IP Library › Granted Patent US 12,231,446
Granted Patent B2
US 12,231,446 · App. 18/543,380 · Granted Feb 18, 2025

Command and control steganographic communications detection engine

Inventors: Steven E. Sinks (Scottsdale, AZ); Jonathan Sheedy (Poynton, GB)
Assignee: Bank of America Corporation
H04L63/1416H04L63/0236H04L63/123H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,446
App. No.
18/543,380
Granted
Feb 18, 2025
Kind
B2
Abstract

A network security computing system includes a steganographic communications analysis engine monitoring incoming and outgoing messages on a secure computing network. The steganographic communications analysis engine identifies a pattern of file transfers between a first computing device on the secure computing network and an internal or external message recipient. When a pattern is identified, the steganographic communications analysis engine quarantines an associated computing device from the secure network. The steganographic communications analysis engine analyzes files transferred between the computing device and the recipient for indications of steganographic information and causes display, based on an identified indication of steganography, an indication that the computing device had been compromised by command and control malware.

Claims (38)

1. A system comprising:

a plurality of computing devices communicatively coupled to a network; and

a second computing device comprising:

a processor; and

non-transitory memory storing instructions that, when executed by the processor, causes the second computing device to:

monitor, the network, for indications of file transfers that push and retrieve a same file multiple times between a first computing device of the plurality of computing devices and an image hosting website;

quarantine, based on an identification of a pattern of file transfers and via simulations of a command and control server environment, the first computing device from the network;

identify, from a file transferred within the pattern of the file transfers to and from the first computing device, an indication of steganography; and

trigger, based on an identified indication of steganography, an alert identifying that the first computing device had been compromised by command and control malware.

2. The system of claim 1 , wherein the instructions, when executed by the processor, that cause the second computing device to quarantine the first computing device from the network further cause the second computing device to disable incoming and outgoing communications from the computing device.

3. The system of claim 1 , wherein a plurality of incoming and outgoing messages associated with the pattern of file transfers comprises a plurality of image file transfers.

4. The system of claim 1 , wherein the alert comprises one or more of an electronic message comprising an indication of the first computing device, information corresponding to the pattern of file transfers, and a link to an image file and information corresponding to identified stenographic encoded information.

5. The system of claim 1 , wherein a simulated command and control server environment is simulated in a testing environment.

6. The system of claim 1 , wherein the instructions, when executed by the processor, further cause the second computing device to disable network access to the simulated command and control server.

7. The system of claim 1 , wherein the simulated command and control server comprises an internet website.

8. The system of claim 1 , wherein the simulated command and control server comprises a second computing device on the network.

9. A computing device comprising

a processor; and

non-transitory memory storing instructions that, when executed by a processor, causes the computing device to:

monitor communications on a network for an indication of pulling, pushing, and retrieving of a same file multiple times;

identify, based on a knowledge base comprising patterns identified via a simulated command and control server, a pattern of file transfers between a computing device on the network and an image hosting website;

analyze the file transferred during the pattern of file transfers between the computing device and the image hosting websites for an indication of steganography; and

cause display, based on the indication of steganography, an indication that the computing device had been compromised by command and control malware.

10. The computing device of claim 9 , wherein the instructions, when executed by the processor, that cause the computing device to disable incoming and outgoing communications from the computing device.

11. The computing device of claim 9 , wherein the instructions further cause the computing device to monitor a plurality of incoming and outgoing messages that comprises a plurality of image file transfers.

12. The computing device of claim 9 , wherein the indication that the computing device had been compromised by command and control malware comprises an electronic message including one or more of an indication of a quarantined computing device, information corresponding to the pattern of file transfers, and a link to an image file and information corresponding to identified stenographic encoded information.

13. The computing device of claim 9 , wherein the instructions, when executed by the processor, further cause the computing device to disable network access to the simulated command and control server.

14. The computing device of claim 9 , wherein the simulated command and control server comprises an internet website.

15. The computing device of claim 9 , wherein the simulated command and control server comprises a second computing device on the network.

16. The computing device of claim 9 , wherein the computing device and the simulated command and control server are simulations of a compromised network in a testing environment.

17. A method comprising:

monitoring, by a steganographic communications analysis engine based on a knowledge base comprising patterns of file transfers of sending and receiving a same file, network communications for an indication of a file transfer pattern of incoming and outgoing messages between a computing device on a network and an image hosting website;

quarantining, based on the indication that an identified file transfer pattern matches a simulated pattern of file transfers, the computing device from the network;

identifying, by the steganographic communications analysis engine, that the file transfer pattern corresponds to a file comprising an indication of steganography; and

triggering, by the steganographic communications analysis engine based on an identified indication of steganography, an alert comprising the indication of steganography.

18. The method of claim 17 , wherein the alert comprises one or more of an electronic message comprising an indication of a quarantined computing device, information corresponding to the file transfer pattern, and a link to an image file and information corresponding to identified stenographic encoded information.

19. The method of claim 17 , wherein the incoming and outgoing messages comprises a plurality of image file transfers.

20. The method of claim 17 , further comprising disabling, by the steganographic communications analysis engine, network access to the image hosting website.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2023
From: SINKS, STEVEN E.; SHEEDY, JONATHAN
To: BANK OF AMERICA CORPORATION
Reel/Frame 065897/0925 →
Continuity (3)
Continuation 18058390 · Nov 23, 2022
Continuation 17153605 · Jan 20, 2021
Related Publication 20240121251A1 · Apr 11, 2024
References Cited (17)
US 6324573B1 · Rhoads · 2001 [cited by applicant]
US 7620253B2 · Miller et al. · 2009 [cited by applicant]
US 7797411B1 · Guruswamy et al. · 2010 [cited by applicant]
US 7822226B2 · Hannigan et al. · 2010 [cited by applicant]
US 8307212B2 · Van Wie et al. · 2012 [cited by applicant]
US 8610709B2 · Choi et al. · 2013 [cited by applicant]
US 8745742B1 · Satish et al. · 2014 [cited by applicant]
US 9241010B1 · Bennett et al. · 2016 [cited by applicant]
US 9565202B1 · Kindlund et al. · 2017 [cited by applicant]
US 10708297B2 · Woods et al. · 2020 [cited by applicant]
US 10873589B2 · Cheetancheri · 2020 [cited by examiner]
US 20150026464A1 · Hanner, Sr. · 2015 [cited by examiner]
US 20180012021A1 · Volkov · 2018 [cited by examiner]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20190182268A1 · Lancioni et al. · 2019 [cited by applicant]
US 20190222586A1 · Sachkov et al. · 2019 [cited by applicant]
US 20190364057A1 · Hazay · 2019 [cited by examiner]