application running in the computing device;

detecting, by the second software running in the computing device, second input events received in the application running in the computing device;

detecting, via communications between the first software and the second software in the computing device, an input event received in the application, the input event corresponding to a mismatch between the first input events received in the operating system and the second input events received in the application running in the computing device,

wherein the mismatch is detected based on a determination that the second input events received in the application running in the computing device are a threshold amount more than the first input events detected in the operating system of the computing device; and

in response to the mismatch being detected,

generating an alert indicating a threat of the application being attacked by remote access malware;

communicating, from the computing device, the alert to a server over a computer network;

receiving, from the server, an instruction to block the input event that corresponds to the mismatch; and

blocking, by the second software in the application, the input event that corresponds to the mismatch.

2. The method of claim 1 , wherein the alert causes the server to generate a notification about the threat to a user device.

3. The method of claim 1 , wherein the input event is one of the second input events, the method further comprising, in response to the input event received in the application,

transmitting, from the second software in the application to the first software in the operating system, a request for a confirmation that the input event corresponds to one of the first input events detected in the operating system of the computing device.

4. The method of claim 3 , further comprising:

determining, via the first software running in the operating system, whether the input event received in the application is originated from the first input events detected in the operating system.

5. The method of claim 4 , further comprising:

counting, via the first software running in the operating system, the first input events, wherein the determining of the input event received in the application is originated from the first input events detected in the operating system is based on the counting.

6. The method of claim 4 , further comprising:

tracking, via the first software running in the operating system, types of the first input events, wherein the determining of the input event received in the application is originated from the first input events detected in the operating system is based on the types tracked for the first input events in the operating system.

7. The method of claim 4 , further comprising:

tracking, via the first software running in the operating system, timestamps of the first input events, wherein the determining of the input event received in the application is originated from the first input events detected in the operating system is based on the timestamps tracked for the first input events in the operating system.

8. The method of claim 1 , further comprising:

embedding, via the first software running in the operating system, data in input events communicated from the operating system to the application;

wherein the detecting of the mismatch between the first input events detected in the operating system and the second input events received in the application running in the computing device includes:

detecting the input event, among the second input events, that does not have the data provided by the first software running in the operating system.

9. The method of claim 8 , wherein the data is a secret shared between the first software and the second software.

10. The method of claim 8 , wherein the data includes a digital signature of the first software.

11. The method of claim 8 , further comprising:

blocking, via the second software in the application, the input event that does not have the data provided by the first software running in the operating system.

12. The method of claim 1 , wherein the mismatch is detected based on comparing:

amount and type of the first input events detected in the operating system of the computing device, and

amount and type of the second input events received in the application running in the computing device.

13. The method of claim 1 , further comprising:

determining a risk of the threat based on comparing amounts of input events detected in the operating system and amounts of input events received in the application during a plurality of time slots respectively.

14. A non-transitory computer storage medium storing instructions configured to instruct a computing device to perform a method, the method comprising:

detecting, using first software embedded in an operating system of a computing device, first input events received in the operating system of the computing device;

embedding, via the first software running in the operating system, data in input events communicated from the operating system to the application, wherein the data includes a secret shared between the first software and the second software;

detecting, using second software embedded in an application running in the computing device, second input events received in the application running in the computing device;

detecting, via communications between the first software and the second software in the computing device, an input event received in the application, the input event corresponding to a mismatch between the first input events received in the operating system and the second input events received in the application running in the computing device, wherein the mismatch is detected in response to a determination that the input event, among the second input event, does not have the data provided by the first software running in the operating system,

wherein the mismatch is detected based on a determination that the second input events received in the application running in the computing device are a threshold amount more than the first input events detected in the operating system of the computing device; and

in response to the mismatch being detected,

generating an alert indicating a threat of the application being attacked by remote access malware;

communicating, from the computing device, the alert to a server over a computer network;

receiving, from the server, an instruction to block the input event that corresponds to the mismatch; and

blocking, via the second software in the application, the input event that corresponds to the mismatch.

15. A computing device, comprising:

a communicating device;

at least one microprocessor; and

a memory storing instructions configured to instruct the at least one microprocessor to:

detect, using first software embedded in an operating system of a computing device, first input events received in the operating system of the computing device;

embed, via the first software running in the operating system, data in input events communicated from the operating system to the application, wherein the data includes a digital signature of the first software;

detect, using second software embedded in an application running in the computing device, second input events received in the application running in the computing device; and

detect, via communications between the first software and the second software in the computing device, an input event received in the application, the input event corresponding to a mismatch between the first input events detected in the operating system and the second input events received in the application running in the computing device, wherein the mismatch is detected in response to a determination that the input event, among the second input event, does not have the data provided by the first software running in the operating system, and

wherein the mismatch is detected based on a determination that the second input events received in the application running in the computing device are a threshold amount more than the first input events detected in the operating system of the computing device; and

in response to the mismatch being detected,

generate an alert indicating a threat of the application being attacked by remote access malware;

communicating, from the computing device, the alert to a server over a computer network;

receiving, from the server, an instruction to block the input event that corresponds to the mismatch; and

blocking, via the second software in the application, the input event that corresponds to the mismatch.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2016
From: VARGAS GONZALEZ, JAVIER FERNANDO
To: EASY SOLUTIONS ENTERPRISES CORP.
Reel/Frame 039755/0334 →
Continuity (2)
Provisional Application 62149295 · Apr 17, 2015
Related Publication 20160308888A1 · Oct 20, 2016