IP Library Granted Patent US 11,159,538
Granted Patent B2
US 11,159,538 · App. 15/885,388 · Granted Oct 26, 2021

Context for malware forensics and detection

Inventors: Jun Wang (Fremont, CA); Wei Xu (Santa Clara, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1416G06F21/564G06F21/566H04L63/145H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,159,538
App. No.
15/885,388
Granted
Oct 26, 2021
Kind
B2
Abstract

A malware profile is received. The malware profile comprises a set of one or more activities associated with executing a copy of a known malicious application that is associated with the malware profile. A set of one or more log entries is analyzed for a set of entries that matches the malware profile. Based at least in part on identifying the set of entries matching the malware profile, a determination is made that a host was compromised.

Claims (41)

1. A system, comprising:

a hardware processor, coupled to a memory and configured to:

receive a malware profile, wherein the malware profile comprises a sequence of network events and corresponding attributes previously taken by a known malicious application during execution of the known malicious application, wherein the malware profile was generated at least in part by filtering out, from a raw profile comprising network activity events, system-generated events taken by a sample analysis system coincident to the execution of the malicious application, wherein the filtering out of the system-generated events includes filtering out network activities associated with a predetermined network protocol, and wherein at least some of the network activities comprise a roundtrip request-response pair;

analyze a set of one or more logs for a set of entries occurring within a predetermined sliding time window that matches the malware profile;

determine, based at least in part on identifying the set of entries occurring within the predetermined sliding time window as matching the malware profile, that a host was compromised; and

in response to determining that the host has been compromised, take a remedial action with respect to the host;

wherein the memory is configured to provide the processor with instructions.

2. The system of claim 1 , wherein the set of logs comprises entries associated with a plurality of hosts and wherein analyzing the set of logs includes performing, for each respective host included in the plurality of hosts, a search.

3. The system of claim 1 , wherein identifying that the set of entries matches the malware profile comprises determining a subsequence match.

4. The system of claim 1 , wherein the processor is further configured to transmit a copy of a sample to a security platform for analysis.

5. The system of claim 4 , wherein the malware profile is received from the security platform.

6. The system of claim 5 , wherein the malware profile is received in response to the security platform determining that the sample is malicious.

7. The system of claim 1 , wherein analyzing the set of one or more logs is performed periodically.

8. The system of claim 1 , wherein analyzing the set of one or more logs is performed in response to receipt of the malware profile.

9. The system of claim 1 , wherein the malware profile is generated at least in part by abstracting a capture of network activity associated with the execution of the known malicious application into a set of network activities taken by the known malicious application.

10. The system of claim 1 , wherein at least one activity included in the malware profile comprises service probing.

11. The system of claim 1 , wherein at least one activity included in the malware profile comprises a denial of service activity.

12. The system of claim 1 , wherein at least one activity included in the malware profile comprises a local action taken by the known malicious application.

13. The system of claim 1 , wherein the malware profile corresponds to a malware family and wherein the known malicious application shares the malware profile with a plurality of malicious applications that are members of the malware family.

14. A method, comprising:

receiving a malware profile, wherein the malware profile comprises a sequence of network events and corresponding attributes previously taken by a known malicious application during execution of the known malicious application, wherein the malware profile was generated at least in part by filtering out, from a raw profile comprising network activity events, system-generated events taken by a sample analysis system coincident to the execution of the malicious application, wherein the filtering out of system-generated events includes filtering out network activities associated with a predetermined network protocol and wherein at least some of the network activities comprise a roundtrip request-response pair;

analyzing a set of one or more logs for a set of entries occurring within a predetermined sliding time window that matches the malware profile;

determining, based at least in part on identifying the set of entries occurring within the predetermined sliding time window as matching the malware profile, that a host was compromised; and

in response to determining that the host has been compromised, taking a remedial action with respect to the host.

15. The method of claim 14 , wherein the set of logs comprises entries associated with a plurality of hosts and wherein analyzing the set of logs includes performing, for each respective host included in the plurality of hosts, a search.

16. The method of claim 14 , wherein identifying that the set of entries matches the malware profile comprises determining a subsequence match.

17. The method of claim 14 , wherein the malware profile is generated at least in part by abstracting a capture of network activity associated with the execution of the known malicious application into a set of network activities taken by the known malicious application.

18. The method of claim 14 , further comprising transmitting a copy of a sample to a security platform for analysis.

19. The method of claim 18 , wherein the malware profile is received from the security platform.

20. The method of claim 19 , wherein the malware profile is received in response to the security platform determining that the sample is malicious.

21. The method of claim 14 , wherein analyzing the set of one or more logs is performed periodically.

22. The method of claim 14 , wherein analyzing the set of one or more logs is performed in response to receipt of the malware profile.

23. The method of claim 14 , wherein at least one activity included in the malware profile comprises service probing.

24. The method of claim 14 , wherein at least one activity included in the malware profile comprises a denial of service activity.

25. The method of claim 14 , wherein at least one activity included in the malware profile comprises a local action taken by the known malicious application.

26. The method of claim 14 , wherein the malware profile corresponds to a malware family and wherein the known malicious application shares the malware profile with a plurality of malicious applications that are members of the malware family.

27. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a malware profile, wherein the malware profile comprises a sequence of network events and corresponding attributes previously taken by a known malicious application during execution of the known malicious application, wherein the malware profile was generated at least in part by filtering out, from a raw profile comprising network activity events, system-generated events taken by a sample analysis system coincident to the execution of the malicious application, wherein the filtering out of system-generated events includes filtering out network activities associated with a predetermined network protocol, and wherein at least some of the network activities comprise a roundtrip request-response pair;

analyzing a set of one or more logs for a set of entries occurring within a predetermined sliding time window that matches the malware profile;

determining, based at least in part on identifying the set of entries occurring within the predetermined sliding time window as matching the malware profile, that a host was compromised; and

in response to determining that the host has been compromised, taking a remedial action with respect to the host.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2018
From: WANG, JUN; XU, WEI
To: PALO ALTO NETWORKS, INC.
Reel/Frame 045314/0841 →
Continuity (1)
Related Publication 20190238565A1 · Aug 1, 2019
Cited By (1)
US 12,572,659