IP Library › Granted Patent US 10,437,996
Granted Patent B1
US 10,437,996 · App. 15/657,812 · Granted Oct 8, 2019

Classifying software modules utilizing similarity-based queries

Inventors: Zhou Li (Malden, MA); Martin Rosa (Quebec, CA); Zohar Duchin (Brookline, MA)
Assignee: EMC IP Holding Company LLC
G06F21/562G06F16/2255G06F16/245G06F16/285H04L63/20G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,437,996
App. No.
15/657,812
Filed
Jul 24, 2017
Granted
Oct 8, 2019
Kind
B1
Art Unit
2494
USPC
726/23
Abstract

A method includes preparing a representation of data associated with a plurality of software modules, the representation comprising similarity-based hashing of signatures constructed from a first subset of features of the plurality of software modules. The method also includes performing a similarity-based query utilizing the similarity-based hashing of signatures to identify one or more of the plurality of software modules as candidate software modules matching a received seed software module. The method further includes computing distances between the candidate software modules and the seed software module utilizing a second subset of features of the plurality of software modules, classifying one or more of the candidate software modules as a designated type based on the computed distances, generating a notification comprising a list of the classified candidate software modules, and controlling access by one or more client devices associated with an enterprise to the candidate software modules in the list.

Claims (77)

1. A method comprising:

preparing a representation of data associated with a plurality of software modules, the representation comprising similarity-based hashing of signatures constructed from a first subset of features of the plurality of software modules, the first subset of features of the plurality of software modules comprising at least one of (i) one or more indicator of compromise features having a binary value range and (ii) one or more static features having an integer value range;

receiving a seed software module;

performing a similarity-based query utilizing the similarity-based hashing of signatures constructed from the first subset of features to identify one or more of the plurality of software modules as candidate software modules matching the seed software module;

computing distances between the candidate software modules and the seed software module utilizing a second subset of features of the plurality of software modules, at least one of the second subset of features comprising a textual feature;

classifying one or more of the candidate software modules as a designated software module type based on the computed distances;

generating a notification comprising a list of the candidate software modules classified as the designated software module type; and

modifying access by a given one of one or more client devices associated with an enterprise to a given one of the one or more of the candidate software modules in the list classified as the designated software module type;

wherein preparing the representation of data associated with the plurality of software modules comprises:

building a characteristic matrix having two or more rows each corresponding to one of the first subset of features;

converting each column of the characteristic matrix into a hash signature through a designated number of permutations; and

generating the similarity-based hashing of signatures by performing locality-sensitive hashing to build two or more bands of consecutive components of the hash signatures, each band comprising a concatenation of string values of two or more consecutive components of the hash signatures;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 further comprising:

receiving data associated with the plurality of software modules from a plurality of client devices associated with the enterprise; and

filtering the received data to remove one or more of the plurality of software modules that do not trigger one or more specified conditions and that are not of one or more specified types.

3. The method of claim 2 wherein the one or more specified conditions comprises triggering a threshold number of indicators of compromise and the one or more specified types comprises executable modules and dynamic link library modules.

4. The method of claim 1 wherein the hash signatures comprise Minhash signatures.

5. The method of claim 1 wherein performing the similarity-based query comprises performing a locality-sensitive hashing query matching one or more bands of the seed software module with corresponding bands of the plurality of software modules, and wherein the candidate software modules comprise respective ones of the plurality of software modules matching a designated threshold number of bands with the seed software module.

6. The method of claim 1 further comprising, prior to performing the similarity-based query, filtering out one or more of the plurality of software modules having one or more defined metadata types that do not match corresponding metadata types of the seed software module.

7. The method of claim 6 wherein the one or more defined metadata types comprise at least one of a module type, a module platform, and a certificate owner.

8. The method of claim 1 wherein computing the distances between the candidate software modules and the seed software module comprises computing distances between the candidate software modules and the seed software module for respective features in the second subset of features and summing the distances to determine distance metrics for respective ones of the candidate software modules.

9. The method of claim 8 wherein classifying a given one of the candidate modules as being the designated software module type comprises determining that the distance metric for the given candidate module exceeds a designated threshold.

10. The method of claim 1 wherein the designated software module type comprises malware.

11. The method of claim 1 wherein the designated software module type comprises potentially unwanted programs.

12. The method of claim 1 wherein generating the notification comprises ordering the list of candidate software modules classified as the designated software module type based on the computed distances between the candidate software modules and the seed software module.

13. The method of claim 1 wherein modifying access by the given client device to the given candidate software module classified as the designated software module type comprises at least one of:

removing the given candidate software module from a memory or storage of the given client device;

preventing the given client device from obtaining the given candidate software module; and

causing the given candidate software module to be opened in a sandboxed application environment on the given client device.

14. The method of claim 1 further comprising providing the notification over at least one network to one or more designated users of the enterprise.

15. A method comprising:

preparing a representation of data associated with a plurality of software modules, the representation comprising similarity-based hashing of signatures constructed from a first subset of features of the plurality of software modules, the first subset of features of the plurality of software modules comprising at least one of (i) one or more indicator of compromise features having a binary value range and (ii) one or more static features having an integer value range;

receiving a seed software module;

performing a similarity-based query utilizing the similarity-based hashing of signatures constructed from the first subset of features to identify one or more of the plurality of software modules as candidate software modules matching the seed software module;

computing distances between the candidate software modules and the seed software module utilizing a second subset of features of the plurality of software modules, at least one of the second subset of features comprising a textual feature;

classifying one or more of the candidate software modules as a designated software module type based on the computed distances;

generating a notification comprising a list of the candidate software modules classified as the designated software module type; and

modifying access by a given one of one or more client devices associated with an enterprise to a given one of the one or more of the candidate software modules in the list classified as the designated software module type;

wherein preparing the representation of data associated with the plurality of software modules comprises:

building a characteristic matrix having two or more rows each corresponding to one of the first subset of features; and

converting each column of the characteristic matrix into a hash signature through a designated number of permutations;

wherein the first subset of the plurality of features comprises at least one feature having a binary value range and at least one feature having an associated integer value range, and wherein each feature in the first subset having a binary value range is associated with a single row in the characteristic matrix and each feature in the first subset having an integer value range is associated with two or more rows of the characteristic matrix corresponding to different integer values in its associated integer value range; and

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

16. The method of claim 15 wherein preparing the representation further comprises generating the similarity-based hashing of signatures by performing locality-sensitive hashing to build two or more bands of consecutive components of the hash signatures, each band comprising a concatenation of string values of two or more consecutive components of the hash signatures.

17. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device cause the at least one processing device:

to prepare a representation of data associated with a plurality of software modules, the representation comprising similarity-based hashing of signatures constructed from a first subset of features of the plurality of software modules, the first subset of features of the plurality of software modules comprising at least one of (i) one or more indicator of compromise features having a binary value range and (ii) one or more static features having an integer value range;

to receive a seed software module;

to perform a similarity-based query utilizing the similarity-based hashing of signatures constructed from the first subset of features to identify one or more of the plurality of software modules as candidate software modules matching the seed software module;

to compute distances between the candidate software modules and the seed software module utilizing a second subset of features of the plurality of software modules, at least one of the second subset of features comprising a textual feature;

to classify one or more of the candidate software modules as a designated software module type based on the computed distances;

to generate a notification comprising a list of the candidate software modules classified as the designated software module type; and

to modify access by a given one of one or more client devices associated with an enterprise to a given one of the one or more of the candidate software modules in the list classified as the designated software module type

wherein preparing the representation of data associated with the plurality of software modules comprises:

building a characteristic matrix having two or more rows each corresponding to one of the first subset of features;

converting each column of the characteristic matrix into a hash signature through a designated number of permutations; and

generating the similarity-based hashing of signatures by performing locality-sensitive hashing to build two or more bands of consecutive components of the hash signatures, each band comprising a concatenation of string values of two or more consecutive components of the hash signatures.

18. The computer program product of claim 17 wherein:

performing the similarity-based query comprises performing a locality-sensitive hashing query matching one or more bands of the seed software module with corresponding bands of the plurality of software modules; and

the candidate software modules comprise respective ones of the plurality of software modules matching a designated threshold number of bands with the seed software module.

19. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to prepare a representation of data associated with a plurality of software modules, the representation comprising similarity-based hashing of signatures constructed from a first subset of features of the plurality of software modules, the first subset of features of the plurality of software modules comprising at least one of (i) one or more indicator of compromise features having a binary value range and (ii) one or more static features having an integer value range;

to receive a seed software module;

to perform a similarity-based query utilizing the similarity-based hashing of signatures constructed from the first subset of features to identify one or more of the plurality of software modules as candidate software modules matching the seed software module;

to compute distances between the candidate software modules and the seed software module utilizing a second subset of features of the plurality of software modules, at least one of the second subset of features comprising a textual feature;

to classify one or more of the candidate software modules as a designated software module type based on the computed distances;

to generate a notification comprising a list of the candidate software modules classified as the designated software module type; and

to modify access by a given one of one or more client devices associated with an enterprise to a given one of the one or more of the candidate software modules in the list classified as the designated software module type;

wherein preparing the representation of data associated with the plurality of software modules comprises:

building a characteristic matrix having two or more rows each corresponding to one of the first subset of features;

converting each column of the characteristic matrix into a hash signature through a designated number of permutations; and

generating the similarity-based hashing of signatures by performing locality-sensitive hashing to build two or more bands of consecutive components of the hash signatures, each band comprising a concatenation of string values of two or more consecutive components of the hash signatures.

20. The apparatus of claim 19 wherein:

performing the similarity-based query comprises performing a locality-sensitive hashing query matching one or more bands of the seed software module with corresponding bands of the plurality of software modules; and

the candidate software modules comprise respective ones of the plurality of software modules matching a designated threshold number of bands with the seed software module.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2017
From: LI, ZHOU; ROSA, MARTIN; DUCHIN, ZOHAR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 043508/0492 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
Cited By (2)
US 12,705,264 US 12,717,879