IP Library › Granted Patent US 10,382,468
Granted Patent B2
US 10,382,468 · App. 15/640,622 · Granted Aug 13, 2019

Malware identification via secondary file analysis

Inventor: Craig Dods (Stittsville, CA)
Assignee: Juniper Networks, Inc.
H04L63/1425G06F21/53G06F21/554G06F21/566H04L63/145H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,468
App. No.
15/640,622
Granted
Aug 13, 2019
Kind
B2
Abstract

A device may include one or more processors to receive a file that may be analyzed for malware; open the received file in a secure environment; determine that a secondary file in the secure environment may have been accessed based on the received file being opened; analyze the secondary file in the secure environment to identify malware; and/or perform an action associated with the received file based on the secondary file being analyzed.

Claims (78)

1. A device, comprising:

one or more memories; and

one or more processors to:

receive a file that is to be analyzed for malware;

open the received file in a secure environment;

install a secondary file in the secure environment to permit a malicious object of the received file to embed a malicious payload of the received file in the secondary file,

the secondary file being a file within a directory of a computing environment that runs an application or program that opens the received file;

determine that the secondary file in the secure environment has been accessed based on the received file being opened by a user;

analyze the secondary file in the secure environment to identify malware; and

perform an action associated with the received file based on the secondary file being analyzed,

where the secure environment is implemented on a computing resource of a cloud environment, and

where the one or more processors, when performing the action associated with the received file, are to:

quarantine a source of the received file based on identifying the malware.

2. The device of claim 1 , where the one or more processors, when determining that the secondary file has been accessed, are to:

monitor a directory of the secure environment after opening the received file; and

detect that the secondary file has been modified based on monitoring the directory.

3. The device of claim 1 , where the one or more processors, when determining that the secondary file has been accessed, are to:

monitor a designated set of files, in the secure environment, associated with the received file,

the designated set of files comprising the secondary file.

4. The device of claim 1 , where the one or more processors, when analyzing the secondary file in the secure environment, are to:

conduct at least one of a static analysis of the secondary file, a signature-based analysis of the secondary file, or a statistical-based analysis of the secondary file to detect the malware.

5. The device of claim 1 , where the one or more processors, when analyzing the secondary file in the secure environment, are to:

conduct at least one of a dynamic analysis of the secondary file or a behavior-based analysis of the secondary file to detect the malware.

6. The device of claim 1 , where the one or more processors, when analyzing the secondary file in the secure environment, are to:

identify an application associated with the secondary file, and

use the application to open the secondary file in the secure environment.

7. The device of claim 1 , where the one or more processors are further to:

prevent the received file from reaching an intended target of the received file based on identifying the malware.

8. The device of claim 1 , where the one or more processors are further to:

update a malware database to include information associated with the malware based on identifying the malware.

9. The device of claim 1 , where the one or more processors are further to:

place information associated with the source of the received file on a blacklist based on identifying the malware.

10. The device of claim 1 , where the one or more processors are further to:

remove, based on identifying the malware, the malicious object from the received file to generate a clean file; and

transmit the clean file to an intended target of the received file.

11. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors, cause the one or more processors to:

receive a file that is to be analyzed for malware;

open the received file in a first secure environment;

install a secondary file in the first secure environment to permit a malicious object of the received file to embed a malicious payload of the received file in the secondary file,

the secondary file being a file within a directory of a computing environment that runs an application or program that opens the received file;

determine that the secondary file in the first secure environment has been accessed after opening, by a user, the received file;

open the secondary file in a second secure environment to identify malware; and

perform an action associated with the received file based on identifying the malware,

where the first secure environment is implemented on a computing resource of a cloud environment, and

where the one or more instructions, that cause the one or more processors to perform the action associated with the received file, cause the one or more processors to:

quarantine a source of the received file based on identifying the malware.

12. The non-transitory computer-readable medium of claim 11 , where the one or more instructions, that cause the one or more processors to open the secondary file in the second secure environment, cause the one or more processors to:

copy the secondary file, and

open the copy of the secondary file in the second secure environment,

where the second secure environment is separate from the first secure environment.

13. The non-transitory computer-readable medium of claim 11 , where the one or more instructions further cause the one or more processors to:

prevent the received file from reaching an intended target of the received file based on identifying malware.

14. The non-transitory computer-readable medium of claim 11 , where the one or more instructions further cause the one or more processors to:

update a malware database to include information associated with the malware.

15. The non-transitory computer-readable medium of claim 11 , where the one or more instructions, further cause the one or more processors to

place the source of the received file on a blacklist based on identifying the malware.

16. The non-transitory computer-readable medium of claim 11 , where the one or more instructions further cause the one or more processors to:

provide information regarding the malware to a security platform to modify a future operation of the security platform.

17. A method, comprising:

receiving, by one or more devices of a security platform, a file that into be analyzed for malware;

opening, by at least one of the one or more devices, the received file in a secure environment;

installing, by at least one of the one or more devices, a secondary file in the secure environment to permit a malicious object of the received file to embed a malicious payload of the received file in the secondary file,

the secondary file being a file within a directory of a computing environment that runs an application or program that opens the received file;

determining, by at least one of the one or more devices, that the secondary file in the secure environment has been modified based on the received file being opened by a user;

opening, by at least one of the one or more devices, the secondary file in the secure environment;

identifying, by at least one of the one or more devices, malware after opening the secondary file; and

performing, by at least one of the one or more devices, an action associated with the received file based on identifying the malware,

where the secure environment is implemented on a computing resource of a cloud environment, and

where performing the action comprises:

quarantining a source of the received file based on identifying the malware.

18. The method of claim 17 , further comprising:

removing the malicious object from the received file based on identifying the malware to generate a clean file; and

transmitting the clean file to an intended target of the received file.

19. The method of claim 17 further comprising:

providing information regarding the malware to the security platform to modify a future operation of the security platform.

20. The method of claim 17 , where performing the action comprises:

placing the source of the received file on a blacklist based on identifying the malware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2017
From: DODS, CRAIG
To: JUNIPER NETWORKS, INC.
Reel/Frame 042881/0926 →
Continuity (1)
Related Publication 20190007436A1 · Jan 3, 2019
Cited By (59)
US 12,197,583 US 12,197,590 US 12,219,360 US 12,225,039 US 12,231,433 US 12,238,177 US 12,242,520 US 12,243,294 US 12,244,617 US 12,244,637 US 12,245,036 US 12,255,877 US 12,266,209 US 12,267,355 US 12,273,392 US 12,278,845 US 12,282,545 US 12,284,206 US 12,284,222 US 12,299,117 US 12,301,605 US 12,315,231 US 12,316,647 US 12,326,957 US 12,355,817 US 12,361,680 US 12,373,240 US 12,375,497 US 12,388,711 US 12,395,534 US 12,413,629 US 12,417,253 US 12,425,464 US 12,430,429 US 12,445,451 US 12,452,310 US 12,470,602 US 12,489,734 US 12,500,940 US 12,513,073 US 12,519,857 US 12,537,838 US 12,537,871 US 12,542,812 US 12,561,620 US 12,572,651 US 12,580,945 US 12,580,960 US 12,592,959 US 12,593,210 US 12,596,804 US 12,598,216 US 12,615,242 US 12,632,572 US 12,647,362 US 12,676,908 US 12,684,018 US 12,695,765 US 12,712,920