IP Library › Granted Patent US 8,955,135
Granted Patent B2
US 8,955,135 · App. 13/369,243 · Granted Feb 10, 2015

Malicious code infection cause-and-effect analysis

Inventors: Gregory D. Hartrell (Sammamish, WA); David J. Steeves (Seattle, WA); Efim Hudis (Bellevue, WA)
Assignee: Microsoft Corporation
G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,955,135
App. No.
13/369,243
Granted
Feb 10, 2015
Kind
B2
Abstract

A malware analysis system for automating cause and effect analysis of malware infections is provided. The malware analysis system monitors and records computer system activities. Upon being informed of a suspected malware infection, the malware analysis system creates a time-bounded snapshot of the monitored activities that were conducted within a time frame prior to the notification of the suspected malware infection. The malware analysis system may also create a time-bounded snapshot of the monitored activities that are conducted within a time frame subsequent to the notification of the suspected malware infection. The malware analysis system provides the created snapshot or snapshots for further analysis.

Claims (30)

1. A computer-readable storage device containing computer-executable instructions to control a computing device to analyze effects of a malware infection by a method comprising:

receiving post-infection snapshots from a plurality of machines suspected of being infected with malware, the post-infection snapshots identifying monitored activities of machines suspected of being infected with malware subsequent to the machines being suspected of being infected with malware, wherein the monitored activities of a machine relate to accessing of an operating system resource of an operating system executing on the machine;

comparing the monitored activities of the post-infection snapshot of a first machine to the post-infection snapshots of other machines to identify monitored activities that are common across multiple post-infection snapshots of different machines; and

tagging as possibly being caused by the malware infection the monitored activities that are common across multiple post-infection snapshots.

2. The computer-readable storage device of claim 1 including prior to comparing the monitored activities, normalizing the monitored activities.

3. The computer-readable storage device of claim 2 wherein the normalizing includes associating categories with the monitored activities.

4. The computer-readable storage device of claim 3 wherein a first monitored activity and a second monitored activity are common when associated with the same category.

5. The computer-readable storage device of claim 1 including automatically re-configuring security policies to prevent future malware infections.

6. A computer-readable storage device containing computer-executable instructions for controlling a computing device to analyze a malware infection by a method comprising:

receiving post-infection snapshots from a plurality of machines suspected of being infected with malware, the post-infection snapshot of a machine identifying monitored activities of the machine subsequent to the machine being suspected of being infected with malware, wherein the monitored activities of the machine relate to accessing of an operating system resource of an operating system executing on the machine; and

comparing the monitored activities of the post-infection snapshots of different machines to identify monitored activities that are common across multiple post-infection snapshots of different machines that may be related to the malware infection.

7. The computer-readable storage device of claim 6 wherein the comparing identifies monitored activities that are common across multiple post-infection snapshots.

8. The computer-readable storage device of claim 7 including prior to comparing the monitored activities, normalizing the monitored activities.

9. The computer-readable storage device of claim 8 wherein the normalizing includes associating categories with the monitored activities.

10. The computer-readable storage device of claim 8 wherein monitored activities associated with the same category are common.

11. The computer-readable storage device of claim 10 including mapping the normalized activities to malware states of a malware state model.

12. The computer-readable storage device of claim 6 including automatically re-configuring security policies to prevent malware infections.

13. The computer-readable storage device of claim 6 including after identifying monitored activities that may be related to the malware infection, providing a recommendation for responding to the malware infection.

14. A computing device for analyzing a malware infection comprising:

a data store storing post-infection snapshots of machines suspected of being infected with malware, the post-infection snapshots identifying monitored activities of machines suspected of being infected with malware subsequent to the machine being suspected of being infected with malware, wherein the monitored activities relate to accessing of an operating system resource of an operating system executing on the machine;

a memory storing computer-executable instructions of:

a component that compares the monitored activities of the post-infection snapshots of different machines to identify monitored activities that are common across multiple post-infection snapshots of different machines; and

a component that indicates that the identified monitored activities may be related to the malware infection; and

a processor that executes the computer-executable instructions stored in the memory.

15. The computing device of claim 14 including a component that, prior to comparing the monitored activities, normalizes the monitored activities.

16. The computing device of claim 15 wherein the component that normalizes associates categories with the monitored activities.

17. The computing device of claim 16 wherein a first normalized activity of a first machine and a second normalized activity of a second machine are common when associated with the same category.

18. The computing device of claim 16 wherein the computer-executable instructions includes a component that maps the normalized activities to malware states of a malware state model.

19. The computing device of claim 14 wherein the computer-executable instructions include an expert system that, after monitored activities are identified, provides a recommendation for responding to the malware infection based on the identified monitored activities.

20. The computing device of claim 14 wherein the computer-executable instructions include a component that automatically re-configures security policies to prevent malware infections.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2014
From: HARTRELL, GREGORY D.; STEEVES, DAVID J.; HUDIS, EFIM
To: MICROSOFT CORPORATION
Reel/Frame 033704/0559 →
Continuity (2)
Continuation 11321754 · Dec 28, 2005
Related Publication 20120137342A1 · May 31, 2012