IP Library Granted Patent US 11,882,134
Granted Patent B2
US 11,882,134 · App. 17/871,906 · Granted Jan 23, 2024

Stateful rule generation for behavior based threat detection

Inventors: Paul M. Drapeau (Mendon, MA); Kyle P. Gwinnup (Somerville, MA)
Assignee: VMware, Inc.
H04L63/1416B60W60/0011B60W60/0018B60W60/0025G06F18/25H04L43/0817H04L63/0263H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,134
App. No.
17/871,906
Granted
Jan 23, 2024
Kind
B2
Abstract

Improved tools and techniques for generating stateful rules for behavior-based threat detection enable threat analysts, who do not have advanced computer programming skills, to quickly and easily generate high-level representations of stateful behavioral rules, which are then compiled into a format suitable for execution by a stateful rule processing engine. In some examples, the high-level representations of stateful rules are coded in a high-level, domain specific language (DSL). The DSL may provide high-level primitives suitable for (1) expressing sequences of attack behaviors, (2) tagging computational entities (e.g., threads, processes, applications, systems, users, etc.) with states (e.g., user-defined states), and/or (3) performing operations on endpoint nodes (e.g., reporting activity, blocking activity, terminating processes, etc.).

Claims (49)

1. A method of generating a stateful rule for behavior based threat detection, the method comprising:

identifying a new threat in a first run of an attack on an endpoint node;

upon identifying the new threat, importing a primitive rule;

compiling the primitive rule;

deploying the compiled primitive rule on the endpoint node;

generating, using the deployed primitive rule, additional information about the new threat in a second run of the attack;

based on the additional information about the new threat, generating a new rule;

compiling the new rule;

deploying the compiled new rule on the endpoint node; and

blocking, using the deployed new rule, the new threat in a third run of the attack.

2. The method of claim 1 , wherein importing the primitive rule comprises importing the primitive rule into a domain-specific language (DSL) programming environment.

3. The method of claim 1 , wherein generating the new rule comprises improving the primitive rule to generate the new rule.

4. The method of claim 1 , wherein the new threat includes a launching of a process from a file attached to an email.

5. The method of claim 1 , wherein the primitive rule includes a high-level representation of a stateful behavioral rule.

6. The method of claim 1 , wherein the compiled primitive rule is a low-level representation of the primitive rule and the compiled new rule is a low-level representation of the new rule.

7. The method of claim 6 , wherein the low-level representation of the primitive rule and the low-level representation of the new rule are in JavaScript Object Notation (JSON).

8. A system for generating a stateful rule for behavior based threat detection, the system comprising:

a processor; and

a non-transitory computer readable medium having stored thereon program code, the program code causing the processor to:

identify a new threat in a first run of an attack on an endpoint node;

upon identifying the new threat, import a primitive rule;

compile the primitive rule;

deploy the compiled primitive rule on the endpoint node;

generate, using the deployed primitive rule, additional information about the new threat in a second run of the attack;

based on the additional information about the new threat, generate a new rule;

compile the new rule;

deploy the compiled new rule on the endpoint node; and

block, using the deployed new rule, the new threat in a third run of the attack.

9. The system of claim 8 , wherein importing the primitive rule comprises importing the primitive rule into a domain-specific language (DSL) programming environment.

10. The system of claim 8 , generating the new rule comprises improving the primitive rule to generate the new rule.

11. The system of claim 8 , wherein the new threat includes a launching of a process from a file attached to an email.

12. The system of claim 8 , wherein the primitive rule includes a high-level representation of a stateful behavioral rule.

13. The system of claim 8 , wherein the compiled primitive rule is a low-level representation of the primitive rule and the compiled new rule is a low-level representation of the new rule.

14. The system of claim 13 , the low-level representation of the primitive rule and the low-level representation of the new rule are in JavaScript Object Notation (JSON).

15. A non-transitory computer readable storage medium having stored thereon program code executable by a computer system, the program code embodying a method comprising:

identifying a new threat in a first run of an attack on an endpoint node;

upon identifying the new threat, importing a primitive rule;

compiling the primitive rule;

deploying the compiled primitive rule on the endpoint node;

generating, using the deployed primitive rule, additional information about the new threat in a second run of the attack;

based on the additional information about the new threat, generating a new rule;

compiling the new rule;

deploying the compiled new rule on the endpoint node; and

blocking, using the deployed new rule, the new threat in a third run of the attack.

16. The non-transitory computer readable storage medium of claim 15 , wherein importing the primitive rule comprises importing the primitive rule into a domain-specific language (DSL) programming environment.

17. The non-transitory computer readable storage medium of claim 15 , wherein generating the new rule comprises improving the primitive rule to generate the new rule.

18. The non-transitory computer readable storage medium of claim 17 , wherein the new threat includes a launching of a process from a file attached to an email.

19. The non-transitory computer readable storage medium of claim 15 , wherein the primitive rule includes a high-level representation of a stateful behavioral rule.

20. The non-transitory computer readable storage medium of claim 15 , wherein the compiled primitive rule is a low-level representation of the primitive rule and the compiled new rule is a low-level representation of the new rule, wherein the low-level representation of the primitive rule and the low-level representation of the new rule are in JavaScript Object Notation (JSON).

Assignments (1)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (3)
Continuation 16718183 · Dec 18, 2019
Provisional Application 62857465 · Jun 5, 2019
Related Publication 20220371621A1 · Nov 24, 2022