IP Library › Granted Patent US 11,949,694
Granted Patent B2
US 11,949,694 · App. 17/472,464 · Granted Apr 2, 2024

Context for malware forensics and detection

Inventors: Jun Wang (Sunnyvale, CA); Wei Xu (Cupertino, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1416G06F21/564G06F21/566H04L63/1425H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,949,694
App. No.
17/472,464
Granted
Apr 2, 2024
Kind
B2
Abstract

A malware profile is received. The malware profile comprises a set of n-tuples of attributes that describe one or more activities associated with executing a copy of a known malicious application that is associated with the malware profile. A set of one or more log entries is analyzed for a set of entries that matches the malware profile. Based at least in part on identifying the set of entries matching the malware profile, a determination is made that a host was compromised. In response to determining that the host has been compromised, a remedial action is taken with respect to the host.

Claims (59)

1. A system, comprising:

a processor configured to:

receive a malware profile, wherein the malware profile comprises a sequence comprising a plurality of network activities, each respective one of which is defined using an n-tuple of respective attributes associated with executing a copy of a known malicious application that is associated with the malware profile;

analyze a set of one or more logs for a set of entries occurring within a predetermined sliding time window that matches the malware profile;

determine, based at least in part on identifying the set of entries as matching the malware profile, that a host was compromised; and

in response to determining that the host has been compromised, take a remedial action with respect to the host; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the set of one or more logs comprises entries associated with a plurality of hosts and wherein analyzing the set of one or more logs includes performing, for each respective host included in the plurality of hosts, a search.

3. The system of claim 1 , wherein identifying that the set of entries matches the malware profile comprises determining a subsequence match.

4. The system of claim 1 , wherein the processor is further configured to transmit a copy of a sample to a security platform for analysis.

5. The system of claim 4 , wherein the malware profile is received from the security platform.

6. The system of claim 5 , wherein the malware profile is received in response to the security platform determining that the sample is malicious.

7. The system of claim 1 , wherein analyzing the set of one or more logs is performed in response to receipt of the malware profile.

8. The system of claim 1 , wherein the malware profile is generated at least in part by abstracting a capture of network activity associated with the execution of the copy of the known malicious application into a set of network activities taken by the known malicious application.

9. The system of claim 8 , wherein the malware profile is further generated at least in part by removing network activity coincident to the execution of the copy of the known malicious application.

10. The system of claim 9 , wherein at least one network activity removed comprises at least one of NTP activity, NETBIOS activity, and IGMP activity.

11. The system of claim 1 , wherein at least one activity included in the plurality of network activities taken by the known malicious application comprises service probing.

12. The system of claim 1 , wherein at least one activity included in the plurality of network activities taken by the known malicious application comprises a denial of service activity.

13. The system of claim 1 , wherein at least one activity included in the plurality of network activities taken by the known malicious application comprises a local action taken by the known malicious application.

14. The system of claim 1 , wherein the malware profile corresponds to a malware family and wherein the known malicious application shares the malware profile with a plurality of malicious applications that are members of the malware family.

15. The system of claim 1 , wherein at least one of the respective n-tuples includes a protocol attribute.

16. The system of claim 1 , wherein at least one of the respective n-tuples includes a destination port attribute.

17. The system of claim 1 , wherein at least one of the respective n-tuples includes a user agent attribute.

18. The system of claim 1 , wherein at least one of the respective n-tuples includes a number of packets sent attribute.

19. The system of claim 1 , wherein at least one of the respective n-tuples includes a number of packets received attribute.

20. The system of claim 1 , wherein at least one of the respective n-tuples includes a size of packet sent attribute.

21. The system of claim 1 , wherein at least one of the respective n-tuples includes a size of packet received attribute.

22. The system of claim 1 , wherein at least one of the respective n-tuples includes a traffic direction attribute.

23. A method, comprising:

receiving a malware profile, wherein the malware profile comprises a sequence comprising a plurality of network activities, each respective one of which is defined using an n-tuple of respective attributes associated with executing a copy of a known malicious application that is associated with the malware profile;

analyzing a set of one or more logs for a set of entries occurring within a predetermined sliding time window that matches the malware profile;

determining, based at least in part on identifying the set of entries as matching the malware profile, that a host was compromised; and

in response to determining that the host has been compromised, taking a remedial action with respect to the host.

24. The method of claim 23 , wherein the set of one or more logs comprises entries associated with a plurality of hosts and wherein analyzing the set of one or more logs includes performing, for each respective host included in the plurality of hosts, a search.

25. The method of claim 23 , wherein identifying that the set of entries matches the malware profile comprises determining a subsequence match.

26. The method of claim 23 , further comprising transmitting a copy of a sample to a security platform for analysis.

27. The method of claim 26 , wherein the malware profile is received from the security platform.

28. The method of claim 27 , wherein the malware profile is received in response to the security platform determining that the sample is malicious.

29. The method of claim 23 , wherein analyzing the set of one or more logs is performed in response to receipt of the malware profile.

30. The method of claim 23 , wherein the malware profile is generated at least in part by abstracting a capture of network activity associated with the execution of the copy of the known malicious application into a set of network activities taken by the known malicious application.

31. The method of claim 30 , wherein the malware profile is further generated at least in part by removing network activity coincident to the execution of the copy of the known malicious application.

32. The method of claim 31 , wherein at least one network activity removed comprises at least one of NTP activity, NETBIOS activity, and IG 1 VIP activity.

33. The method of claim 23 , wherein at least one activity included in the plurality of network activities taken by the known malicious application comprises service probing.

34. The method of claim 23 , wherein at least one activity included in the plurality of network activities taken by the known malicious application comprises a denial of service activity.

35. The method of claim 23 , wherein at least one activity included in the plurality of network activities taken by the known malicious application comprises a local action taken by the known malicious application.

36. The method of claim 23 , wherein the malware profile corresponds to a malware family and wherein the known malicious application shares the malware profile with a plurality of malicious applications that are members of the malware family.

37. The method of claim 23 , wherein at least one of the respective n-tuples includes a protocol attribute.

38. The method of claim 23 , wherein at least one of the respective n-tuples includes a destination port attribute.

39. The method of claim 23 , wherein at least one of the respective n-tuples includes a user agent attribute.

40. The method of claim 23 , wherein at least one of the respective n-tuples includes a number of packets sent attribute.

41. The method of claim 23 , wherein at least one of the respective n-tuples includes a number of packets received attribute.

42. The method of claim 23 , wherein at least one of the respective n-tuples includes a size of packet sent attribute.

43. The method of claim 23 , wherein at least one of the respective n-tuples includes a size of packet received attribute.

44. The method of claim 23 , wherein at least one of the respective n-tuples includes a traffic direction attribute.

45. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a malware profile, wherein the malware profile comprises a sequence comprising a plurality of network activities, each respective one of which is defined using an n-tuple of respective attributes associated with executing a copy of a known malicious application that is associated with the malware profile;

analyzing a set of one or more logs for a set of entries occurring within a predetermined sliding time window that matches the malware profile;

determining, based at least in part on identifying the set of entries as matching the malware profile, that a host was compromised; and

in response to determining that the host has been compromised, taking a remedial action with respect to the host.

Continuity (2)
Continuation 15885388 · Jan 31, 2018
Related Publication 20210409431A1 · Dec 30, 2021