IP Library › Granted Patent US 10,878,088
Granted Patent B2
US 10,878,088 · App. 15/890,606 · Granted Dec 29, 2020

Identifying randomly generated character strings

Inventors: Richard Andrew Lawshae (Austin, TX); Josiah Dede Hagen (Austin, TX); Mathew Robert Powell (Austin, TX); Elvis Collado (Austin, TX); Jonathan Edward Andersson (Austin, TX); Stephen David Povolny (Austin, TX)
Assignee: Trend Micro Incorporated
G06F21/554G06F21/56G06F21/60G06F40/279G06F40/30G06F40/53H04L43/00H04L63/1425H04L69/22G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,878,088
App. No.
15/890,606
Granted
Dec 29, 2020
Kind
B2
Abstract

Examples relate to identifying randomly generated character strings. In one example, a computing device may: receive a character string that includes two or more characters; identify a number of character transitions included in the character string, each character transition being a change in character type within an n-gram of the character string, where n is a positive integer; and determine, based on the number of character transitions, whether the character string was randomly generated.

Claims (58)

1. A non-transitory machine-readable storage medium encoded with instructions executable by a hardware processor of a computing device for identifying randomly generated character strings, the machine-readable storage medium comprising instructions to cause the hardware processor to:

receive a character string that includes two or more characters;

identify a number of character transitions included in the character string, each character transition being a change in character type within an n-gram of the character string, where n is a positive integer;

identify a context associated with the character string;

determine, based on the number of character transitions and based on the context associated with the character string, whether the character string was randomly generated; and

produce a security event notification in response to determining that the character string was randomly generated,

wherein whether the character string was randomly generated is determined by comparing the number of character transitions included in the character string to a transition threshold, and the transition threshold depends on the context associated with the character string.

2. The storage medium of claim 1 , wherein the context associated with the character string is one of a plurality of string contexts, the plurality of string contexts including at least two of:

a domain name;

a universal resource locator;

security certificate metadata;

file name;

executable file header;

software code variable name;

software code function name;

host computer name;

electronic mail metadata; and

HTTP header metadata.

3. The storage medium of claim 1 , wherein each character of the character string has one of a plurality of character types, the plurality of character types including at least two of:

lower case alphabetical character;

upper case alphabetical character;

numerical digit;

punctuation;

symbol;

foreign language character; and

non-printable character.

4. The storage medium of claim 1 , wherein:

the computing device is an intermediary network device;

the character string is included in a network packet passing through the intermediary network device; and

each character transition is identified based on a match of characters included in a particular n-gram of the character string with a regular expression that specifies character transitions.

5. A computing device for determining string similarity, the computing device comprising:

a hardware processor; and

a data storage device storing instructions that, when executed by the hardware processor, cause the hardware processor to:

receive, from network traffic of a computer network, a character string that includes two or more characters;

identify a number of character transitions included in the character string by determining, for each n-gram of the character string, whether a character transition occurred, each character transition being a change in character type, and wherein n is a positive integer;

identify a context associated with the character string;

determine, based on the number of character transitions and based on the context associated with the character string, whether the character string was randomly generated; and

produce a security event notification in response to determining that the character string was randomly generated,

wherein whether the character string was randomly generated is determined by comparing the number of character transitions included in the character string to a transition threshold, and the transition threshold depends on the context associated with the character string.

6. A method for identifying randomly generated character strings, implemented by a hardware processor, the method comprising:

receiving, from network traffic of a computer network, a character string that includes two or more characters;

determining, for each n-gram of the character string, whether a character transition occurred, each character transition being a change in character type, and wherein n is a positive integer;

identifying, based on the determinations, a number of character transitions included in the character string;

identifying a context associated with the character string;

determining, based on the number of character transitions and based on the context associated with the character string, whether the character string was randomly generated; and

producing a security event notification in response to determining that the character string was randomly generated,

wherein whether the character string was randomly generated is determined by comparing the number of character transitions included in the character string to a transition threshold, and the transition threshold depends on the context associated with the character string.

7. The method of claim 6 , wherein the context associated with the character string is one of a plurality of string contexts, the plurality of string contexts including at least two of:

a domain name;

a universal resource locator;

security certificate metadata;

file name;

executable file header;

software code variable name;

software code function name;

host computer name;

electronic mail metadata; and

HTTP header metadata.

Continuity (2)
Continuation PCTUS2015045756 · Aug 18, 2015
Related Publication 20180173875A1 · Jun 21, 2018