US2017230389A1PendingUtilityA1

Behavioral model based malware protection system and method

Assignee: HOPLITE IND INCPriority: Dec 17, 2013Filed: Jun 2, 2016Published: Aug 10, 2017
Est. expiryDec 17, 2033(~7.4 yrs left)· nominal 20-yr term from priority
H04L 63/1416G06F 21/6218H04L 63/1425H04L 63/145H04W 12/128
36
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method includes identifying an attempt to access protected data accessible by way of a computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data. The method also includes generating a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process. The method further includes causing, by a processor, the malicious process to be remediated with respect to the computing device. The forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 identifying an attempt to access protected data accessible by way of a computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data;   generating a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process; and   causing, by a processor, the malicious process to be remediated with respect to the computing device,   wherein the forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.   
     
     
         2 . The method of  claim 1 , further comprising:
 processing the forensic image to determine one or more indicators of compromise associated with the malicious process.   
     
     
         3 . The method of  claim 2 , further comprising:
 causing, at least in part, one or more of the forensic image, the one or more indicators of compromise, an event log detailing the one or more interactions with the protected data, or metadata to be stored in a database.   
     
     
         4 . The method of  claim 2 , further comprising:
 causing, at least in part, the one or more indicators of compromise to be communicated to a malicious process remediation platform; and   causing, at least in part, the malicious process remediation platform to share the one or more indicators of compromise with one or more other computing devices associated with the malicious process remediation platform.   
     
     
         5 . The method of  claim 4 , wherein the malicious process remediation platform is configured to store one or more of the forensic image, the one or more indicators of compromise, an event log detailing the one or more interactions with the protected data, or metadata. 
     
     
         6 . The method of  claim 4 , wherein one or more of the computing device or the one or more other computing devices comprise a communication device, and the malicious process remediation platform is configured to remediate the malicious process with respect to the computing device or the one or more other computing devices by one or more of blocking network traffic through the communication device to the computing device or the one or more other computing devices, or redirecting network traffic through the communication device away from the computing device or the one or more other computing devices. 
     
     
         7 . The method of  claim 6 , wherein the communication device comprises one or more of a router, a switch, a firewall, or a computer associated with an intrusion protection service. 
     
     
         8 . The method of  claim 4 , wherein the malicious process remediation platform is remote from the computing device. 
     
     
         9 . The method of  claim 1 , wherein the behavioral model is shared with a malicious process determination module, the malicious process determination module processes the attempt to access the protected data and compares the attempt to access the protected data with the received behavioral model, and the malicious process determination module is remote from the computing device. 
     
     
         10 . The method of  claim 1 , wherein the one or more interactions associated with the protected data comprise one or more of a file system event, a read or write interaction accessing the protected data, or a change to metadata. 
     
     
         11 . The method of  claim 1 , wherein remediation of the malicious process comprises one or more of (1) terminating the malicious process; (2) identifying and removing data associated with the malicious process from a memory; or (3) identifying and removing persistence mechanisms configured to allow the malicious process to reoccur. 
     
     
         12 . The method of  claim 1 , wherein the behavioral model is based, at least in part, on received information associated with one or more of a user interacting with the computing device configured to access the protected data, the computing device configured to access the protected data, a network portal configured to enable the computing device configured to access the protected data to communicate with a remote computing device, a process by which the protected data is accessed, a file type of the protected data, metadata, or a time the protected data is accessed. 
     
     
         13 . The method of  claim 1 , wherein the computing device is accessible by way of a hypervisor and the attempt to access the protected data occurs by way of the hypervisor. 
     
     
         14 . An apparatus, comprising:
 at least one processor; and   at least one memory including computer program code for one or more programs,   the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following,   identify an attempt to access protected data accessible by way of a computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data;   generate a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process; and   cause the malicious process to be remediated with respect to the computing device,   wherein the forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.   
     
     
         15 . The apparatus of  claim 14 , wherein the apparatus is further caused to:
 process the forensic image to determine one or more indicators of compromise associated with the malicious process.   
     
     
         16 . The apparatus of  claim 15 , wherein the apparatus is further caused to:
 cause, at least in part, one or more of the forensic image, the one or more indicators of compromise, an event log detailing the one or more interactions with the protected data, or metadata to be stored in a database.   
     
     
         17 . The apparatus of  claim 15 , wherein the apparatus is further caused to:
 cause, at least in part, the one or more indicators of compromise to be communicated to a malicious process remediation platform; and   cause, at least in part, the malicious process remediation platform to share the one or more indicators of compromise with one or more other computing devices associated with the malicious process remediation platform.   
     
     
         18 . The apparatus of  claim 17 , wherein one or more of the computing device or the one or more other computing devices comprise a communication device, and the malicious process remediation platform is configured to remediate the malicious process with respect to the computing device or the one or more other computing devices by one or more of blocking network traffic through the communication device to the computing device or the one or more other computing devices, or redirecting network traffic through the communication device away from the computing device or the one or more other computing devices. 
     
     
         19 . The apparatus of  claim 14 , wherein remediation of the malicious process comprises one or more of (1) terminating the malicious process; (2) identifying and removing data associated with the malicious process from a memory; or (3) identifying and removing persistence mechanisms that are configured to allow the malicious process to reoccur. 
     
     
         20 . A system, comprising:
 a first computing device configured to:
 identify an attempt to access protected data accessible by way of the first computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data; 
 generate a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process; and 
 cause the malicious process to be remediated with respect to the computing device; and 
   a malicious process remediation platform communicatively coupled with the computing device, the malicious process remediation platform being configured share one or more indicators of compromise with a second computing device communicatively coupled with the malicious process remediation platform,   wherein the forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.

Join the waitlist — get patent alerts

Track US2017230389A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.