Behavioral model based malware protection system and method
Abstract
A method includes identifying an attempt to access protected data accessible by way of a computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data. The method also includes generating a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process. The method further includes causing, by a processor, the malicious process to be remediated with respect to the computing device. The forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
identifying an attempt to access protected data accessible by way of a computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data; generating a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process; and causing, by a processor, the malicious process to be remediated with respect to the computing device, wherein the forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.
2 . The method of claim 1 , further comprising:
processing the forensic image to determine one or more indicators of compromise associated with the malicious process.
3 . The method of claim 2 , further comprising:
causing, at least in part, one or more of the forensic image, the one or more indicators of compromise, an event log detailing the one or more interactions with the protected data, or metadata to be stored in a database.
4 . The method of claim 2 , further comprising:
causing, at least in part, the one or more indicators of compromise to be communicated to a malicious process remediation platform; and causing, at least in part, the malicious process remediation platform to share the one or more indicators of compromise with one or more other computing devices associated with the malicious process remediation platform.
5 . The method of claim 4 , wherein the malicious process remediation platform is configured to store one or more of the forensic image, the one or more indicators of compromise, an event log detailing the one or more interactions with the protected data, or metadata.
6 . The method of claim 4 , wherein one or more of the computing device or the one or more other computing devices comprise a communication device, and the malicious process remediation platform is configured to remediate the malicious process with respect to the computing device or the one or more other computing devices by one or more of blocking network traffic through the communication device to the computing device or the one or more other computing devices, or redirecting network traffic through the communication device away from the computing device or the one or more other computing devices.
7 . The method of claim 6 , wherein the communication device comprises one or more of a router, a switch, a firewall, or a computer associated with an intrusion protection service.
8 . The method of claim 4 , wherein the malicious process remediation platform is remote from the computing device.
9 . The method of claim 1 , wherein the behavioral model is shared with a malicious process determination module, the malicious process determination module processes the attempt to access the protected data and compares the attempt to access the protected data with the received behavioral model, and the malicious process determination module is remote from the computing device.
10 . The method of claim 1 , wherein the one or more interactions associated with the protected data comprise one or more of a file system event, a read or write interaction accessing the protected data, or a change to metadata.
11 . The method of claim 1 , wherein remediation of the malicious process comprises one or more of (1) terminating the malicious process; (2) identifying and removing data associated with the malicious process from a memory; or (3) identifying and removing persistence mechanisms configured to allow the malicious process to reoccur.
12 . The method of claim 1 , wherein the behavioral model is based, at least in part, on received information associated with one or more of a user interacting with the computing device configured to access the protected data, the computing device configured to access the protected data, a network portal configured to enable the computing device configured to access the protected data to communicate with a remote computing device, a process by which the protected data is accessed, a file type of the protected data, metadata, or a time the protected data is accessed.
13 . The method of claim 1 , wherein the computing device is accessible by way of a hypervisor and the attempt to access the protected data occurs by way of the hypervisor.
14 . An apparatus, comprising:
at least one processor; and at least one memory including computer program code for one or more programs, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to perform at least the following, identify an attempt to access protected data accessible by way of a computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data; generate a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process; and cause the malicious process to be remediated with respect to the computing device, wherein the forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.
15 . The apparatus of claim 14 , wherein the apparatus is further caused to:
process the forensic image to determine one or more indicators of compromise associated with the malicious process.
16 . The apparatus of claim 15 , wherein the apparatus is further caused to:
cause, at least in part, one or more of the forensic image, the one or more indicators of compromise, an event log detailing the one or more interactions with the protected data, or metadata to be stored in a database.
17 . The apparatus of claim 15 , wherein the apparatus is further caused to:
cause, at least in part, the one or more indicators of compromise to be communicated to a malicious process remediation platform; and cause, at least in part, the malicious process remediation platform to share the one or more indicators of compromise with one or more other computing devices associated with the malicious process remediation platform.
18 . The apparatus of claim 17 , wherein one or more of the computing device or the one or more other computing devices comprise a communication device, and the malicious process remediation platform is configured to remediate the malicious process with respect to the computing device or the one or more other computing devices by one or more of blocking network traffic through the communication device to the computing device or the one or more other computing devices, or redirecting network traffic through the communication device away from the computing device or the one or more other computing devices.
19 . The apparatus of claim 14 , wherein remediation of the malicious process comprises one or more of (1) terminating the malicious process; (2) identifying and removing data associated with the malicious process from a memory; or (3) identifying and removing persistence mechanisms that are configured to allow the malicious process to reoccur.
20 . A system, comprising:
a first computing device configured to:
identify an attempt to access protected data accessible by way of the first computing device as a malicious process based, at least in part, on a determined degree of variation between the attempt to access the protected data and a behavioral model that describes one or more interactions associated with the protected data;
generate a forensic image of one or more of the malicious process, one or more processes related to the malicious process, data associated with the malicious process, or data associated with the one or more processes related to the malicious process; and
cause the malicious process to be remediated with respect to the computing device; and
a malicious process remediation platform communicatively coupled with the computing device, the malicious process remediation platform being configured share one or more indicators of compromise with a second computing device communicatively coupled with the malicious process remediation platform, wherein the forensic image is generated upon identifying the abnormal attempt to access the protected data as a malicious process and prior to completion of execution of the malicious process.Join the waitlist — get patent alerts
Track US2017230389A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.