IP Library › Granted Patent US 11,822,666
Granted Patent B2
US 11,822,666 · App. 17/298,108 · Granted Nov 21, 2023

Malware detection

Inventor: Varun Seth (New Delhi, IN)
G06F21/575G06F21/552G06F21/566G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,822,666
App. No.
17/298,108
Granted
Nov 21, 2023
Kind
B2
Abstract

Approaches for detecting and rectifying the malware in the computing systems are described. In an example, a request by a process or is intercepted by the malware detection module. Relevant information and characteristics pertaining to the request are extracted and on the based on the extraction, operational attributes are generated. These extracted operational attributes are analyzed and compared with the baseline attributes and if there are any anomalies present, the susceptible code or process originating from the intercepted request is ascertained as malicious.

Claims (49)

1. A method for detecting and rectifying a malware threats in a computing system, the method comprising:

intercepting a request from a process, wherein the process is to implement a plurality of functions to be caused pursuant to an execution of a susceptible code, wherein the plurality of functions comprises creating, reading, writing one of data and entries stored on the computing system, and modifications affected onto system configuration entries;

determining a type of the request, wherein the types of requests originating from the process is one of a first category, second category and third category;

extracting operational attributes from the request based on the intercepted request affected by the execution of the susceptible code; and

on determining the type of request as the first category, storing the corresponding operational attributes of a suspicious activity being performed in a data repository;

on determining the type of request as the second category, analyzing extracted operational attributes based on baseline attributes for evaluating the susceptible code to be malicious or benign, wherein the baseline attributes comprise characteristics corresponding to operations known to be performed by malware;

on determining the type of request as the third category, analyzing extracted operational attributes and result and/or data returned by the request based on baseline attributes for evaluating the susceptible code to be malicious or benign.

2. The method as claimed in claim 1 , wherein the method comprises:

determining whether the process is whitelisted, wherein whitelisted processes further comprise digitally signed processes, system processes or processes marked as benign by a user.

3. The method as claimed in claim 1 , wherein the computing system further comprises a data repository, wherein the data repository is to store a list of processes, information pertaining to one or more suspicious activity with associated data, dynamic modules created by various processes, current status and result of analyses done by a malware detection module, scan areas, rules and baseline and operational attributes.

4. The method as claimed in claim 1 , wherein:

for the request falling in second and third category, creating operational attributes which are to be utilized either with or without utilizing any previously created operational attributes to check for malware, and wherein operational attributes are extracted and created after analyzing various characteristics of the requests/configuration entry; and

for the request for falling in the third category, analyzing the result and data that is returned due to the request.

5. The method as claimed in claim 1 , wherein the operational attributes are analyzed using one of code recognition, code prediction, key word recognition and analyses, heuristic analyses and comparison, direct comparison, and behaviour analyses.

6. The method as claimed in claim 1 , wherein the method comprises:

upon detecting malware, generating an alert to indicate presence of the detected malware; and

presenting a user with an option to stop further execution of the malware.

7. The method as claimed in claim 6 , wherein the user response is stored in a system and the request is passed on to an appropriate system, if the user permits further execution of the malware.

8. The method as claimed in claim 6 , wherein on approval of the user, the computing system eliminates the process, cleans the malware, and undoes changes brought by the malware in the computing system.

9. The method as claimed in claim 1 , wherein the method further comprises reading, by a scanning module of the malware detection module, susceptible system configuration entries to detect malware by analyzing configuration entries by creating corresponding operational attributes which are to be utilized either with or without utilizing any previously created operational attributes to check for malware, and wherein operational attributes are extracted and created after analyzing characteristics of one of the configuration entries and any configuration entries linked to the configuration entries.

10. The method as claimed in claim 9 , wherein the method comprises checking if a process file is whitelisted.

11. A system comprising:

a processor;

a malware detection module coupled to the processor, wherein the malware detection module is to:

intercepting a request from a process, by the system, wherein process is to implement a plurality of functions caused pursuant to an execution of susceptible code, wherein the plurality of functions comprises creating, reading, writing one of data and entries stored on the computing system, and modifications affected onto system configuration entries;

determine a type of the request, wherein the types of request originating from the process is one of a first category, second category and third category;

extract operational attributes from the request based on the intercepted request affected by the execution of the susceptible code; and

on determining the type of request as the first category, store the corresponding operational attributes of a suspicious activity being performed in a data repository;

on determining the type of request as the second category, analyze extracted operational attributes based on baseline attributes for evaluating the susceptible code to be malicious or benign, wherein the baseline attributes comprise characteristics corresponding to operations known to be performed by malware;

on determining the type of request as the third category, analyze operational attributes and result and/or data returned by the request based on baseline attributes for evaluating the susceptible code to be malicious or benign.

12. The system as claimed in claim 11 , wherein the malware detection module is to build a data repository containing entries to track details of process activities.

13. The system as claimed in claim 11 , wherein the malware detection module is to categorize the types of request originating from process in one of the three categories.

14. The system as claimed in claim 11 , wherein the malware detection module further comprises a scanning module, wherein the scanning module is to:

read susceptible system configuration entries within the system;

further ascertain whether a process file is whitelisted for each of the susceptible system configuration entries; and

on determining the process file to be whitelisted, ignore the corresponding susceptible system configuration entry;

on determining the process file not to be whitelisted, further analyzing the corresponding susceptible system configuration entry;

based on analyzing the entry, selecting a rule for assessing;

extracting operational attributes; and

utilizing determined operational attributes either with or without utilizing any previously created operational attributes to further check for malware, wherein operational attributes are extracted and created after analyzing characteristics of one of the configuration entries and any configuration entries linked to the configuration entries.

15. The system as claimed in claim 11 , wherein the operational attributes are analyzed with plurality of baseline attributes in a variety of ways including code recognition, code prediction, key word recognition and analyses, heuristic analyses and comparison, direct comparison, and behaviour analyses.

16. A non-transitory computer-readable medium comprising computer-readable instructions being executable by a processing resource to:

intercept a request from a process, by a system, wherein process is to implement a plurality of functions caused pursuant to an execution of susceptible code, wherein the plurality of functions comprises creating, reading, writing one of data and entries stored on the computing system, and modifications affected onto system configuration entries;

determine a type of the request, wherein the types of request originating from the process is one of a first category, second category and third category;

extract operational attributes from the request based on the intercepted request; and

on determining the type of request as the first category, store the corresponding operational attributes of a suspicious activity being performed in a data repository; or

on determining the type of request as the second category, analyze extracted operational attributes based on baseline attributes for evaluating the susceptible code to be malicious or benign, wherein the baseline attributes comprise characteristics corresponding to operations known to be performed by malware;

on determining the type of request as the third category, analyze extracted operational attributes and result and/or data by the request based on baseline attributes for evaluating the susceptible code to be malicious or benign.

17. The non-transitory computer-readable medium as claimed in claim 16 , wherein the operational attributes are analyzed with baseline attributes based on one of code recognition, code prediction, key word recognition and analyses, heuristic analyses and comparison, direct comparison, and behaviour analyses.

Priority Claims (1)
IN 201811049737 · Dec 28, 2018 · national
Continuity (1)
Related Publication 20220027475A1 · Jan 27, 2022