IP Library Granted Patent US 9,218,461
Granted Patent B2
US 9,218,461 · App. 13/308,528 · Granted Dec 22, 2015

Method and apparatus for detecting malicious software through contextual convictions

Inventors: Oliver Friedrichs (Woodside, CA); Alfred Huger (Calgary, CA); Adam O'Donnell (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F21/00G06F21/56G06F21/577H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,218,461
App. No.
13/308,528
Granted
Dec 22, 2015
Kind
B2
Abstract

Novel methods, components, and systems that enhance traditional techniques for detecting malicious software are presented. More specifically, we describe methods, components, and systems that leverage important contextual information from a client system (such as recent history of events on that system) to detect malicious software that might have otherwise gone ignored. The disclosed invention provides a significant improvement with regard to detection capabilities compared to previous approaches.

Claims (65)

1. A computer-implemented method for making a determination concerning whether a software application is benign or malicious comprising:

extracting metadata about the application;

gathering a first set of contextual information concerning the system to generate a constructed infection history for a client, wherein said first set of contextual information includes recent infection history, applications running on the system, web sites visited, the geographic location of the client, the Internet Protocol (IP) address of the client, and a client identifier;

transmitting the metadata and the first set of contextual information to a server component, wherein the metadata and the first set of contextual information are encoded prior to the transmitting;

making a determination as to whether the application is benign or malicious by:

examining the metadata and determining that the application is suspicious; and

when the application is suspicious and a final determination as to whether the application is benign or malicious cannot be made without analyzing the first set of contextual information, examining the metadata based on the constructed infection history, including analyzing the metadata based on geographic parameters and web site specific parameters determined based on the constructed infection history, to determine whether the application is benign or malicious;

deriving a model based on the determination, the model encoding rules to be utilized in making future determinations when a second set of contextual information is similar to the first set of contextual information;

transmitting a response to the client containing information relating to the determination; and

making a determination as to whether to take any action concerning the application based on the information from the server component.

2. The method according to claim 1 , wherein said extracted metadata is selected from the group consisting of traditional fingerprints and generic signatures.

3. The method according to claim 1 , wherein said server component and said client reside on the same computing device.

4. The method according to claim 1 , wherein said server component and said client reside on separate and remote computing devices.

5. The method according to claim 1 , wherein said client continuously gathers contextual information, the first set of contextual information being from a first period of time and the second set of contextual information being from a second period of time.

6. Non-transitory computer-readable storage medium containing computer readable instructions operable to make a determination concerning whether a software application is benign or malicious, said instructions comprising instructions operable to:

extract metadata about the application;

gather a first set of contextual information concerning the system to generate a constructed infection history for a client, wherein said first set of contextual information includes recent infection history, applications running on the system, web sites visited, the geographic location of the client, the Internet Protocol (IP) address of the client, and a client identifier;

transmit the metadata and the first set of contextual information to a server component, wherein the metadata and the a first set of contextual information is encoded prior to the transmitting;

make a determination as to whether the application is benign or malicious by:

examining the metadata and determining that the application is suspicious; and

when the application is suspicious and a final determination as to whether the application is benign or malicious cannot be made without analyzing the first set of contextual information, examining the metadata based on the constructed infection history, including analyzing the metadata based on geographic parameters and web site specific parameters determined based on the constructed infection history, to determine whether the application is benign or malicious;

derive a model based on the determination, the model encoding rules to be utilized in making future determinations when a second set of contextual information is similar to the first set of contextual information;

transmit a response to the client containing information relating to the determination; and

make a determination as to whether to take any action concerning the application based on the information from the server component.

7. The non-transitory computer-readable storage medium according to claim 6 , wherein said extracted metadata is selected from the group consisting of traditional fingerprints and generic signatures.

8. The non-transitory computer-readable storage medium according to claim 6 , wherein said server component and said client reside on the same computing device.

9. The non-transitory computer-readable storage medium according to claim 6 , wherein said server component and said client reside on separate and remote computing devices.

10. The non-transitory computer-readable storage medium according to claim 6 , wherein said client continuously gathers contextual information, the first set of contextual information being from a first period of time and the second set of contextual information being from a second period of time.

11. Non-transitory computer-readable storage medium containing instructions operable to make a determination concerning whether a software application is benign or malicious, said instructions comprising instructions operable to:

extract metadata about the application;

gather a first set of contextual information concerning the system to generate a constructed infection history for a client, wherein said first set of contextual information includes recent infection history, applications running on the system, web sites visited, the geographic location of the client, the Internet Protocol (IP) address of the client, and a client identifier;

transmit the metadata and the first set of contextual information to a server component, wherein the metadata and the first set of contextual information are encoded prior to the transmitting;

receive a response from the server component relating to a determination as to whether the application is benign or malicious based on the metadata and the first set of contextual information, wherein said determination as to whether the application is benign or malicious is made by:

examining the metadata and determining that the application is suspicious;

when the application is suspicious and a final determination as to whether the application is benign or malicious cannot be made without analyzing the first set of contextual information, examining the metadata based on the constructed infection history, including analyzing the metadata based on geographic parameters and web site specific parameters determined based on the constructed infection history, to determine whether the application is benign or malicious; and

derive a model based on the determination, the model encoding rules to be utilized in making future determinations when a second set of contextual information is similar to the first set of contextual information; and

take an action with respect to the application based on the information received from the server component.

12. The non-transitory computer-readable storage medium according to claim 11 , wherein said server component and said client reside on the same computing device.

13. The non-transitory computer-readable storage medium according to claim 11 , wherein said server component and said client reside on separate and remote computing devices.

14. The non-transitory computer-readable storage medium according to claim 11 , wherein said client continuously gathers contextual information, the first set of contextual information being from a first period of time and the second set of contextual information being from a second period of time.

15. Non-transitory computer-readable storage medium containing instructions operable to make a determination concerning whether a software application is benign or malicious, said instructions comprising instructions operable to:

receive metadata about the application and a first set of contextual information concerning the system to generate a constructed infection history for a client, wherein the metadata and the first set of contextual information are encoded prior to being received, and wherein said first set of contextual information includes recent infection history, applications running on the system, web sites visited, the geographic location of the client, the Internet Protocol (IP) address of the client, and a client identifier;

make a determination as to whether the application is benign or malicious by:

examining the metadata and determining that the application is suspicious; and

when the application is suspicious and a final determination as to whether the application is benign or malicious cannot be made without analyzing the first set of contextual information, examining the metadata based on the constructed infection history, including analyzing the metadata based on geographic parameters and web site specific parameters determined based on the constructed infection history, to determine whether the application is benign or malicious;

derive a model based on the determination, the model encoding rules to be utilized in making future determinations when a second set of contextual information is similar to the first set of contextual information; and

transmit a response to the client containing information relating to the determination.

16. The non-transitory computer-readable storage medium according to claim 15 , wherein said metadata is selected from the group consisting of traditional fingerprints and generic signatures.

17. The non-transitory computer-readable storage medium according to claim 15 , wherein said client continuously gathers contextual information, the first set of contextual information being from a first period of time and the second set of contextual information being from a second period of time.

18. A computer system configured to determine whether a software application is benign or malicious, comprising:

a first non-transitory computer-readable storage medium containing instructions operable to:

extract metadata about the application;

gather a first set of contextual information concerning the system to generated a constructed infection history for a client, wherein said first set of contextual information includes recent infection history, applications running on the system, web sites visited, the geographic location of the client, the Internet Protocol (IP) address of the client, and a client identifier; and

transmit the metadata and the first set of contextual information to a server component, wherein the metadata and the first set of contextual information are encoded prior to being transmitted; and

a second non-transitory computer-readable storage medium containing instructions operable to:

make a determination as to whether the application is benign or malicious by:

examining the metadata and determining that the application is suspicious; and

when the application is suspicious and a final determination as to whether the application is benign or malicious cannot be made without analyzing the first set of contextual information, examining the metadata based on the constructed infection history, including analyzing the metadata based on geographic parameters and web site specific parameters determined based on the constructed infection history, to determine whether the application is benign or malicious;

derive a model based on the determination, the model encoding rules to be utilized in making future determinations when a second set of contextual information is similar to the first set of contextual information; and

transmit a response to the client containing information relating to the determination.

19. The computer system according to claim 18 , wherein said extracted metadata is selected from the group consisting of traditional fingerprints and generic signatures.

20. The computer system according to claim 18 , wherein said server component and said client reside on the same computing device.

21. The computer system according to claim 18 , wherein said server component and said client reside on separate and remote computing devices.

22. The computer system according to claim 18 , wherein said client continuously gathers contextual information, the first set of contextual information being from a first period of time and the second set of contextual information being from a second period of time.

23. The non-transitory computer-readable storage medium according to claim 11 , wherein said extracted metadata is selected from the group consisting of traditional fingerprints and generic signatures.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2014
From: IMMUNET LLC
To: SOURCEFIRE LLC
Reel/Frame 033235/0701 →
CHANGE OF NAME Recorded Jul 2, 2014
From: IMMUNET CORPORATION
To: IMMUNET LLC
Reel/Frame 033267/0471 →
CHANGE OF NAME Recorded Mar 24, 2014
From: SOURCEFIRE, INC.
To: SOURCEFIRE LLC
Reel/Frame 032513/0481 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2014
From: SOURCEFIRE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 032513/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2012
From: FRIEDRICHS, OLIVER; HUGER, ALFRED A.; O'DONNELL, ADAM J.
To: IMMUNET CORPORATION
Reel/Frame 027798/0394 →
Continuity (5)
Provisional Application 61418532 · Dec 1, 2010
Provisional Application 61418514 · Dec 1, 2010
Provisional Application 61418547 · Dec 1, 2010
Provisional Application 61418580 · Dec 1, 2010
Related Publication 20130139261A1 · May 30, 2013