US2019081963A1PendingUtilityA1
Realtime event detection
Est. expirySep 8, 2037(~11.1 yrs left)· nominal 20-yr term from priority
Inventors:William David Waghorn
G06F 16/9024H04L 63/1441G06F 21/554H04L 63/0272G06F 21/56H04L 63/101G06F 21/552G06F 21/565H04L 63/1416H04L 63/0227G06F 9/542
59
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
An event handler implements a state machine or similar construct for processing of complex event chains as incremental events are detected. This approach advantageously limits processing to monitoring for and responding to a next event in a sequence of events, and supports complex event detection in a manner that scales efficiently in time and computation.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:
identifying a sequence of events associated with malware on an endpoint; configuring an event handler for use with the endpoint, the event handler including a first state configured to monitor for an occurrence of a first one of the sequence of events, and configured to respond to the occurrence of the first one of the sequence of events by transitioning to a second state where the event handler monitors for a second one of the sequence of events, wherein the second one of the sequence of events is a next sequential one of the sequence of events associated with malware, the even handler further configured to respond to a terminal event in the sequence of events by identifying the malware on the endpoint and to respond to an exit condition by returning to the first one of the sequence of events; deploying the event handler for use with the endpoint; monitoring events on the endpoint with the event handler; detecting the malware on the endpoint based upon an occurrence of the sequence of events concluding in the terminal event; and remediating the malware on the endpoint.
2 . The computer program product of claim 1 wherein the one or more computing devices includes the endpoint.
3 . The computer program product of claim 1 wherein the one or more computing devices includes a threat management facility for an enterprise that includes the endpoint.
4 . A method comprising:
identifying a sequence of events associated with malware on an endpoint; configuring an event handler for use with the endpoint, the event handler including a first state configured to monitor for an occurrence of a first one of the sequence of events, and configured to respond to the occurrence of the first one of the sequence of events by transitioning to a second state where the event handler monitors for a second one of the sequence of events, wherein the second one of the sequence of events is a next sequential one of the sequence of events associated with malware, the even handler further configured to respond to a terminal event in the sequence of events by identifying the malware on the endpoint and to respond to an exit condition by returning to the first one of the sequence of events; and deploying the event handler for use with the endpoint.
5 . The method of claim 4 further comprising monitoring events on the endpoint with the event handler.
6 . The method of claim 4 wherein the second one of the sequence of events is the terminal event.
7 . The method of claim 4 wherein deploying the event handler includes deploying the event handler as a security agent on the endpoint.
8 . The method of claim 4 wherein deploying the event handler includes deploying the event handler on a threat management facility, wherein the endpoint is instrumented to communicate event detection information for the sequence of events to the threat management facility.
9 . The method of claim 4 wherein at least one of the sequence of events includes a multi-parameter event.
10 . The method of claim 4 wherein the first one of the sequence of events is an initial one of the sequence of events.
11 . The method of claim 4 wherein the event handler is configured to monitor events for a plurality of sequences of events, each one of the plurality of sequences of events associated with a particular malware item.
12 . The method of claim 4 further comprising providing a scripting language for configuring the event handler.
13 . The method of claim 4 wherein identifying the sequence of events includes traversing an event graph among a sequence of causal events in reverse chronological order to a root cause of the malware.
14 . The method of claim 13 wherein providing the event handler includes creating the sequence of events based on a forward traversal of the event graph.
15 . The method of claim 4 wherein the event handler includes a state machine comprising a plurality of states each corresponding to a monitoring state for one of the sequence of events.
16 . The method of claim 4 wherein the exit condition includes a time limit for detection of the malware.
17 . The method of claim 4 wherein the event handler includes a plurality of exit conditions that return the event handler to the first state.
18 . The method of claim 4 wherein the sequence of events includes at least one event from a computing object selected from a group consisting of a data file, a process, an application, a registry entry, a network address, and a peripheral device.
19 . The method of claim 4 wherein the sequence of events includes at least one event from a network address selected from a group consisting of a uniform resource locator (URL), an internet protocol (IP) address, and a domain name.
20 . The method of claim 4 wherein the sequence of events includes at least one event from a peripheral device selected from a group including at least one of a universal serial bus (USB) memory, a network interface card, a camera, a printer, a mouse and a keyboard.
21 . The method of claim 4 wherein the sequence of events includes at least one file operation selected from a group consisting of a read, a write, an open, a move, a copy and a delete.
22 . The method of claim 4 wherein the sequence of events includes at least one inter-process communication selected from a group consisting of a create, a handle, a debug and a remote injection.
23 . A method comprising:
identifying a sequence of events associated with malware on an endpoint, the sequence of events including at least an initial event and a terminal event; configuring an event handler to transition between a number of states in order, each one of the states monitoring for a respective one of the events in the sequence of events as a condition for transitioning to a next one of the number of states; executing the event handler to monitor activity on an endpoint; when the event handler transitions through the number of states and detects the terminal event on the endpoint, identifying the endpoint as affected by the malware; and initiating a remedial action to address the malware on the endpoint.
24 . An endpoint comprising:
a network interface; a memory; and a processor configured by computer executable code stored in the memory to detect malware by operating an event handler with a state machine having a plurality of states including a first state configured to monitor for an occurrence of a first one of a sequence of events, and configured to respond to the occurrence of the first one of the sequence of events by transitioning to a second state where the event handler monitors for a second one of the sequence of events, wherein the second one of the sequence of events is a next sequential one of the sequence of events associated with malware, the even handler further configured to respond to a terminal event in the sequence of events by identifying the malware on the endpoint and to respond to an exit condition by returning to the first one of the sequence of events.Join the waitlist — get patent alerts
Track US2019081963A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.