IP Library Granted Patent US 11,201,876
Granted Patent B2
US 11,201,876 · App. 16/065,482 · Granted Dec 14, 2021

Malicious software identification

Inventors: George Kallos (London, GB); Fadi El-Moussa (London, GB)
Assignee: British Telecommunications Public Limited Company
H04L63/1416G06F21/50G06F21/55G06F21/552G06F21/554G06F21/56G06F21/563G06F21/564G06F21/566G06F21/568G06N7/08H04L63/145H04L63/1408H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,201,876
App. No.
16/065,482
Filed
Jun 22, 2018
Granted
Dec 14, 2021
Kind
B2
Art Unit
2434
USPC
726/22
Abstract

A computer implemented method to identify malicious software in a computer system includes receiving an indication of a detection of malicious network traffic communicated via a computer network accessed by the computer system; identifying a software component involved in the malicious network traffic at the computer system; evaluating a measure of a correlation fractal dimension (CFD) for at least a portion of the software component; and storing the measure of CFD for subsequent comparison with a second measure of CFD for a corresponding portion of a second software component in the computer system to identify the second software component as a software component involved in malicious network communication.

Claims (17)

1. A computer implemented method to identify malicious software in a computer system comprising:

receiving an indication of a detection of malicious network traffic communicated via a computer network accessed by the computer system;

identifying a first software component involved in the malicious network traffic at the computer system;

evaluating a measure of a correlation fractal dimension (CFD) for at least a portion of the first software component, wherein the at least a portion of the first software component includes code for executing the first software component and the evaluating includes analyzing the code; and

storing the measure of CFD for subsequent comparison with a second measure of CFD for a corresponding portion of a second software component in the computer system to identify the second software component as a software component involved in malicious network communication.

2. The method of claim 1 , wherein the second software component involved in malicious network communication performs one or more of sending or receiving malicious network traffic via the computer network.

3. The method of claim 1 , further comprising, in response to a determination that the second software component is involved in malicious network communication, triggering a protective component to protect the computer system from the second software component.

4. A non-transitory computer-readable storage element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer system to perform the method as claimed in claim 1 .

5. A computer implemented method to identify malicious software in a computer system comprising:

evaluating a measure of a correlation fractal dimension (CFD) for at least a portion of a monitored software component in the computer system, wherein the at least a portion of the monitored software component includes code for executing the monitored software component and the evaluating includes analyzing the code; and

comparing the measure of CFD with a reference measure of CFD for a corresponding portion of a software component involved in malicious network communication via a computer network accessed by the computer system so as to determine if the monitored software component is involved in malicious network traffic communicated via the computer network.

6. The method of claim 5 , wherein the corresponding software component involved in malicious network communication performs one or more of sending or receiving malicious network traffic via the computer network.

7. The method of claim 5 , further comprising, in response to a determination that the monitored software component is involved in malicious network communication, triggering a protective component to protect the computer system from the monitored software component.

8. A computer system to identify malicious software comprising:

a memory and a processor, wherein the processor is configured to:

evaluate a measure of a correlation fractal dimension (CFD) for at least a portion of a monitored software component in the computer system, wherein the at least a portion of the monitored software component includes code for executing the monitored software component and the evaluating includes analyzing the code; and

compare the measure of CFD with a reference measure of CFD for a corresponding portion of a software component involved in malicious network communication via a computer network accessed by the computer system so as to determine if the monitored software component is involved in malicious network traffic communicated via the computer network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2018
From: KALLOS, GEORGE; EL-MOUSSA, FADI
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 046182/0648 →
Priority Claims (1)
EP 15202737 · Dec 24, 2015 · regional
Continuity (1)
Related Publication 20180375882A1 · Dec 27, 2018
Cited By (8)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,608,474 US 12,647,441 US 12,652,312