US 10,122,746 B1Grant
Correlation and consolidation of analytic data for holistic view of malware attack
Issue Date:2018-11-06
•20 Claims
•15 Drawing Sheets
Abstract
In communication with security appliances, an electronic device for providing a holistic view of a malware attack is described. The electronic device features one or more processors and a storage device. The storage device includes aggregation logic, correlation logic, consolidation logic, and display logic: The aggregation logic is configured to receive input attributes and analysis attributes from each of the security appliances. The correlation logic attempts to find relationships between analysis attributes provided from each security appliance. The consolidation logic receives at least (i) a first analysis attribute from a first security appliance and (ii) a second analysis attribute from a second security appliance in response to the first analysis attribute corresponding to the second analysis attribute. The display logic generates display information including the consolidated input attributes.
Metadata
Assignee
- FireEye, Inc.
Inventors
- Jayaraman Manni
- Philip Eun
- Michael M. Berrow
Application Information
Application Number:US 15/583,725
Filing Date:2017-05-01
Priority Date:2013-03-14
Art Unit:2497
Classifications
IPC:
H04L29/06
Field of Search:
H04L 63/1441H04L 63/14H04L 63/1408H04L 63/1416H04L 63/145H04L 63/1483H04L 63/1433
Patent Drawings (15 sheets)
Description
RELATED APPLICATIONS
[0001] This application is a continuation of U.S. patent application Ser. No. 15/096,088 filed Apr. 11, 2016, now U.S. Pat. No. 9,641,546, which is a continuation of U.S. patent application Ser. No. 13/828,785 filed on Mar. 14, 2013, now U.S. Pat. No. 9,311,479, the entire contents of both of which are incorporated by reference herein.
FIELD OF THE INVENTION
[0002] Embodiments of the disclosure relate to the field of network security. More specifically, one embodiment of the disclosure relates to a system, apparatus and method for correlating analytic data produced by different malware content detection systems, and consolidating portions of this data to provide a holistic view of a malware attack.
BACKGROUND
[0003] Over the last decade, malicious software (malware) has become a pervasive problem for Internet users. In some situations, malware is a program or file that is embedded within downloadable content and designed to adversely influence (i.e. attack) normal operations of a computer. Examples of different types of malware may include bots, computer viruses, worms, Trojan horses, spyware, adware, or any other programming that operates within the computer without permission.
[0004] For instance, content may be embedded with objects associated with a web page hosted by a malicious web site. By downloading this content, malware causing another web page to be requested from a malicious web site may be unknowingly installed on the computer. Similarly, malware may also be installed on a computer upon receipt or opening of an electronic mail (email) message. For example, an email message may contain an attachment, such as a Portable Document Format (PDF) document, with embedded executable malware. Also, malware may exist in files infected through any of a variety of attack vectors, which are uploaded from the infected computer onto a networked storage device such as a file share.
[0005] Over the past few years, various types of security appliances have been deployed at different segments of a network. These security appliances are configured to uncover the presence of malware embedded within ingress content propagating through over these different segments. However, there is no mechanism that operates, in concert with multiple security appliances, to correlate and consolidate information from these security appliances in order to provide a customer with a holistic view of a malware attack.
BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Embodiments of the invention are illustrated by way of example and not by way of limitation in the figures of the accompanying drawings, in which like references indicate similar elements and in which:
[0007] FIG. 1 is an exemplary block diagram of a communication network deploying a plurality of malware content detection (MCD) systems.
[0008] FIG. 2 is an exemplary block diagram of logic implemented within the management system of FIG. 1 .
[0009] FIG. 3 is an exemplary block diagram of an Analytic Data Response message received by the management system from a MCD system.
[0010] FIG. 4 is an exemplary diagram of logic within a MCD system.
[0011] FIG. 5A is an exemplary embodiment of a flowchart partially illustrating an operation of populating a data store by a MCD system for subsequent access by the management system.
[0012] FIGS. 5B and 5C are exemplary general diagrams of the aggregation of analytic data by a MCD system for supply to the management system.
[0013] FIG. 6A is an exemplary embodiment of a flowchart of the general operations for correlating and consolidating analytic data from multiple MCD systems as conducted by the management system.
[0014] FIG. 6B is an exemplary embodiment of a more detailed flowchart partially illustrating correlation and consolidation of analytic data by the management system.
[0015] FIGS. 7A-7D are exemplary embodiments of a detailed illustrative example of aggregation, correlation and consolidation of analytic data by the management system.
[0016] FIG. 8 is an exemplary embodiment of a display screen that includes data produced by the correlation logic and consolidation logic to provide a consumer with a holistic view of a malware attack.
DETAILED DESCRIPTION
[0017] Various embodiments of the disclosure relate to a management system configured to correlate analytic data received from multiple malware content detection (MCD) systems. In general, the management system controls the uploading of analytic data from each MCD system. This analytic data enables the management system to (i) determine whether the same malware appears to be present at different MCD systems (i.e. evidence of a malware attack) and (ii) consolidate at least a portion of the analytic data in order to provide a holistic view of the malware attack. This “holistic view” may be accomplished by generating one or more screen displays that provide comprehensive details concerning the network entry point and migration of suspicious network content.
[0018] More specifically, the management system is configured to receive, from each of the MCD systems, analytic data associated with suspicious network content that has been analyzed by that MCD system for malware. The analytic data comprises (1) information that identifies the suspicious network content (e.g., a time-stamp value, monotonic count value, or another type of identifier); (2) input attributes; and (3) analysis attributes. In general, “input attributes” include information used in the routing of the content, such as source and/or destination information. “Analysis attributes” include information directed to portions of the suspicious network content that are analyzed for malware (hereinafter referred to as “artifacts”) as well as one or more anomalous behaviors observed during malware detection analysis of the artifacts.
[0019] After receipt of analytic data from different MCD systems, the management system correlates the analytic data by recursively comparing analysis attributes recovered from one MCD system with analysis attributes recovered from one or more other MCD systems. Upon determining that at least certain analysis attributes from different MCD systems match, the input attributes corresponding to these compared analysis attributes may be consolidated to provide greater details as to the infection vector for the suspicious network content (e.g. initial source, number of recipients, time of receipt, etc.).
I. Terminology
[0020] In the following description, certain terminology is used to describe features of the invention. For example, in certain situations, the terms “logic” and “engine” are representative of hardware, firmware or software that is configured to perform one or more functions. As hardware, logic may include circuitry such as processing circuitry (e.g., a microprocessor, one or more processor cores, a programmable gate array, a microcontroller, an application specific integrated circuit, etc.), wireless receiver, transmitter and/or transceiver circuitry, semiconductor memory, combinatorial logic, or other types of electronic components.
[0021] As software, logic may be in the form of one or more software modules, such as executable code in the form of an executable application, an application programming interface (API), a subroutine, a function, a procedure, an applet, a servlet, a routine, source code, object code, a shared library/dynamic load library, or one or more instructions. These software modules may be stored in any type of a suitable non-transitory storage medium, or transitory storage medium (e.g., electrical, optical, acoustical or other form of propagated signals such as carrier waves, infrared signals, or digital signals). Examples of non-transitory storage medium may include, but is not limited or restricted to a programmable circuit; a semiconductor memory; non-persistent storage such as volatile memory (e.g., any type of random access memory “RAM”); persistent storage such as non-volatile memory (e.g., read-only memory “ROM”, power-backed RAM, flash memory, phase-change memory, etc.), a solid-state drive, hard disk drive, an optical disc drive, or a portable memory device. As firmware, the executable code is stored in persistent storage.
[0022] The term “network content” generally refers to information transmitted over a network as one or more messages, namely a grouping of information that comprises a header and a payload, such as any of the following: a packet; a frame; a stream being a sequence of packets or frames; an Asynchronous Transfer Mode “ATM” cell; or any other series of bits having a prescribed format. The “payload” is generally defined as including the data associated with the message such as text, software, an image, an object, audio, video, a Uniform Resource Locator (URL), or other types of digital data. The “header” is generally defined as including control information. However, the specific types of control information depend on the network content type.
[0023] For data traffic, such as data transmitted in accordance with a Hypertext Transfer Protocol (HTTP), HyperText Markup Language (HTML) protocol, the header may include source and destination Internet Protocol (IP) addresses (e.g., IPv4 or IPv6 addressing) and/or source and destination port information.
[0024] Another examples of network content includes email, which may be transmitted using an email protocol such as Simple Mail Transfer Protocol (SMTP), Post Office Protocol version 3 (POP3), or Internet Message Access Protocol (IMAP4). A further example of network content includes an Instant Message, which may be transmitted using Session Initiation Protocol (SIP) or Extensible Messaging and Presence Protocol (XMPP) for example. Yet another example of network content includes one or more files that are transferred using a data transfer protocol such as File Transfer Protocol (FTP) for subsequent storage on a file share. Where the network content is email, Instant Message or a file, the header may include the sender/recipient address, the sender/recipient phone number, or a targeted network location of the file, respectively.
[0025] The term “malware” is directed to software that produces an undesirable behavior upon execution, where the behavior is deemed to be “undesirable” based on customer-specific rules, manufacturer-based rules, or any other type of rules formulated by public opinion or a particular governmental or commercial entity. This undesired behavior may include a communication-based anomaly or an execution-based anomaly that (1) alters the functionality of an electronic device executing that application software in a malicious manner; (2) alters the functionality of an electronic device executing that application software without any malicious intent; and/or (3) provides an unwanted functionality which is generally acceptable in other context.
[0026] The term “transmission medium” is a communication path between two or more systems (e.g. any electronic devices with data processing functionality such as, for example, a security appliance, server, mainframe, computer, netbook, tablet, smart phone, router, switch, bridge or brouter). The communication path may include wired and/or wireless segments. Examples of wired and/or wireless segments include electrical wiring, optical fiber, cable, bus trace, or a wireless channel using infrared, radio frequency (RF), or any other wired/wireless signaling mechanism.
[0027] Lastly, the terms “or” and “and/or” as used herein are to be interpreted as inclusive or meaning any one or any combination. Therefore, “A, B or C” or “A, B and/or C” mean “any of the following: A; B; C; A and B; A and C; B and C; A, B and C.” An exception to this definition will occur only when a combination of elements, functions, steps or acts are in some way inherently mutually exclusive.
[0028] As this invention is susceptible to embodiments of many different forms, it is intended that the present disclosure is to be considered as an example of the principles of the invention and not intended to limit the invention to the specific embodiments shown and described.
II. General Architecture
[0029] Referring to FIG. 1 , an exemplary block diagram of a communication network 100 deploying a plurality of malware content detection (MCD) systems 1101-110N (N>1) communicatively coupled to a management system 120 via a network 130 is shown. In general, management system 120 is adapted to manage MCD systems 1101-110N. For instance, management system 120 may be adapted to cause malware signatures generated by any of MCD systems 1101-110N to be shared with one or more of the other MCD systems 1101-110N, for example, on a subscription basis. Furthermore, management system 120 may be adapted to aggregate, correlate and consolidate analytic data provided by MCD systems 1101-110N for subsequent conveyance to an electronic device 125 with display capabilities, as represented by communication paths 115. This analytic data, when correlated and consolidated, provides a network administrator with more information for defending against and preventing a malware attack.
[0030] Each MCD system 1101-110N (N=3) is adapted to intercept and analyze network content (e.g., data traffic, email, files, etc.) in real-time so as to determine whether the network content constitutes suspicious network content. The network content is considered to be “suspicious” when a portion of the network content (e.g. payload data) is determined, with a certain level of likelihood, to include malware.
[0031] According to this embodiment of the communication network, a first MCD system 1101 may be a web-based security appliance that is configured to inspect ingress data traffic, identify whether any artifacts of the data traffic may include malware, and if so, analyze at least those artifacts. This analysis may be partially conducted in a virtual machine (VM) execution environment to detect anomalous behaviors that would be present if the data traffic was actually processed by an electronic device. The particulars of this analysis are described below.
[0032] As shown in FIG. 1 , first MCD system 1101 may be deployed as an inline security appliance (not shown) or coupled to network 130 via a network tap 1501 (e.g., a data/packet capturing device), which can be integrated into first MCD system 1101, provided as a standalone component, or integrated into different network components such as a firewall 140, a router, a switch or other type of network relay device. Network tap 1501 may include a digital network tap configured to monitor network content (data traffic) and provide a copy of the data traffic along with its metadata to first MCD system 1101 for analysis. The data traffic may comprise signaling transmitted over network 130, including data from/to a remote server 160.
[0033] As further shown in FIG. 1 , second MCD system 1102 is a communication-based security appliance that is configured to analyze and report suspicious network content, such as malware within an incoming communication message (e.g., email message, short message service “SMS” message, etc.). As shown, second MCD system 1102 may be positioned within a message transfer agent (MTA) deployed in network 130 as shown, or connected to network 130 via a network tap.
[0034] Third MCD system 1103 is a storage-based security appliance that is configured to analyze and report suspicious network content, such as potential malware within a file to be uploaded into one or more file shares 160. As with first MCD system 1101, third MCD system 1103 may be deployed as an inline security appliance (not shown) or coupled to network 130 via a network tap 1502.
[0035] It is contemplated that management system 120 may be deployed to provide cloud computing services for correlation and consolidation of the analytic data as described. Furthermore, it is contemplated that the functionality of one or more MCD systems 1101-110N may be incorporated into management system 120 when malware detection is to be conducted at a centralized resource.
[0036] Referring now to FIG. 2 , an exemplary block diagram of logic that is implemented within management system 120 is shown. Management system 110 comprises one or more processors 200 that are coupled to communication interface logic 210 via a first transmission medium 220. Communication interface 210 enables communications with MCD systems 1101-110N of FIG. 1 as well as other electronic devices over private and/or public networks, such as electronic device 125 used to view the correlated and consolidated analytic results from the malware detection analysis. According to one embodiment of the disclosure, communication interface logic 210 may be implemented as a physical interface including one or more ports for wired connectors. Additionally, or in the alternative, communication interface logic 210 may be implemented with one or more radio units for supporting wireless communications with other electronic devices.
[0037] Processor 200 is further coupled to persistent storage 230 via transmission medium 225. According to one embodiment of the disclosure, persistent storage 230 may include configuration logic 240, distribution logic 250, aggregation logic 260, correlation logic 270 and/or consolidation logic 280. Of course, when implemented as hardware, logic 240, 250, 260, 270 and/or 280 would be implemented separately from persistent memory 230.
[0038] Configuration logic 240 provides centralized control of the functionality of MCD systems 1101-110N. In particular, configuration logic 240 allows an administrator in a customer environment to alter configuration information within MCD systems 1101-110N as well as other networked electronic devices. For instance, as illustrative examples, configuration logic 240 may be used to alter the Internet Protocol (IP) address assigned to one of the security appliances (e.g., MCD system 1101), alter key information stored within any of MCD systems 1101-110N, alter user access/privileges so that different administrators have different access rights, or the like.
[0039] Distribution logic 250 allows management system 120 to influence analysis priorities at one MCD system based on suspicious network content detected at another MCD system. For instance, during analysis of the network content, a second MCD system 1102 may receive an email message for malware detection analysis, where the email message includes an artifact (e.g., URL) within its payload. As second MCD system 1102 is not configured to analyze the URL before access by the end-user, the URL is merely provided to management system 120 as an analysis attribute.
[0040] The presence of certain artifacts (e.g., URL) as an analysis attribute within the stored analytic data may prompt distribution logic 250 to transmit a priority message to first MCD system 1101 of FIG. 1 . The priority message requests malware detection analysis to be conducted on any network content associated with the URL, where the URL is selected by the end user. Of course, it is contemplated that management system 120 may be adapted to ignore or lessen the analysis priority of network content, especially where the network content is determined to be provided from a trusted source.
[0041] Aggregation logic 260 is configured to request (i.e. pull) analytic data from each of the MCD systems 1101-110N for storage within an internal data store 290, where at least a portion of the analytic data is used by correlation logic 270. In particular, according to one embodiment of the disclosure, aggregation logic 260 maintains network addresses (e.g., Internet Protocol “IP” address and/or media access control “MAC” address) for each MCD system 1101-110N. In response to a triggering event, where the event may be scheduled based on an elapsed time or may be aperiodic, aggregation logic 260 sends a message to one or more MCD systems 1101-110N requesting analytic data (hereinafter generally referred to as an “Analytic Data Query message”). Within each Analytic Data Query message, aggregation logic 260 may provide information (e.g. last stored time-stamp value and/or sequence value, etc.) to assist a targeted MCD system (e.g., MCD system 110i, where 1≤i≤N) to identify stored analytic data that has not yet been uploaded to management system 120.
[0042] In response to an Analytic Data Query message, management system 120 receives one or more Analytic Data Response messages 300 from targeted MCD system 110i as shown in FIG. 3 . Analytic Data Response message 300 comprises (1) a header 310 and (2) a payload 350. Header 310 includes at least a source address 320 identifying MCD system 110i. Payload 350 comprises information associated with suspicious network content analyzed by the targeted MCD system. The information includes at least (i) an identifier for the suspicious network content (e.g., assigned sequence number and/or time-stamp value, etc.), (ii) one or more input attributes associated with the suspicious network content, and/or (iii) one or more analysis attributes associated with the suspicious network content.
[0043] It is contemplated that multiple messages may be utilized to provide the information to management system 120, such as the analysis attributes being provided in a first message and input attributes provided in a subsequent message. Also, it is contemplated that MCD system 110i may be adapted to “push” the input attributes and/or analysis attributes in lieu of the “pull” operations as described.
[0044] Where different MCD systems are operating on common suspicious network content, these MCD systems 1101-110N of FIG. 1 will provide one or more identical analysis attributes. These analysis attributes are identical, in part, because the malware detection analysis conducted by these MCD systems is in accordance with a common mechanism as described below (static and VM-execution environment). The input attributes are different based on the MCD system analyzing the network content. Examples of analysis and input attributes realized by different types of MCD systems are set forth below in Table A.
[0045]
| TABLE A | |
|---|---|
| Examples of Attributes | |
| MCD System Type | Attributes (Input “I” and/or Analysis “A”) |
| Network-based | I: Source IP (and/or MAC) address |
| I: Destination IP (and/or MAC) address | |
| A: URL (website accessed) | |
| A: Information identifying anomalous behaviors | |
| detected within the virtual execution environment | |
| (e.g., file changes, registry changes, process | |
| changes, etc.) | |
| Communications- | I: Sender identifier (email address, phone number |
| based | for text, etc.) |
| I: Recipient identifier (email address, phone | |
| number for text, etc.) | |
| I: Subject Line information | |
| A: URL(s) present in communication message | |
| A: Attachment present in communication message | |
| A: Information identifying anomalous behaviors | |
| detected within the virtual execution environment | |
| (e.g., file changes, registry changes, process | |
| changes, etc.) | |
| Storage-based | I: Network location of the file |
| I: Source IP (and/or MAC) address of | |
| downloading source | |
| A: File Share name | |
| A: File name/File size/File type | |
| A: File checksum | |
| A: Information identifying anomalous behaviors | |
| detected within the virtual execution environment | |
| (e.g., file changes, registry changes, process | |
| changes, etc.) | |
[0046] Referring back to FIG. 2 , triggered by aggregation logic 260 receiving analytic data from one or more MCD systems, correlation logic 270 attempts to find relationships between analysis attributes provided from different MCD systems. This may be accomplished by comparing similarities between artifacts being part of the analyzed network content (e.g., URLs, PDF attachments, etc.) as well as the anomalous behavior observed during analysis of the artifacts (e.g., registry changes, process changes, file changes, etc.). Time proximity may further be considered.
[0047] As an illustrative example, an anomalous behavior (e.g. particular registry change) for a first suspicious network content is detected by the first MCD system. The data associated with the anomalous behavior, namely the registry change in this example, undergoes a hash operation to produce a first hash value that is stored as a first analysis attribute.
[0048] Similarly, the second MCD system detects an anomalous behavior during malware analysis on a second suspicious network content, which is related to the first suspicious network content. The data associated with this anomalous behavior, such as the same registry change for example, undergoes a hash operation to produce a second hash value that is stored as a second analysis attribute. As the hash operation is conducted on the identical information, the second hash value would be equivalent to the first hash value.
[0049] Continuing this illustrative example, correlation logic 270 determines a match by comparing the first analysis attribute to analysis attributes supplied by the second MCD system, including the second analysis attribute. By determining that the first hash value matches the second hash value, the management system has effectively determined that the first network content is related to the second network content.
[0050] Optionally, as a secondary determination, correlation logic 270 may confirm that the first analysis attribute occurred within a prescribed time period (e.g., a few minutes, an hour, etc.) from detection of the second analysis attribute. The temporal proximity of the occurrence of these analysis attributes may provide additional information to confirm that the network contents associated with these attributes are related or the same.
[0051] Triggered by correlation logic 270, consolidation logic 280 consolidates input attributes associated with these matched analysis attributes. Continuing the above example, consolidation logic 280 provides consolidated input attributes to GUI logic 285. Based on these consolidated input attributes, GUI logic 285 provides one or more screen displays for conveying a more detailed summary of suspicious network content being detected by different MCD systems.
[0052] Although the illustrative embodiments are directed to conducting a hash or transformation operation on one or more analysis attributes prior to comparison with other analysis attributes uncovered elsewhere, it is contemplated that information associated with the analysis attributes (or a portion of such information) may be used in lieu of a hash (or transformation) value. For instance, it is possible to use some or all of information from the analysis attribute itself in a complex comparative algorithm to determine if a match is detected.
[0053] Referring now to FIG. 4 , an exemplary block diagram of logic within a MCD system (e.g., MCD system 1101 of FIG. 1 ) is shown. Herein, MCD system 1101 comprises (1) static instrumentation engine 400; (2) dynamic run-time test and observation (RTO) engine 420, (3) priority setting logic 470; (4) an optional hash (transformation) logic 480 and/or (5) local data store 490. As shown, static instrumentation engine 400 and dynamic RTO engine 420 are deployed within the same device. However, it is contemplated that static instrumentation engine 400 and dynamic RTO engine 420 may be employed within different devices and/or executed by different processors when implemented as software.
[0054] Static instrumentation engine 400 receives ingress network content 405 and generates a representation of the content 405 that is analyzed with one or more various software analysis techniques (e.g., control information analysis, or data analysis). Static instrumentation engine 400 then modifies content 405 to include within itself special monitoring functions and/or special stimuli functions operable during processing of content 405 in dynamic run-time test and observation engine 420. The monitoring functions report their results to control logic 425 and the stimuli functions are told what stimuli to generate by control logic 425. Also, a time-stamp value may be applied to content 405 through a time-stamp generation unit 427 and provided as an identifier for content 405. During the malware detection analysis by static instrumentation engine 400, upon detection of potential malware within the network content, an alert message is generated where at least a portion of information 410 associated with the alert message is routed to data store 490. Some of information 410, namely analysis attributes and/or identification information, may undergo hashing or some sort of transformation to minimize the amount of data to be stored in data store 490.
[0055] It is contemplated that static instrumentation engine 400 may be adapted to receive information from dynamic RTO engine 420 in order to instrument the code to better analyze specific behaviors.
[0056] After processing is completed by static instrumentation engine 400, content 405 is then provided to control logic 425 within dynamic RTO engine 420. Control logic 425 operates as a scheduler to dynamically control the malware detection analysis among different applications and/or the same application software among different run-time test and observation environments (“run-time environments”).
[0057] In general, dynamic RTO engine 420 acts as an intelligent testing function. According to one approach, dynamic RTO engine 420 recursively collects information describing the current state of network content 405 and selects a subset of rules, perhaps corresponding at least in part to the behaviors set by the user, to be monitored during virtual execution of network content 405. The strategic selection and application of various rules over a number of recursions in view of each new observed operational state permits control logic 425 to resolve a specific conclusion about network content 405, namely if network content 405 constitutes suspicious network content.
[0058] As shown in FIG. 4 , dynamic RTO engine 420 comprises a virtual machine repository 430 that is configured to store one or more virtual machines 4401-440P (where P≥1). More specifically, virtual machine repository 430 may be adapted to store a single virtual machine (VM) that can be configured by scheduling functionality within control unit 425 to simulate the performance of multiple types of electronic devices. Virtual machine repository 430 also can store any number of distinct VMs each configured to simulate performance of a different electronic device and/or different operating systems (or versions) for such electronic devices.
[0059] One or more run-time environments 450 simulate operations of network content 405 to detect one or more anomalous behaviors. For instance, run-time environment 4551 can be used to identify the presence of anomalous behavior during analysis of simulated operations of network content 405 performed on a virtual machine 4401. Of course, there can be multiple run-time test environments 4551-455M (M≥2) to simulate multiple types of processing environments for network content 405.
[0060] A virtual machine may be considered a representation of a specific electronic device that is provided to a selected run-time environment by control unit 425. In one example, control unit 425 retrieves virtual machine 4401 from virtual machine repository 430 and configures virtual machine 4401 to mimic a particular type of electronic device, such as a computer operating a certain version of Windows® OS. The configured virtual machine 4401 is then provided to one of the run-time environments 4551-455M (e.g., run-time environment 4551).
[0061] As run-time environment 4551 simulates the operations of network content 405, virtual machine 4401 can be closely monitored for any behaviors set by the user or for any prioritized content identified by priority setting logic 470. By simulating the processing of network content 405 and analyzing the response of virtual machine 4401, run-time environment 4551 can detect anomalous behaviors and upload analytic data associated with these behaviors to data store 490. This analytic data may include information identifying process changes, file changes and registry changes (or hash values associated with these changes).
[0062] Besides VM 4401, run-time environment 4551 is provided with network content 405 (or an instance 460 of network content) along with an instance 465 of the type of operating system on which target content 405 will run if deemed sufficiently safe during the dynamic anomalous behavior detection process. Here, the use of virtual machines (VMs) permits the instantiation of multiple additional run-time environments 4551-455M each handling specific network content and the OS instance, where the various run-time environments 4551-455M are isolated from one another.
[0063] As previously described, the simultaneous existence of multiple run-time environments 4551-455M permits different types of observations/tests to be run on particular network content. That is, different instances of the same network content may be provided in different run-time environments so that different types of tests/observances can be concurrently performed on the same content. Alternatively, different network content can be concurrently tested/observed.
[0064] For instance, a first packet-based data stream associated with network content may be tested/observed in a first run-time environment (e.g., environment 4551) while a second packet-based data stream is tested/observed in another run-time environment (e.g., environment 455M). Notably, instances of different operating system types and even different versions of the same type of operating system may be located in different run-time environments. For example, a Windows® 8 operating system (OS) instance 465 may be located in first run-time test environment 4551 while another instance of a different version of Windows® OS or Linux® OS (not shown) may be located in a second run-time test environment 455M. Concurrent testing of one or more packet-based data streams (whether different instances of the same packet-based data stream or respective instances of different packet-based data streams or some combination thereof) enhances the overall performance of the communication network.
III. Anomalous Behavior Analysis and Generation/Aggregation of Analytic Data
[0065] Referring to FIG. 5A , an exemplary diagram of a flowchart partially illustrating populating of a data store by a MCD system for subsequent access by the management system is shown. Prior to conducting the malware detection analysis, however, ingress network content is received by the MCD system. Upon determining that this content constitutes suspicious network content, a first identifier is assigned to the suspicious network content (blocks 500, 502 and 505). Input attributes associated with the ingress network content (e.g., source and/or destination) are extracted for subsequent storage in the data store of the MCD system (block 510). Also, malware detection analysis is conducted on the artifacts associated with the ingress network content (block 515).
[0066] Upon completion of the malware detection analysis, the MCD system stores the artifacts and information associated with any detected anomalous behavior as analysis attributes within a data store. With these analysis artifacts, the MCD system further stores an identifier associated with the content along with the input attributes (blocks 520 and 525). However, if anomalous behavior is not detected, the input attributes along with the identifier associated with the content and the artifacts are collectively stored in the data store (block 530).
[0067] Referring now to FIGS. 5B and 5C , exemplary diagrams of the generation and aggregation of analytic data from a MCD system is illustrated. Herein, as shown in FIG. 5B , a plurality of MCD systems 1101-110N are communicatively coupled to management system 120 via transmission mediums 5351-535N. MCD systems 1101-1103 are adapted to intercept and analyze, in real-time, different types of network content (e.g., data traffic, email messages, uploaded files for storage, etc.) so as to determine whether the network content constitutes suspicious network content.
[0068] As shown in FIG. 5C , each MCD system 110i (i=1, 2 or 3 in FIG. 1 ) is configured to receive a first type of network content 540, including header 542 and a payload 544. Upon receipt of network content 540, MCD system 110i assigns an identifier 550 for network content 540 and extracts at least a portion of information within header 542 as the input attributes 555. Both identifier 550 and input attributes 555 are stored in an entry 580 in data store 490. Data store 490 may be situated as a local data store (as shown) or remotely located from MCD system 110i.
[0069] Upon performing malware detection analysis on payload 544, a determination is made whether any artifacts 560 (e.g. text, objects, etc.) within payload 544 are “suspicious,” namely that data may constitute malware. If one or more artifacts 560 within payload 544 is “suspicious,” MCD system 110i analyzes artifact(s) 560 in a virtual machine (VM) execution logic (as described above) to detect any anomalous behavior(s) 565. Hence, artifacts 560 along with any detected anomalous behavior(s) 565 are stored as analysis attributes 570 and 575, respectively. However, if none of the artifacts within payload 544 is determined to be “suspicious,” these artifact(s) 560 are merely stored as analysis attribute(s) 570.
[0070] Also, it is contemplated that MCD system 110i may conduct a transformation on artifacts and/or recorded anomalous behaviors associated with network content 540 (e.g., one-way hash operation in accordance with a message-digest algorithm such as “MD5”) to produce results having a lesser byte size than the artifact/behavior itself (e.g. hash value or digest). Of course, in lieu of a one-way hash operation, other transformations may be performed on payload artifacts 560 such as a checksum operation, for example. The hash values would be stored as analysis attributes 570 and 575 along with input attributes 555 and identifier 550.
[0071] Hence, content identifier 550 along with input attributes 555 and analysis attributes 570-575 are stored in data store 490, which is accessible by management system 120 on a periodic or aperiodic basis. More specifically, according to one embodiment of the disclosure, after a prescribed time has elapsed, management system 120 sends a query (e.g. Analytic Data Query message) for analytic data within local store 490 which has been recently stored since the last query. Upon receipt of the query, with perhaps successful authentication of management system 120 through a challenge/response scheme or another authentication scheme, analytic data from one or more entries within data store 490 are uploaded to management system 120.
IV. Correlation/Consolidation of Analytic Data
[0072] Referring to FIG. 6A , an exemplary embodiment of a flowchart of the operations for correlating and consolidating the analytic data from multiple MCD systems is shown. Herein, correlation logic within the management system compares analysis attributes associated with a first MCD system to analysis attributes associated with a second MCD system (block 600). If a match is detected for any of these attributes, the input attributes associated with the compared attributes are consolidated to collectively provide additional information concerning a malware attack associated with the network content (blocks 605 and 610). If a match is not detected, a determination is made whether all comparisons between the incoming analysis attributes have been conducted (block 615). If not, the correlation and consolidation operations continue (block 620). Otherwise, the correlation and consolidation process completes.
[0073] Referring now to FIG. 6B , an exemplary diagram of a flowchart partially illustrating correlation and consolidation of analytic data by the management system is shown. Herein, in response to a triggering event to commence acquisition of analytic data from a targeted MCD system (e.g., elapse of a prescribed time period, signaling of the presence of an alert message, etc.), the management system retrieves stored analytic data from the targeted MCD system (blocks 650 and 655). Thereafter, as an optional feature, the MCD system may perform a hash operation on each analysis attribute in the analytic data (block 660).
[0074] Thereafter, a recursive comparison scheme is conducted as to whether an analysis attribute associated with the targeted MCD system matches an analysis attribute associated with another MCD system (block 665). For example, the comparison may involve determining whether the hash value associated with an analysis attribute uploaded by the targeted MCD system matches a hash value associated with an analysis attribute uploaded by another MCD system.
[0075] If a match is detected, the management system consolidates the input attributes associated with the compared analysis attributes (block 670). Otherwise, a determination is made whether all of the newly received analysis attributes have been analyzed (block 675). If not, the correlation and consolidation analysis is recursive and returns to the operations set forth in operation 680. Otherwise, the analysis is completed (operation 685).
V. Illustration of Aggregation/Correlation/Consolidation of Analytic Data
[0076] Referring to FIG. 7 , a detailed illustrative example of aggregation, correlation and consolidation of analytic data to provide a more detailed elaboration of a malware attack is shown. Operating as a communication-based security appliance, a second MCD system is configured to receive a first type of network content such as an email message including a header and a payload (block 700). Upon receipt of email message, the second MCD system assigns a content identifier to the email message and extracts at least a portion of information within header as the input attributes (blocks 702 and 704). Both the content identifier and the input attributes are stored within an entry associated with a data store associated with the second MCD system (block 706).
[0077] Thereafter, a determination is made as to whether the payload of the email message includes a first artifact such as an attachment (block 708). If so, the second MCD system conducts a malware detection analysis on the first artifact (attachment) by conducting static and dynamic malware analysis as described in FIG. 4 to detect any anomalous behaviors (block 712). Prior to performing the malware detection analysis, however, the second MCD system may conduct a one-way hash operation on the attachment to produce a hash value for storage as the analysis attribute or store the artifact as an analysis attribute (block 710).
[0078] Thereafter, any anomalous behaviors uncovered during the virtual processing of the artifact (e.g., detachment and opening of the attachment) within the VM-based run-time environment. The anomalous behaviors, if any, are stored as analysis attributes within the corresponding entry (block 714).
[0079] Besides determining whether the payload of the email message includes a first type of artifact, another determination is made as to whether the payload includes a second type of artifact such as a URL (block 716). If so, the URL is not analyzed in the VM-base run-time environment. Rather, the URL (or a hash value of the URL) is added as an analysis attributes within the entry (block 718).
[0080] Operating as a web-based security appliance contemporaneously with the second MCD system, a first MCD system is configured to receive a second type of network content such as a network data traffic including a header and a payload (block 720). Upon receipt of data traffic, the first MCD system assigns a content identifier and extracts at least a portion of information within header as the input attributes (blocks 722 and 724). Both the content identifier and the input attributes are stored within an entry within a data store associated with the first MCD system (block 726).
[0081] Thereafter, a malware detection analysis is performed on the data traffic by at least analyzing artifacts of the payload by conducting static and dynamic malware analysis as described in FIG. 4 to detect any anomalous behaviors (block 730). These artifacts may include a single frame or series of video frames, audio, text, images, etc. The first MCD system also stores the one or more artifacts as analysis attributes, where such artifacts may be stored as hash values (block 728).
[0082] Thereafter, any anomalous behaviors uncovered during analysis of the artifact(s) in a VM-based run-time environment are also stored as analysis attributes within the corresponding entry (block 732).
[0083] Lastly, operating as a storage-based security appliance, the third MCD system is configured to receive a third type of network content, such as a file being part of the data payload (block 740). Upon receipt of the file, the first MCD system assigns a content identifier and extracts at least a portion of information within header as the input attributes (blocks 742 and 744). This information may include a network location for storage of the file. Both the content identifier and the input attributes are stored as an entry within a local store associated with the third MCD system (block 746).
[0084] Thereafter, a malware detection analysis is performed on the file by at least analyzing artifacts in the file by conducting static and dynamic malware analysis as described in FIG. 4 to detect any anomalous behaviors (block 750). The third MCD system also stores the one or more artifacts as analysis attributes, where such artifacts may be transformed as hash values (block 748).
[0085] Any anomalous behaviors uncovered during analysis of the file artifact(s) in a VM-based run-time environment are also stored as analysis attributes within the corresponding entry (block 752).
[0086] Periodically, the management system queries each of the MCD systems for recently stored analytic data (block 760). The entries within the data store for a corresponding MCD system that include analytic data (e.g. at least input and analysis attributes) recently stored since the last query are uploaded to the management system (block 762). According to one embodiment, the analytic data from each MCD system remains segregated within the local store of the management system.
[0087] The management system compares the analysis attributes associated with the first MCD system, the second MCD system and the third MCD system to determine if any of these analysis attributes match to denote that the network content was detected by multiple MCD systems (blocks 764 and 766).
[0088] Presuming for this illustrative example that the URL within the email message was selected, which caused a file (FILE-1) to be downloaded from a malicious server and FILE-1 was subsequently stored on the file share. For this example, the management system correlates the analytic data and determines that the URL associated with the email message matches the URL associated with the network data traffic (block 768). Hence, the input attributes associated with these analysis attributes are consolidated so that the management system may now convey that the URL associated with FILE-1 was received via an email message at time t1 from sender (SENDER-1) to multiple recipients, including RECIPIENT-1 who selected the URL (and received FILE-1 at time t2) as a download while RECIPIENTS-2 . . . 5 who have not yet activated the URL (block 770).
[0089] Furthermore, upon further correlation of analysis attributes associated with the URLs, a determination is made that FILE-1 detected by the first MCD system as being downloaded upon selecting the URL also was detected by the third MCD system as being uploaded into a file share (block 772). Hence, the input attributes associated with these analysis attributes are consolidated so that the management system may convey that the URL associated with FILE-1 was received via an email message at time t1 from SENDER-1 to RECEPIENTS-1 . . . 5, where RECIPIENT-1 activated the URL while RECIPIENTS-2 . . . 5 have not yet activated the URL, and FILE_1 was downloaded to RECIPIENT-1 at time t2 and uploaded by RECIPIENT-1 to the file share at network location 0011xx at time t3 (block 774). Such an analysis continues until no further matches are determined for the associated analysis attributes for this particular network content thread.
[0090] This information enables the network administrator to further monitor whether the migration of FILE-1 (e.g., was it downloaded by any electronic devices from file share, etc.) and enables the network administrator to not only remove the malicious file from the file share, but also send advisories to USERS 2-5 of the presence of malware and to avoid activating the URL on the particular email message.
[0091] Referring now to FIG. 8 , an exemplary embodiment of a display screen 800 that includes data produced by the correlation logic and consolidation logic to provide a consumer with a holistic view of a malware attack is shown. In particular, display screen 800 illustrates a first display portion 810 that identifies alerts from first MCD system 1101 of FIG. 1 and a second display portion 820 that identifies alerts from second MCD system 1102 of FIG. 1 .
[0092] As shown, second display portion 820 provides one or more entries that identify recipients of analyzed email messages. For instance, as shown, a first entry 825 comprises a first field 830 identifying a recipient ([email protected]) to which email messages have been sent. The recipient may correspond to any type of system such as an employee's computer, a server accessible to multiple employees, etc. First entry 825 of second display portion 820 further comprises a second field 831 identifying the total number of email messages (e.g. forty email messages) received by the recipient; a third field 832 identifying a number of attachments in the email messages (e.g., 92 attachments) as well as the number of attachments that are deemed either “malicious” or at least “suspicious” (e.g. no attachments); a fourth field 833 identifying a number of URLS detected in the email messages (e.g. 615 URLs) and the number of suspicious (or malicious) URLs (e.g., 9 suspicious URLs); a fifth field 834 identifying the last malware detected for the suspicious (or malicious) URLs; and a sixth field 835 identifying a time of last detection of the email messages.
[0093] An image 840, which is represented by a globe for this illustrative example, is produced by the correlation logic and/or the consolidation logic and displayed within display screen in one of the fields of second display portion 820 (e.g., fourth field 833). Image 840 identifies that at least some of these URLs have been selected by users of downstream electronic devices based on the correlation and consolidation of input attributes for matching analysis attributes detected by both first and second MCD systems 1102 and 1102 of FIG. 1 .
[0094] First display portion 810 provides one or more entries that identify electronic devices that have received ingress traffic with suspicious network content. For instance, as shown, a first entry 850 comprises a first field 860 identifying an IP address of a first electronic device (10.10.101.93) from which suspicious (or malicious) network content has been detected. First entry 850 in first display portion 810 further comprises a second field 861 identifying a severity rating of suspicious (or malicious) activity detected for the first electronic device. The severity rating may be based, at least in part, on a total number of suspicious (or malicious) activities detected and the type of activities (e.g. infections of malware, callbacks, blocks, etc.) set forth in fields 862-865.
[0095] As further shown in FIG. 8 , field 866 identifies the last malware detected for the suspicious (or malicious) network content (e.g., malicious code such as Trojan Generic, Exploit.Browser, etc.). Additional malware detected for network content may be displayed by selecting an element within field 866. A final field 867 identifies a time of last detection of the network content.
[0096] An image 870, which is represented by an envelope for this illustrative example, is produced by the correlation logic and/or the consolidation logic and displayed within display screen in one of the fields (e.g., field 862) of first display portion 810. Image 870 identifies that the suspicious network content resulted from an email message received by the host electronic devices, where such generation is based on the correlation and consolidation of input attributes for matching analysis attributes detected by both first and second MCD systems 1102 and 1102 of FIG. 1 .
[0097] The same general layout is provided for second entry 852 and other entries within first display portion 810. It is contemplated that the layout may be provided through other viewpoints besides alerts and e-alerts, such as by specific MCD systems where the granularity of the correlation and consolidation information may represent which MCD system detected which suspicious activity.
[0098] In the foregoing description, the invention is described with reference to specific exemplary embodiments thereof. It will, however, be evident that various modifications and changes may be made thereto without departing from the broader spirit and scope of the invention as set forth in the appended claims. For instance, in lieu of or in addition to the MCD system 1101-1103 of FIG. 1 , a malware analysis system (MAS) system may be communicatively coupled to management system 120 of FIG. 1 . The MAS system operates as a forensic workbench by receiving, based on user interaction, suspicious network content from at least one of MCD systems 1101-1103. The MAS system can be adapted with capabilities for a user to conduct a more in-depth analysis of suspicious network content, where such analysis may be uploaded to management system 120 as well.
Claims
What is claimed is:
1. An electronic device for detecting and providing a holistic view of a malware attack across a plurality of networked electronic devices, the electronic device comprising:
a processor; and
a storage device communicatively coupled to the processor, the storage device comprises
correlation logic being processed by the processor, the correlation logic to detect relationships between one or more analysis attributes including at least (i) a first analysis attribute received from a first electronic device of the plurality of networked electronic devices remotely located from the electronic device, and (ii) a second analysis attribute received from a second electronic device of the plurality of networked electronic devices remotely located from the electronic device, wherein the first analysis attribute being data representative of a first anomalous behavior detected during processing of a first network content within a first virtual machine and the second analysis attribute being data representative of a second anomalous behavior,
consolidation logic being processed by the processor, the consolidation logic to consolidate one or more input attributes associated with at least the first analysis attribute and the second analysis attribute in response to detected similarities between the first analysis attribute and the second analysis attribute, and
display logic being processed by the processor, the display logic to generate display information including the consolidated one or more input attributes.
2. The electronic device of claim 1, wherein the correlation logic to detect the relationships between the one or more analysis attributes provided from each of the plurality of networked electronic devices by at least identifying that the first network content including the first analysis attribute received from the first electronic device is the same as or related to a second network content including the second analysis attribute received from the second electronic device.
3. The electronic device of claim 1, wherein the first analysis attribute comprises at least one of (i) information directed to a portion of the first network content that is analyzed for malware within the first electronic device and (ii) at least the first anomalous behavior observed during malware detection analysis of the information.
4. The electronic device of claim 2 wherein the first network content includes an electronic mail message that is analyzed for malware by the first electronic device and the second network content includes network traffic that is analyzed for malware by the second electronic device.
5. The electronic device of claim 1, wherein the one or more input attributes associated with the first analysis attribute comprises at least one of (i) information identifying a destination of the first network content and (ii) information identifying a source of the first network content.
6. The electronic device of claim 1, wherein the correlation logic to find the relationships between at least the first analysis attribute and the second analysis attribute by at least comparing similarities between an artifact being part of the network content and a behavior observed during analysis of the artifact.
7. The electronic device of claim 6, wherein artifact including a Uniform Resource Locator (URL) or a document while the observed behavior includes a registry change or a file change.
8. The electronic device of claim 6, wherein the display logic, when executed by the processor, generates the display information that includes one or more images representing that the first analysis attribute detected by the first electronic device originated from the second network content analyzed by the second electronic device.
9. The electronic device of claim 1 being communicatively coupled to the first electronic device operating as a web-based security appliance that inspects ingress data traffic and provides at least the first attribute to the electronic device based on an analysis of the ingress data traffic.
10. The electronic device of claim 9 being communicatively coupled to the second electronic device operating as a communication-based security appliance that analyzes an incoming communication message and provides at least the second attribute to the electronic device, the incoming communication message includes an electronic mail message or a text message.
11. The electronic device of claim 9 being communicatively coupled to the second electronic device operating as a storage-based security appliance that analyzes a file and provides at least the second attribute associated with the file to the electronic device.
12. A method for providing a holistic view of a malware attack, comprising:
receiving analytic data from each of a plurality of electronic devices, the analytic data comprises one or more input attributes being information used in routing of suspicious network content over a network and one or more analysis attributes being a portion of the suspicious network content;
detecting relationships between one or more analysis attributes including at least (i) a first analysis attribute received from a first electronic device of the plurality of electronic devices and (ii) a second analysis attribute from a second electronic device of the plurality of electronic devices, wherein the first analysis attribute is data representative of a first anomalous behavior detected during processing of a first network content within a virtual machine of the first electronic device and the second analysis attribute being data representative of a second anomalous behavior detecting during processing of a second network content within a virtual machine of the second electronic device;
consolidating the one or more input attributes associated with at least the first analysis attribute and the second analysis attribute in response to a detected relationship between the first analysis attribute and the second analysis attribute; and
generating display information including the consolidated one or more input attributes.
13. The method of claim 12, wherein the display information further includes the first analysis attribute and the second analysis attribute.
14. The method of claim 12, wherein the first analysis attribute comprises at least one of (i) information directed to a portion of the first network content that is analyzed for malware within the first electronic device and (ii) one or more anomalous behaviors including the first anomalous behavior observed during malware detection analysis of the information.
15. The method of claim 14 wherein the network content includes an electronic mail message that is analyzed for malware by the first electronic device.
16. The method of claim 12, wherein the detecting of the relationship between the first analysis attribute and the second analysis attribute comprises (i) conducting a hash operation on the first analysis attribute to produce a first hash value being the data representative of the first anomalous behavior, (ii) conducting a hash operation on the second analysis attribute to produce a second hash value being the data representative of the second anomalous behavior, and (iii) determining whether the first hash value matches the second hash value.
17. A method for providing a holistic view of a malware attack, comprising:
receiving analytic data from each of a plurality of electronic devices, the analytic data comprises at least analysis attributes from a first electronic device and analysis attributes from a second electronic device;
comparing the analysis attributes from the first electronic device to the analysis attributes from the second electronic device, wherein the analysis attributes from the first electronic device is data representative of a first anomalous behavior detected during processing of a first network content within a virtual machine of the first electronic device and the second analysis attribute being data representative of a second anomalous behavior detecting during processing of a second network content within a virtual machine of the second electronic device;
responsive to a first analysis attribute of the analysis attributes from the first electronic device matching a second analysis attribute of the analysis attributes from the second electronic device, consolidating one or more input attributes associated with the first analysis attribute and the second analysis attribute; and
generating display information including the consolidated one or more input attributes.
18. The method of claim 17, wherein the first analysis attribute matches the second analysis attribute when a hash value produced from the first analysis attribute matches a hash value produced from the second analysis attribute.
19. The method of claim 17, wherein the first analysis attribute matches the second analysis attribute when content associated with the first analysis attribute is identical to content associated with the second analysis attribute.
20. The method of claim 17, wherein the first analysis attribute comprises at least one of (i) information directed to a portion of network content that is analyzed for malware within the first electronic device and (ii) one or more anomalous behaviors observed during malware detection analysis of the information.
Patent Citations (618)
| Patent | Date | Inventor | Cited By |
|---|---|---|---|
| US4292580(A) | 1981-09-01 | Ott et al. | Applicant |
| US5175732(A) | 1992-12-01 | Hendel et al. | Applicant |
| US5440723(A) | 1995-08-01 | Arnold et al. | Applicant |
| US5490249(A) | 1996-02-01 | Miller | Applicant |
| US5657473(A) | 1997-08-01 | Killean et al. | Applicant |
| US5842002(A) | 1998-11-01 | Schnurer et al. | Applicant |
| US5978917(A) | 1999-11-01 | Chi | Applicant |
| US6088803(A) | 2000-07-01 | Tso et al. | Applicant |
| US6094677(A) | 2000-07-01 | Capek et al. | Applicant |
| US6108799(A) | 2000-08-01 | Boulay et al. | Applicant |
| US6118382(A) | 2000-09-01 | Hibbs et al. | Applicant |
| US6269330(B1) | 2001-07-01 | Cidon et al. | Applicant |
| US6272641(B1) | 2001-08-01 | Ji | Applicant |
| US6279113(B1) | 2001-08-01 | Vaidya | Applicant |
| US6298445(B1) | 2001-10-01 | Shostack et al. | Applicant |
| US6357008(B1) | 2002-03-01 | Nachenberg | Applicant |
| US6417774(B1) | 2002-07-01 | Hibbs et al. | Applicant |
| US6424627(B1) | 2002-07-01 | Sørhaug et al. | Applicant |
| US6442696(B1) | 2002-08-01 | Wray et al. | Applicant |
| US6484315(B1) | 2002-11-01 | Ziese | Applicant |
| US6487666(B1) | 2002-11-01 | Shanklin et al. | Applicant |
| US6493756(B1) | 2002-12-01 | O'Brien et al. | Applicant |
| US6550012(B1) | 2003-04-01 | Villa et al. | Applicant |
| US6700497(B2) | 2004-03-01 | Hibbs et al. | Applicant |
| US6775657(B1) | 2004-08-01 | Baker | Applicant |
| US6831893(B1) | 2004-12-01 | Ben Nun et al. | Applicant |
| US6832367(B1) | 2004-12-01 | Choi et al. | Applicant |
| US6895550(B2) | 2005-05-01 | Kanchirayappa et al. | Applicant |
| US6898632(B2) | 2005-05-01 | Gordy et al. | Applicant |
| US6907396(B1) | 2005-06-01 | Muttik et al. | Applicant |
| US6941348(B2) | 2005-09-01 | Petry et al. | Applicant |
| US6971097(B1) | 2005-11-01 | Wallman | Applicant |
| US6981279(B1) | 2005-12-01 | Arnold et al. | Applicant |
| US6995665(B2) | 2006-02-01 | Appelt et al. | Applicant |
| US7007107(B1) | 2006-02-01 | Ivchenko et al. | Applicant |
| US7028179(B2) | 2006-04-01 | Anderson et al. | Applicant |
| US7043757(B2) | 2006-05-01 | Hoefelmeyer et al. | Applicant |
| US7069316(B1) | 2006-06-01 | Gryaznov | Applicant |
| US7080407(B1) | 2006-07-01 | Zhao et al. | Applicant |
| US7080408(B1) | 2006-07-01 | Pak et al. | Applicant |
| US7093002(B2) | 2006-08-01 | Wolff et al. | Applicant |
| US7093239(B1) | 2006-08-01 | van der Made | Applicant |
| US7096498(B2) | 2006-08-01 | Judge | Applicant |
| US7100201(B2) | 2006-08-01 | Izatt | Applicant |
| US7107617(B2) | 2006-09-01 | Hursey et al. | Applicant |
| US7159149(B2) | 2007-01-01 | Spiegel et al. | Applicant |
| US7213260(B2) | 2007-05-01 | Judge | Applicant |
| US7231667(B2) | 2007-06-01 | Jordan | Applicant |
| US7240364(B1) | 2007-07-01 | Branscomb et al. | Applicant |
| US7240368(B1) | 2007-07-01 | Roesch et al. | Applicant |
| US7243371(B1) | 2007-07-01 | Kasper et al. | Applicant |
| US7249175(B1) | 2007-07-01 | Donaldson | Applicant |
| US7287278(B2) | 2007-10-01 | Liang | Applicant |
| US7308716(B2) | 2007-12-01 | Danford et al. | Applicant |
| US7328453(B2) | 2008-02-01 | Merkle, Jr. et al. | Applicant |
| US7346486(B2) | 2008-03-01 | Ivancic et al. | Applicant |
| US7356736(B2) | 2008-04-01 | Natvig | Applicant |
| US7386888(B2) | 2008-06-01 | Liang et al. | Applicant |
| US7392542(B2) | 2008-06-01 | Bucher | Applicant |
| US7418729(B2) | 2008-08-01 | Szor | Applicant |
| US7428300(B1) | 2008-09-01 | Drew et al. | Applicant |
| US7441272(B2) | 2008-10-01 | Durham et al. | Applicant |
| US7448084(B1) | 2008-11-01 | Apap et al. | Applicant |
| US7458098(B2) | 2008-11-01 | Judge et al. | Applicant |
| US7464404(B2) | 2008-12-01 | Carpenter et al. | Applicant |
| US7464407(B2) | 2008-12-01 | Nakae et al. | Applicant |
| US7467408(B1) | 2008-12-01 | O'Toole, Jr. | Applicant |
| US7478428(B1) | 2009-01-01 | Thomlinson | Applicant |
| US7480773(B1) | 2009-01-01 | Reed | Applicant |
| US7487543(B2) | 2009-02-01 | Arnold et al. | Applicant |
| US7496960(B1) | 2009-02-01 | Chen et al. | Applicant |
| US7496961(B2) | 2009-02-01 | Zimmer et al. | Applicant |
| US7519990(B1) | 2009-04-01 | Xie | Applicant |
| US7523493(B2) | 2009-04-01 | Liang et al. | Applicant |
| US7530104(B1) | 2009-05-01 | Thrower et al. | Applicant |
| US7540025(B2) | 2009-05-01 | Tzadikario | Applicant |
| US7565550(B2) | 2009-07-01 | Liang et al. | Applicant |
| US7568233(B1) | 2009-07-01 | Szor et al. | Applicant |
| US7584455(B2) | 2009-09-01 | Ball | Applicant |
| US7603715(B2) | 2009-10-01 | Costa et al. | Applicant |
| US7607171(B1) | 2009-10-01 | Marsden et al. | Applicant |
| US7639714(B2) | 2009-12-01 | Stolfo et al. | Applicant |
| US7644441(B2) | 2010-01-01 | Schmid et al. | Applicant |
| US7657419(B2) | 2010-02-01 | van der Made | Applicant |
| US7676841(B2) | 2010-03-01 | Sobchuk et al. | Applicant |
| US7698548(B2) | 2010-04-01 | Shelest et al. | Applicant |
| US7707633(B2) | 2010-04-01 | Danford et al. | Applicant |
| US7712136(B2) | 2010-05-01 | Sprosts et al. | Applicant |
| US7730011(B1) | 2010-06-01 | Deninger et al. | Applicant |
| US7739740(B1) | 2010-06-01 | Nachenberg et al. | Applicant |
| US7779463(B2) | 2010-08-01 | Stolfo et al. | Applicant |
| US7784097(B1) | 2010-08-01 | Stolfo et al. | Applicant |
| US7832008(B1) | 2010-11-01 | Kraemer | Applicant |
| US7836502(B1) | 2010-11-01 | Zhao et al. | Applicant |
| US7849506(B1) | 2010-12-01 | Dansey et al. | Applicant |
| US7854007(B2) | 2010-12-01 | Sprosts et al. | Applicant |
| US7869073(B2) | 2011-01-01 | Oshima | Applicant |
| US7877803(B2) | 2011-01-01 | Enstone et al. | Applicant |
| US7904959(B2) | 2011-03-01 | Sidiroglou et al. | Applicant |
| US7908660(B2) | 2011-03-01 | Bahl | Applicant |
| US7930738(B1) | 2011-04-01 | Petersen | Applicant |
| US7937387(B2) | 2011-05-01 | Frazier et al. | Applicant |
| US7937761(B1) | 2011-05-01 | Bennett | Applicant |
| US7949849(B2) | 2011-05-01 | Lowe et al. | Applicant |
| US7996556(B2) | 2011-08-01 | Raghavan et al. | Applicant |
| US7996836(B1) | 2011-08-01 | McCorkendale et al. | Applicant |
| US7996904(B1) | 2011-08-01 | Chiueh et al. | Applicant |
| US7996905(B2) | 2011-08-01 | Arnold et al. | Applicant |
| US8006305(B2) | 2011-08-01 | Aziz | Applicant |
| US8010667(B2) | 2011-08-01 | Zhang et al. | Applicant |
| US8020206(B2) | 2011-09-01 | Hubbard et al. | Applicant |
| US8028338(B1) | 2011-09-01 | Schneider et al. | Applicant |
| US8042184(B1) | 2011-10-01 | Batenin | Applicant |
| US8045094(B2) | 2011-10-01 | Teragawa | Applicant |
| US8045458(B2) | 2011-10-01 | Alperovitch et al. | Applicant |
| US8069484(B2) | 2011-11-01 | McMillan et al. | Applicant |
| US8087086(B1) | 2011-12-01 | Lai et al. | Applicant |
| US8171553(B2) | 2012-05-01 | Aziz et al. | Applicant |
| US8176049(B2) | 2012-05-01 | Deninger et al. | Applicant |
| US8176480(B1) | 2012-05-01 | Spertus | Applicant |
| US8201246(B1) | 2012-06-01 | Wu et al. | Applicant |
| US8204984(B1) | 2012-06-01 | Aziz et al. | Applicant |
| US8214905(B1) | 2012-07-01 | Doukhvalov et al. | Applicant |
| US8220055(B1) | 2012-07-01 | Kennedy | Applicant |
| US8225288(B2) | 2012-07-01 | Miller et al. | Applicant |
| US8225373(B2) | 2012-07-01 | Kraemer | Applicant |
| US8233882(B2) | 2012-07-01 | Rogel | Applicant |
| US8234640(B1) | 2012-07-01 | Fitzgerald et al. | Applicant |
| US8234709(B2) | 2012-07-01 | Viljoen et al. | Applicant |
| US8239944(B1) | 2012-08-01 | Nachenberg et al. | Applicant |
| US8260914(B1) | 2012-09-01 | Ranjan | Applicant |
| US8266091(B1) | 2012-09-01 | Gubin et al. | Applicant |
| US8286251(B2) | 2012-10-01 | Eker et al. | Applicant |
| US8291499(B2) | 2012-10-01 | Aziz et al. | Applicant |
| US8307435(B1) | 2012-11-01 | Mann et al. | Applicant |
| US8307443(B2) | 2012-11-01 | Wang et al. | Applicant |
| US8312545(B2) | 2012-11-01 | Tuvell et al. | Applicant |
| US8321936(B1) | 2012-11-01 | Green et al. | Applicant |
| US8321941(B2) | 2012-11-01 | Tuvell et al. | Applicant |
| US8332571(B1) | 2012-12-01 | Edwards, Sr. | Applicant |
| US8365286(B2) | 2013-01-01 | Poston | Applicant |
| US8365297(B1) | 2013-01-01 | Parshin et al. | Applicant |
| US8370938(B1) | 2013-02-01 | Daswani et al. | Applicant |
| US8370939(B2) | 2013-02-01 | Zaitsev et al. | Applicant |
| US8375444(B2) | 2013-02-01 | Aziz et al. | Applicant |
| US8381299(B2) | 2013-02-01 | Stolfo et al. | Applicant |
| US8402529(B1) | 2013-03-01 | Green et al. | Applicant |
| US8464340(B2) | 2013-06-01 | Ahn et al. | Applicant |
| US8479174(B2) | 2013-07-01 | Chiriac | Applicant |
| US8479276(B1) | 2013-07-01 | Vaystikh et al. | Applicant |
| US8479291(B1) | 2013-07-01 | Bodke | Applicant |
| US8510827(B1) | 2013-08-01 | Leake et al. | Applicant |
| US8510828(B1) | 2013-08-01 | Guo et al. | Applicant |
| US8510842(B2) | 2013-08-01 | Amit et al. | Applicant |
| US8516478(B1) | 2013-08-01 | Edwards et al. | Applicant |
| US8516590(B1) | 2013-08-01 | Ranadive et al. | Applicant |
| US8516593(B2) | 2013-08-01 | Aziz | Applicant |
| US8522348(B2) | 2013-08-01 | Chen et al. | Applicant |
| US8528086(B1) | 2013-09-01 | Aziz | Applicant |
| US8533824(B2) | 2013-09-01 | Hutton et al. | Applicant |
| US8539582(B1) | 2013-09-01 | Aziz et al. | Applicant |
| US8549638(B2) | 2013-10-01 | Aziz | Applicant |
| US8555391(B1) | 2013-10-01 | Demir et al. | Applicant |
| US8561177(B1) | 2013-10-01 | Aziz et al. | Applicant |
| US8566476(B2) | 2013-10-01 | Shifter et al. | Applicant |
| US8566946(B1) | 2013-10-01 | Aziz et al. | Applicant |
| US8584094(B2) | 2013-11-01 | Dadhia et al. | Applicant |
| US8584234(B1) | 2013-11-01 | Sobel et al. | Applicant |
| US8584239(B2) | 2013-11-01 | Aziz et al. | Applicant |
| US8595834(B2) | 2013-11-01 | Xie et al. | Applicant |
| US8627476(B1) | 2014-01-01 | Satish et al. | Applicant |
| US8635696(B1) | 2014-01-01 | Aziz | Applicant |
| US8682054(B2) | 2014-03-01 | Xue et al. | Applicant |
| US8682812(B1) | 2014-03-01 | Ranjan | Applicant |
| US8689333(B2) | 2014-04-01 | Aziz | Applicant |
| US8695096(B1) | 2014-04-01 | Zhang | Applicant |
| US8713631(B1) | 2014-04-01 | Pavlyushchik | Applicant |
| US8713681(B2) | 2014-04-01 | Silberman et al. | Applicant |
| US8726392(B1) | 2014-05-01 | McCorkendale et al. | Applicant |
| US8739280(B2) | 2014-05-01 | Chess et al. | Applicant |
| US8776229(B1) | 2014-07-01 | Aziz | Applicant |
| US8782792(B1) | 2014-07-01 | Bodke | Applicant |
| US8789172(B2) | 2014-07-01 | Stolfo et al. | Applicant |
| US8789178(B2) | 2014-07-01 | Kejriwal et al. | Applicant |
| US8793278(B2) | 2014-07-01 | Frazier et al. | Applicant |
| US8793787(B2) | 2014-07-01 | Ismael et al. | Applicant |
| US8805947(B1) | 2014-08-01 | Kuzkin et al. | Applicant |
| US8806647(B1) | 2014-08-01 | Daswani et al. | Applicant |
| US8832829(B2) | 2014-09-01 | Manni et al. | Applicant |
| US8850570(B1) | 2014-09-01 | Ramzan | Applicant |
| US8850571(B2) | 2014-09-01 | Staniford et al. | Applicant |
| US8881234(B2) | 2014-11-01 | Narasimhan et al. | Applicant |
| US8881271(B2) | 2014-11-01 | Butler, II | Applicant |
| US8881282(B1) | 2014-11-01 | Aziz et al. | Applicant |
| US8898788(B1) | 2014-11-01 | Aziz et al. | Applicant |
| US8935779(B2) | 2015-01-01 | Manni et al. | Applicant |
| US8949257(B2) | 2015-02-01 | Shifter et al. | Applicant |
| US8984638(B1) | 2015-03-01 | Aziz et al. | Applicant |
| US8990939(B2) | 2015-03-01 | Staniford et al. | Applicant |
| US8990944(B1) | 2015-03-01 | Singh et al. | Applicant |
| US8997219(B2) | 2015-03-01 | Staniford et al. | Applicant |
| US9009822(B1) | 2015-04-01 | Ismael et al. | Applicant |
| US9009823(B1) | 2015-04-01 | Ismael et al. | Applicant |
| US9027135(B1) | 2015-05-01 | Aziz | Applicant |
| US9071638(B1) | 2015-06-01 | Aziz et al. | Applicant |
| US9104867(B1) | 2015-08-01 | Thioux et al. | Applicant |
| US9106630(B2) | 2015-08-01 | Frazier et al. | Applicant |
| US9106694(B2) | 2015-08-01 | Aziz et al. | Applicant |
| US9118715(B2) | 2015-08-01 | Staniford et al. | Applicant |
| US9159035(B1) | 2015-10-01 | Ismael et al. | Applicant |
| US9171160(B2) | 2015-10-01 | Vincent et al. | Applicant |
| US9176843(B1) | 2015-11-01 | Ismael et al. | Applicant |
| US9189627(B1) | 2015-11-01 | Islam | Applicant |
| US9195829(B1) | 2015-11-01 | Goradia et al. | Applicant |
| US9197664(B1) | 2015-11-01 | Aziz et al. | Applicant |
| US9223972(B1) | 2015-12-01 | Vincent et al. | Applicant |
| US9225740(B1) | 2015-12-01 | Ismael et al. | Applicant |
| US9241010(B1) | 2016-01-01 | Bennett et al. | Applicant |
| US9251343(B1) | 2016-02-01 | Vincent et al. | Applicant |
| US9262635(B2) | 2016-02-01 | Paithane et al. | Applicant |
| US9268936(B2) | 2016-02-01 | Butler | Applicant |
| US9275229(B2) | 2016-03-01 | LeMasters | Applicant |
| US9282109(B1) | 2016-03-01 | Aziz et al. | Applicant |
| US9294501(B2) | 2016-03-01 | Mesdaq et al. | Applicant |
| US9300686(B2) | 2016-03-01 | Pidathala et al. | Applicant |
| US9306960(B1) | 2016-04-01 | Aziz | Applicant |
| US9306974(B1) | 2016-04-01 | Aziz et al. | Applicant |
| US9311479(B1) | 2016-04-01 | Manni et al. | Applicant |
| US9355247(B1) | 2016-05-01 | Thioux et al. | Applicant |
| US9356944(B1) | 2016-05-01 | Aziz | Applicant |
| US9363280(B1) | 2016-06-01 | Rivlin et al. | Applicant |
| US9367681(B1) | 2016-06-01 | Ismael et al. | Applicant |
| US9398028(B1) | 2016-07-01 | Karandikar et al. | Applicant |
| US9413781(B2) | 2016-08-01 | Cunningham et al. | Applicant |
| US9430646(B1) | 2016-08-01 | Mushtaq et al. | Applicant |
| US9432389(B1) | 2016-08-01 | Khalid et al. | Applicant |
| US9438613(B1) | 2016-09-01 | Paithane et al. | Applicant |
| US9438622(B1) | 2016-09-01 | Staniford et al. | Applicant |
| US9438623(B1) | 2016-09-01 | Thioux et al. | Applicant |
| US9459901(B2) | 2016-10-01 | Jung et al. | Applicant |
| US9483644(B1) | 2016-11-01 | Paithane et al. | Applicant |
| US9495180(B2) | 2016-11-01 | Ismael | Applicant |
| US9497213(B2) | 2016-11-01 | Thompson et al. | Applicant |
| US9516057(B2) | 2016-12-01 | Aziz | Applicant |
| US9519782(B2) | 2016-12-01 | Aziz et al. | Applicant |
| US9536091(B2) | 2017-01-01 | Paithane et al. | Applicant |
| US9560059(B1) | 2017-01-01 | Islam | Applicant |
| US9565202(B1) | 2017-02-01 | Kindlund et al. | Applicant |
| US9591015(B1) | 2017-03-01 | Amin et al. | Applicant |
| US9591020(B1) | 2017-03-01 | Aziz | Applicant |
| US9594904(B1) | 2017-03-01 | Jain et al. | Applicant |
| US9594905(B1) | 2017-03-01 | Ismael et al. | Applicant |
| US9594912(B1) | 2017-03-01 | Thioux et al. | Applicant |
| US9609007(B1) | 2017-03-01 | Rivlin et al. | Applicant |
| US9626509(B1) | 2017-04-01 | Khalid et al. | Applicant |
| US9628498(B1) | 2017-04-01 | Aziz et al. | Applicant |
| US9628507(B2) | 2017-04-01 | Haq et al. | Applicant |
| US9633134(B2) | 2017-04-01 | Ross | Applicant |
| US9635039(B1) | 2017-04-01 | Islam et al. | Applicant |
| US9641546(B1) | 2017-05-01 | Manni et al. | Applicant |
| US2001/0005889(A1) | 2001-06-01 | Albrecht | Applicant |
| US2001/0047326(A1) | 2001-11-01 | Broadbent et al. | Applicant |
| US2002/0018903(A1) | 2002-02-01 | Kokubo et al. | Applicant |
| US2002/0038430(A1) | 2002-03-01 | Edwards et al. | Applicant |
| US2002/0091819(A1) | 2002-07-01 | Melchione et al. | Applicant |
| US2002/0095607(A1) | 2002-07-01 | Lin-Hendel | Applicant |
| US2002/0116627(A1) | 2002-08-01 | Tarbotton et al. | Applicant |
| US2002/0144156(A1) | 2002-10-01 | Copeland | Applicant |
| US2002/0162015(A1) | 2002-10-01 | Tang | Applicant |
| US2002/0166063(A1) | 2002-11-01 | Lachman et al. | Applicant |
| US2002/0169952(A1) | 2002-11-01 | DiSanto et al. | Applicant |
| US2002/0184528(A1) | 2002-12-01 | Shevenell et al. | Applicant |
| US2002/0188887(A1) | 2002-12-01 | Largman et al. | Applicant |
| US2002/0194490(A1) | 2002-12-01 | Halperin et al. | Applicant |
| US2003/0074578(A1) | 2003-04-01 | Ford et al. | Applicant |
| US2003/0084318(A1) | 2003-05-01 | Schertz | Applicant |
| US2003/0101381(A1) | 2003-05-01 | Mateev et al. | Applicant |
| US2003/0115483(A1) | 2003-06-01 | Liang | Applicant |
| US2003/0188190(A1) | 2003-10-01 | Aaron et al. | Applicant |
| US2003/0191957(A1) | 2003-10-01 | Hypponen et al. | Applicant |
| US2003/0200460(A1) | 2003-10-01 | Morota et al. | Applicant |
| US2003/0212902(A1) | 2003-11-01 | van der Made | Applicant |
| US2003/0229801(A1) | 2003-12-01 | Kouznetsov et al. | Applicant |
| US2003/0237000(A1) | 2003-12-01 | Denton et al. | Applicant |
| US2004/0003323(A1) | 2004-01-01 | Bennett et al. | Applicant |
| US2004/0015712(A1) | 2004-01-01 | Szor | Applicant |
| US2004/0019832(A1) | 2004-01-01 | Arnold et al. | Applicant |
| US2004/0047356(A1) | 2004-03-01 | Bauer | Applicant |
| US2004/0083408(A1) | 2004-04-01 | Spiegel et al. | Applicant |
| US2004/0088581(A1) | 2004-05-01 | Brawn et al. | Applicant |
| US2004/0093513(A1) | 2004-05-01 | Cantrell et al. | Applicant |
| US2004/0111531(A1) | 2004-06-01 | Staniford et al. | Applicant |
| US2004/0117478(A1) | 2004-06-01 | Triulzi et al. | Applicant |
| US2004/0117624(A1) | 2004-06-01 | Brandt et al. | Applicant |
| US2004/0128355(A1) | 2004-07-01 | Chao et al. | Applicant |
| US2004/0165588(A1) | 2004-08-01 | Pandya | Applicant |
| US2004/0236963(A1) | 2004-11-01 | Danford et al. | Applicant |
| US2004/0243349(A1) | 2004-12-01 | Greifeneder et al. | Applicant |
| US2004/0249911(A1) | 2004-12-01 | Alkhatib et al. | Applicant |
| US2004/0255161(A1) | 2004-12-01 | Cavanaugh | Applicant |
| US2004/0268147(A1) | 2004-12-01 | Wiederin et al. | Applicant |
| US2005/0005159(A1) | 2005-01-01 | Oliphant | Applicant |
| US2005/0021740(A1) | 2005-01-01 | Bar et al. | Applicant |
| US2005/0033960(A1) | 2005-02-01 | Vialen et al. | Applicant |
| US2005/0033989(A1) | 2005-02-01 | Poletto et al. | Applicant |
| US2005/0050148(A1) | 2005-03-01 | Mohammadioun et al. | Applicant |
| US2005/0086523(A1) | 2005-04-01 | Zimmer et al. | Applicant |
| US2005/0091513(A1) | 2005-04-01 | Mitomo et al. | Applicant |
| US2005/0091533(A1) | 2005-04-01 | Omote et al. | Applicant |
| US2005/0091652(A1) | 2005-04-01 | Ross et al. | Applicant |
| US2005/0108562(A1) | 2005-05-01 | Khazan et al. | Applicant |
| US2005/0114663(A1) | 2005-05-01 | Cornell et al. | Applicant |
| US2005/0125195(A1) | 2005-06-01 | Brendel | Applicant |
| US2005/0149726(A1) | 2005-07-01 | Joshi et al. | Applicant |
| US2005/0157662(A1) | 2005-07-01 | Bingham et al. | Applicant |
| US2005/0183143(A1) | 2005-08-01 | Anderholm et al. | Applicant |
| US2005/0201297(A1) | 2005-09-01 | Peikari | Applicant |
| US2005/0210533(A1) | 2005-09-01 | Copeland et al. | Applicant |
| US2005/0238005(A1) | 2005-10-01 | Chen et al. | Applicant |
| US2005/0240781(A1) | 2005-10-01 | Gassoway | Applicant |
| US2005/0262562(A1) | 2005-11-01 | Gassoway | Applicant |
| US2005/0265331(A1) | 2005-12-01 | Stolfo | Applicant |
| US2005/0283839(A1) | 2005-12-01 | Cowburn | Applicant |
| US2006/0010495(A1) | 2006-01-01 | Cohen et al. | Applicant |
| US2006/0015416(A1) | 2006-01-01 | Hoffman et al. | Applicant |
| US2006/0015715(A1) | 2006-01-01 | Anderson | Applicant |
| US2006/0015747(A1) | 2006-01-01 | Van de Ven | Applicant |
| US2006/0021029(A1) | 2006-01-01 | Brickell et al. | Applicant |
| US2006/0021054(A1) | 2006-01-01 | Costa et al. | Applicant |
| US2006/0031476(A1) | 2006-02-01 | Mathes et al. | Applicant |
| US2006/0047665(A1) | 2006-03-01 | Neil | Applicant |
| US2006/0070130(A1) | 2006-03-01 | Costea et al. | Applicant |
| US2006/0075496(A1) | 2006-04-01 | Carpenter et al. | Applicant |
| US2006/0095968(A1) | 2006-05-01 | Portolani et al. | Applicant |
| US2006/0101516(A1) | 2006-05-01 | Sudaharan et al. | Applicant |
| US2006/0101517(A1) | 2006-05-01 | Banzhof et al. | Applicant |
| US2006/0117385(A1) | 2006-06-01 | Mester et al. | Applicant |
| US2006/0123477(A1) | 2006-06-01 | Raghavan et al. | Applicant |
| US2006/0143709(A1) | 2006-06-01 | Brooks et al. | Applicant |
| US2006/0150249(A1) | 2006-07-01 | Gassen et al. | Applicant |
| US2006/0161983(A1) | 2006-07-01 | Cothrell et al. | Applicant |
| US2006/0161987(A1) | 2006-07-01 | Levy-Yurista | Applicant |
| US2006/0161989(A1) | 2006-07-01 | Reshef et al. | Applicant |
| US2006/0164199(A1) | 2006-07-01 | Glide et al. | Applicant |
| US2006/0173992(A1) | 2006-08-01 | Weber et al. | Applicant |
| US2006/0179147(A1) | 2006-08-01 | Tran et al. | Applicant |
| US2006/0184632(A1) | 2006-08-01 | Marino et al. | Applicant |
| US2006/0191010(A1) | 2006-08-01 | Benjamin | Applicant |
| US2006/0221956(A1) | 2006-10-01 | Narayan et al. | Applicant |
| US2006/0236393(A1) | 2006-10-01 | Kramer et al. | Applicant |
| US2006/0242709(A1) | 2006-10-01 | Seinfeld et al. | Applicant |
| US2006/0248519(A1) | 2006-11-01 | Jaeger et al. | Applicant |
| US2006/0248582(A1) | 2006-11-01 | Panjwani et al. | Applicant |
| US2006/0251104(A1) | 2006-11-01 | Koga | Applicant |
| US2006/0288417(A1) | 2006-12-01 | Bookbinder et al. | Applicant |
| US2007/0006288(A1) | 2007-01-01 | Mayfield et al. | Applicant |
| US2007/0006313(A1) | 2007-01-01 | Porras et al. | Applicant |
| US2007/0011174(A1) | 2007-01-01 | Takaragi et al. | Applicant |
| US2007/0016951(A1) | 2007-01-01 | Piccard et al. | Applicant |
| US2007/0033645(A1) | 2007-02-01 | Jones | Applicant |
| US2007/0038943(A1) | 2007-02-01 | Fitzgerald et al. | Applicant |
| US2007/0064689(A1) | 2007-03-01 | Shin et al. | Applicant |
| US2007/0074169(A1) | 2007-03-01 | Chess et al. | Applicant |
| US2007/0089165(A1) | 2007-04-01 | Wei et al. | Applicant |
| US2007/0094730(A1) | 2007-04-01 | Bhikkaji et al. | Applicant |
| US2007/0101435(A1) | 2007-05-01 | Konanka et al. | Applicant |
| US2007/0128855(A1) | 2007-06-01 | Cho et al. | Applicant |
| US2007/0142030(A1) | 2007-06-01 | Sinha et al. | Applicant |
| US2007/0143827(A1) | 2007-06-01 | Nicodemus et al. | Applicant |
| US2007/0156895(A1) | 2007-07-01 | Vuong | Applicant |
| US2007/0157180(A1) | 2007-07-01 | Tillmann et al. | Applicant |
| US2007/0157306(A1) | 2007-07-01 | Elrod et al. | Applicant |
| US2007/0168988(A1) | 2007-07-01 | Eisner et al. | Applicant |
| US2007/0171824(A1) | 2007-07-01 | Ruello et al. | Applicant |
| US2007/0174915(A1) | 2007-07-01 | Gribble et al. | Applicant |
| US2007/0192500(A1) | 2007-08-01 | Lum | Applicant |
| US2007/0192858(A1) | 2007-08-01 | Lum | Applicant |
| US2007/0198275(A1) | 2007-08-01 | Malden et al. | Applicant |
| US2007/0208822(A1) | 2007-09-01 | Wang et al. | Applicant |
| US2007/0220607(A1) | 2007-09-01 | Sprosts et al. | Applicant |
| US2007/0240218(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0240219(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0240220(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0240222(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0250930(A1) | 2007-10-01 | Aziz et al. | Applicant |
| US2007/0256132(A2) | 2007-11-01 | Oliphant | Applicant |
| US2007/0271446(A1) | 2007-11-01 | Nakamura | Applicant |
| US2008/0005782(A1) | 2008-01-01 | Aziz | Applicant |
| US2008/0028463(A1) | 2008-01-01 | Dagon et al. | Applicant |
| US2008/0032556(A1) | 2008-02-01 | Schreier | Applicant |
| US2008/0040710(A1) | 2008-02-01 | Chiriac | Applicant |
| US2008/0046781(A1) | 2008-02-01 | Childs et al. | Applicant |
| US2008/0066179(A1) | 2008-03-01 | Liu | Applicant |
| US2008/0072326(A1) | 2008-03-01 | Danford et al. | Applicant |
| US2008/0077793(A1) | 2008-03-01 | Tan et al. | Applicant |
| US2008/0080518(A1) | 2008-04-01 | Hoeflin et al. | Applicant |
| US2008/0086720(A1) | 2008-04-01 | Lekel | Applicant |
| US2008/0098476(A1) | 2008-04-01 | Syversen | Applicant |
| US2008/0120722(A1) | 2008-05-01 | Sima et al. | Applicant |
| US2008/0134178(A1) | 2008-06-01 | Fitzgerald et al. | Applicant |
| US2008/0134334(A1) | 2008-06-01 | Kim et al. | Applicant |
| US2008/0141376(A1) | 2008-06-01 | Clausen et al. | Applicant |
| US2008/0181227(A1) | 2008-07-01 | Todd | Applicant |
| US2008/0184367(A1) | 2008-07-01 | McMillan et al. | Applicant |
| US2008/0184373(A1) | 2008-07-01 | Traut et al. | Applicant |
| US2008/0189787(A1) | 2008-08-01 | Arnold et al. | Applicant |
| US2008/0201778(A1) | 2008-08-01 | Guo et al. | Applicant |
| US2008/0209557(A1) | 2008-08-01 | Herley et al. | Applicant |
| US2008/0215742(A1) | 2008-09-01 | Goldszmidt et al. | Applicant |
| US2008/0222729(A1) | 2008-09-01 | Chen et al. | Applicant |
| US2008/0263665(A1) | 2008-10-01 | Ma et al. | Applicant |
| US2008/0295172(A1) | 2008-11-01 | Bohacek | Applicant |
| US2008/0301810(A1) | 2008-12-01 | Lehane et al. | Applicant |
| US2008/0307524(A1) | 2008-12-01 | Singh et al. | Applicant |
| US2008/0313738(A1) | 2008-12-01 | Enderby | Applicant |
| US2008/0320594(A1) | 2008-12-01 | Jiang | Applicant |
| US2009/0003317(A1) | 2009-01-01 | Kasralikar et al. | Applicant |
| US2009/0007100(A1) | 2009-01-01 | Field et al. | Applicant |
| US2009/0013408(A1) | 2009-01-01 | Schipka | Applicant |
| US2009/0031423(A1) | 2009-01-01 | Liu et al. | Applicant |
| US2009/0036111(A1) | 2009-02-01 | Danford et al. | Applicant |
| US2009/0037835(A1) | 2009-02-01 | Goldman | Applicant |
| US2009/0044024(A1) | 2009-02-01 | Oberheide et al. | Applicant |
| US2009/0044274(A1) | 2009-02-01 | Budko et al. | Applicant |
| US2009/0064332(A1) | 2009-03-01 | Porras et al. | Applicant |
| US2009/0077666(A1) | 2009-03-01 | Chen et al. | Applicant |
| US2009/0083369(A1) | 2009-03-01 | Marmor | Applicant |
| US2009/0083855(A1) | 2009-03-01 | Apap et al. | Applicant |
| US2009/0089879(A1) | 2009-04-01 | Wang et al. | Applicant |
| US2009/0094697(A1) | 2009-04-01 | Provos et al. | Applicant |
| US2009/0113425(A1) | 2009-04-01 | Ports et al. | Applicant |
| US2009/0125976(A1) | 2009-05-01 | Wassermann et al. | Applicant |
| US2009/0126015(A1) | 2009-05-01 | Monastyrsky et al. | Applicant |
| US2009/0126016(A1) | 2009-05-01 | Sobko et al. | Applicant |
| US2009/0133125(A1) | 2009-05-01 | Choi et al. | Applicant |
| US2009/0144823(A1) | 2009-06-01 | Lamastra et al. | Applicant |
| US2009/0158430(A1) | 2009-06-01 | Borders | Applicant |
| US2009/0172815(A1) | 2009-07-01 | Gu et al. | Applicant |
| US2009/0187992(A1) | 2009-07-01 | Poston | Applicant |
| US2009/0193293(A1) | 2009-07-01 | Stolfo et al. | Applicant |
| US2009/0198651(A1) | 2009-08-01 | Shifter et al. | Applicant |
| US2009/0198670(A1) | 2009-08-01 | Shifter et al. | Applicant |
| US2009/0198689(A1) | 2009-08-01 | Frazier et al. | Applicant |
| US2009/0199274(A1) | 2009-08-01 | Frazier et al. | Applicant |
| US2009/0199296(A1) | 2009-08-01 | Xie et al. | Applicant |
| US2009/0228233(A1) | 2009-09-01 | Anderson et al. | Applicant |
| US2009/0241187(A1) | 2009-09-01 | Troyansky | Applicant |
| US2009/0241190(A1) | 2009-09-01 | Todd et al. | Applicant |
| US2009/0265692(A1) | 2009-10-01 | Godefroid et al. | Applicant |
| US2009/0271867(A1) | 2009-10-01 | Zhang | Applicant |
| US2009/0300415(A1) | 2009-12-01 | Zhang et al. | Applicant |
| US2009/0300761(A1) | 2009-12-01 | Park et al. | Applicant |
| US2009/0328185(A1) | 2009-12-01 | Berg et al. | Applicant |
| US2009/0328221(A1) | 2009-12-01 | Blumfield et al. | Applicant |
| US2010/0005146(A1) | 2010-01-01 | Drako et al. | Applicant |
| US2010/0011205(A1) | 2010-01-01 | McKenna | Applicant |
| US2010/0017546(A1) | 2010-01-01 | Poo et al. | Applicant |
| US2010/0030996(A1) | 2010-02-01 | Butler, II | Applicant |
| US2010/0031353(A1) | 2010-02-01 | Thomas et al. | Applicant |
| US2010/0037314(A1) | 2010-02-01 | Perdisci et al. | Applicant |
| US2010/0043073(A1) | 2010-02-01 | Kuwamura | Applicant |
| US2010/0054278(A1) | 2010-03-01 | Stolfo et al. | Applicant |
| US2010/0058474(A1) | 2010-03-01 | Hicks | Applicant |
| US2010/0064044(A1) | 2010-03-01 | Nonoyama | Applicant |
| US2010/0077481(A1) | 2010-03-01 | Polyakov et al. | Applicant |
| US2010/0083376(A1) | 2010-04-01 | Pereira et al. | Applicant |
| US2010/0115621(A1) | 2010-05-01 | Staniford et al. | Applicant |
| US2010/0132038(A1) | 2010-05-01 | Zaitsev | Applicant |
| US2010/0154056(A1) | 2010-06-01 | Smith et al. | Applicant |
| US2010/0180344(A1) | 2010-07-01 | Malyshev et al. | Applicant |
| US2010/0192223(A1) | 2010-07-01 | Ismael et al. | Applicant |
| US2010/0220863(A1) | 2010-09-01 | Dupaquis et al. | Applicant |
| US2010/0235831(A1) | 2010-09-01 | Dittmer | Applicant |
| US2010/0251104(A1) | 2010-09-01 | Massand | Applicant |
| US2010/0281102(A1) | 2010-11-01 | Chinta et al. | Applicant |
| US2010/0281541(A1) | 2010-11-01 | Stolfo et al. | Applicant |
| US2010/0281542(A1) | 2010-11-01 | Stolfo et al. | Applicant |
| US2010/0287260(A1) | 2010-11-01 | Peterson et al. | Applicant |
| US2010/0299754(A1) | 2010-11-01 | Amit et al. | Applicant |
| US2010/0306173(A1) | 2010-12-01 | Frank | Applicant |
| US2011/0004737(A1) | 2011-01-01 | Greenebaum | Applicant |
| US2011/0025504(A1) | 2011-02-01 | Lyon et al. | Applicant |
| US2011/0041179(A1) | 2011-02-01 | St Hlberg | Applicant |
| US2011/0047594(A1) | 2011-02-01 | Mahaffey et al. | Applicant |
| US2011/0047620(A1) | 2011-02-01 | Mahaffey et al. | Applicant |
| US2011/0055907(A1) | 2011-03-01 | Narasimhan et al. | Applicant |
| US2011/0078794(A1) | 2011-03-01 | Manni et al. | Applicant |
| US2011/0093951(A1) | 2011-04-01 | Aziz | Applicant |
| US2011/0099620(A1) | 2011-04-01 | Stavrou et al. | Applicant |
| US2011/0099633(A1) | 2011-04-01 | Aziz | Applicant |
| US2011/0099635(A1) | 2011-04-01 | Silberman et al. | Applicant |
| US2011/0113231(A1) | 2011-05-01 | Kaminsky | Applicant |
| US2011/0145918(A1) | 2011-06-01 | Jung et al. | Applicant |
| US2011/0145920(A1) | 2011-06-01 | Mahaffey et al. | Applicant |
| US2011/0145934(A1) | 2011-06-01 | Abramovici et al. | Applicant |
| US2011/0167493(A1) | 2011-07-01 | Song et al. | Applicant |
| US2011/0167494(A1) | 2011-07-01 | Bowen et al. | Applicant |
| US2011/0173213(A1) | 2011-07-01 | Frazier et al. | Applicant |
| US2011/0173460(A1) | 2011-07-01 | Ito et al. | Applicant |
| US2011/0219449(A1) | 2011-09-01 | St. Neitzel et al. | Applicant |
| US2011/0219450(A1) | 2011-09-01 | McDougal et al. | Applicant |
| US2011/0225624(A1) | 2011-09-01 | Sawhney et al. | Applicant |
| US2011/0225655(A1) | 2011-09-01 | Niemela et al. | Applicant |
| US2011/0247072(A1) | 2011-10-01 | Staniford et al. | Applicant |
| US2011/0265182(A1) | 2011-10-01 | Peinado et al. | Applicant |
| US2011/0289582(A1) | 2011-11-01 | Kejriwal et al. | Applicant |
| US2011/0302587(A1) | 2011-12-01 | Nishikawa et al. | Applicant |
| US2011/0307954(A1) | 2011-12-01 | Melnik et al. | Applicant |
| US2011/0307955(A1) | 2011-12-01 | Kaplan et al. | Applicant |
| US2011/0307956(A1) | 2011-12-01 | Yermakov et al. | Applicant |
| US2011/0314546(A1) | 2011-12-01 | Aziz et al. | Applicant |
| US2012/0023593(A1) | 2012-01-01 | Puder et al. | Applicant |
| US2012/0054869(A1) | 2012-03-01 | Yen et al. | Applicant |
| US2012/0066698(A1) | 2012-03-01 | Yanoo | Applicant |
| US2012/0079596(A1) | 2012-03-01 | Thomas et al. | Applicant |
| US2012/0084859(A1) | 2012-04-01 | Radinsky et al. | Applicant |
| US2012/0110667(A1) | 2012-05-01 | Zubrilin et al. | Applicant |
| US2012/0117652(A1) | 2012-05-01 | Manni et al. | Applicant |
| US2012/0121154(A1) | 2012-05-01 | Xue et al. | Applicant |
| US2012/0124426(A1) | 2012-05-01 | Maybee et al. | Applicant |
| US2012/0174186(A1) | 2012-07-01 | Aziz et al. | Applicant |
| US2012/0174196(A1) | 2012-07-01 | Bhogavilli et al. | Applicant |
| US2012/0174218(A1) | 2012-07-01 | McCoy et al. | Applicant |
| US2012/0198279(A1) | 2012-08-01 | Schroeder | Applicant |
| US2012/0210423(A1) | 2012-08-01 | Friedrichs et al. | Applicant |
| US2012/0222121(A1) | 2012-08-01 | Staniford et al. | Applicant |
| US2012/0255015(A1) | 2012-10-01 | Sahita et al. | Applicant |
| US2012/0255017(A1) | 2012-10-01 | Sallam | Applicant |
| US2012/0260342(A1) | 2012-10-01 | Dube et al. | Applicant |
| US2012/0266244(A1) | 2012-10-01 | Green et al. | Applicant |
| US2012/0278886(A1) | 2012-11-01 | Luna | Applicant |
| US2012/0297489(A1) | 2012-11-01 | Dequevy | Applicant |
| US2012/0330801(A1) | 2012-12-01 | McDougal et al. | Applicant |
| US2012/0331553(A1) | 2012-12-01 | Aziz et al. | Applicant |
| US2013/0014259(A1) | 2013-01-01 | Gribble et al. | Applicant |
| US2013/0036472(A1) | 2013-02-01 | Aziz | Applicant |
| US2013/0047257(A1) | 2013-02-01 | Aziz | Applicant |
| US2013/0074185(A1) | 2013-03-01 | McDougal et al. | Applicant |
| US2013/0086684(A1) | 2013-04-01 | Mohler | Applicant |
| US2013/0097699(A1) | 2013-04-01 | Balupari et al. | Applicant |
| US2013/0097706(A1) | 2013-04-01 | Titonis et al. | Applicant |
| US2013/0111587(A1) | 2013-05-01 | Goel et al. | Applicant |
| US2013/0117852(A1) | 2013-05-01 | Stute | Applicant |
| US2013/0117855(A1) | 2013-05-01 | Kim et al. | Applicant |
| US2013/0139264(A1) | 2013-05-01 | Brinkley et al. | Applicant |
| US2013/0160125(A1) | 2013-06-01 | Likhachev et al. | Applicant |
| US2013/0160127(A1) | 2013-06-01 | Jeong et al. | Applicant |
| US2013/0160130(A1) | 2013-06-01 | Mendelev et al. | Applicant |
| US2013/0160131(A1) | 2013-06-01 | Madou et al. | Applicant |
| US2013/0167236(A1) | 2013-06-01 | Sick | Applicant |
| US2013/0174214(A1) | 2013-07-01 | Duncan | Applicant |
| US2013/0185789(A1) | 2013-07-01 | Hagiwara et al. | Applicant |
| US2013/0185795(A1) | 2013-07-01 | Winn et al. | Applicant |
| US2013/0185798(A1) | 2013-07-01 | Saunders et al. | Applicant |
| US2013/0191915(A1) | 2013-07-01 | Antonakakis et al. | Applicant |
| US2013/0196649(A1) | 2013-08-01 | Paddon et al. | Applicant |
| US2013/0227691(A1) | 2013-08-01 | Aziz et al. | Applicant |
| US2013/0246370(A1) | 2013-09-01 | Bartram et al. | Applicant |
| US2013/0247186(A1) | 2013-09-01 | LeMasters | Applicant |
| US2013/0263260(A1) | 2013-10-01 | Mahaffey et al. | Applicant |
| US2013/0291109(A1) | 2013-10-01 | Staniford et al. | Applicant |
| US2013/0298243(A1) | 2013-11-01 | Kumar et al. | Applicant |
| US2013/0318038(A1) | 2013-11-01 | Shifter et al. | Applicant |
| US2013/0318073(A1) | 2013-11-01 | Shifter et al. | Applicant |
| US2013/0325791(A1) | 2013-12-01 | Shiffer et al. | Applicant |
| US2013/0325792(A1) | 2013-12-01 | Shiffer et al. | Applicant |
| US2013/0325871(A1) | 2013-12-01 | Shifter et al. | Applicant |
| US2013/0325872(A1) | 2013-12-01 | Shifter et al. | Applicant |
| US2013/0333032(A1) | 2013-12-01 | Delatorre et al. | Applicant |
| US2014/0032875(A1) | 2014-01-01 | Butler | Applicant |
| US2014/0053260(A1) | 2014-02-01 | Gupta et al. | Applicant |
| US2014/0053261(A1) | 2014-02-01 | Gupta et al. | Applicant |
| US2014/0130158(A1) | 2014-05-01 | Wang et al. | Applicant |
| US2014/0137180(A1) | 2014-05-01 | Lukacs et al. | Applicant |
| US2014/0169762(A1) | 2014-06-01 | Ryu | Applicant |
| US2014/0179360(A1) | 2014-06-01 | Jackson et al. | Applicant |
| US2014/0181131(A1) | 2014-06-01 | Ross | Applicant |
| US2014/0189687(A1) | 2014-07-01 | Jung et al. | Applicant |
| US2014/0189866(A1) | 2014-07-01 | Shiffer et al. | Applicant |
| US2014/0189882(A1) | 2014-07-01 | Jung et al. | Applicant |
| US2014/0237600(A1) | 2014-08-01 | Silberman et al. | Applicant |
| US2014/0280245(A1) | 2014-09-01 | Wilson | Applicant |
| US2014/0283037(A1) | 2014-09-01 | Sikorski et al. | Applicant |
| US2014/0283063(A1) | 2014-09-01 | Thompson et al. | Applicant |
| US2014/0328204(A1) | 2014-11-01 | Klotsche et al. | Applicant |
| US2014/0337836(A1) | 2014-11-01 | Ismael | Applicant |
| US2014/0344926(A1) | 2014-11-01 | Cunningham et al. | Applicant |
| US2014/0351935(A1) | 2014-11-01 | Shao et al. | Applicant |
| US2014/0380473(A1) | 2014-12-01 | Bu et al. | Applicant |
| US2014/0380474(A1) | 2014-12-01 | Paithane et al. | Applicant |
| US2015/0007312(A1) | 2015-01-01 | Pidathala et al. | Applicant |
| US2015/0096022(A1) | 2015-04-01 | Vincent et al. | Applicant |
| US2015/0096023(A1) | 2015-04-01 | Mesdaq et al. | Applicant |
| US2015/0096024(A1) | 2015-04-01 | Haq et al. | Applicant |
| US2015/0096025(A1) | 2015-04-01 | Ismael | Applicant |
| US2015/0180886(A1) | 2015-06-01 | Staniford et al. | Applicant |
| US2015/0186645(A1) | 2015-07-01 | Aziz et al. | Applicant |
| US2015/0220735(A1) | 2015-08-01 | Paithane et al. | Applicant |
| US2015/0372980(A1) | 2015-12-01 | Eyada | Applicant |
| US2016/0044000(A1) | 2016-02-01 | Cunningham | Applicant |
| US2016/0127393(A1) | 2016-05-01 | Aziz et al. | Applicant |
| US2016/0191547(A1) | 2016-06-01 | Zafar et al. | Applicant |
| US2016/0261612(A1) | 2016-09-01 | Mesdaq et al. | Applicant |
| US2016/0285914(A1) | 2016-09-01 | Singh et al. | Applicant |
| US2016/0301703(A1) | 2016-10-01 | Aziz | Applicant |
| US2016/0335110(A1) | 2016-11-01 | Paithane et al. | Applicant |
| US2017/0083703(A1) | 2017-03-01 | Abbasi et al. | Applicant |
| GB2439806(A) | 2008-01-01 | Applicant | |
| GB2490431(A) | 2012-10-01 | Applicant | |
| WO2/006928(A2) | 2002-01-01 | Applicant | |
| WO2/23805(A2) | 2002-03-01 | Applicant | |
| WO2007117636(A2) | 2007-10-01 | Applicant | |
| WO2008041950(A2) | 2008-04-01 | Applicant | |
| WO2011084431(A2) | 2011-07-01 | Applicant | |
| WO2011/112348(A1) | 2011-09-01 | Applicant | |
| WO2012/075336(A1) | 2012-06-01 | Applicant | |
| WO2012145066(A1) | 2012-10-01 | Applicant | |
| WO2013/067505(A1) | 2013-05-01 | Applicant |
Non-Patent Literature (77)
- Aura, Tuomas, “Scanning electronic documents for personally identifiable information”, Proceedings of the 5th ACM workshop on Privacy in electronic society. ACM, 2006.Applicant
- Baecher, “The Nepenthes Platform: An Efficient Approach to collect Malware”, Springer-verlag Berlin Heidelberg, (2006), pp. 165-184.Applicant
- Baldi, Mario; Risso, Fulvio; “A Framework for Rapid Development and Portable Execution of Packet-Handling Applications”, 5th IEEE International Symposium Processing and Information Technology, Dec. 21, 2005, pp. 233-238.Applicant
- Bayer, et al., “Dynamic Analysis of Malicious Code”, J Comput Virol, Springer-Verlag, France., (2006), pp. 67-77.Applicant
- Boubalos, Chris , “extracting syslog data out of raw pcap dumps, seclists.org, Honeypots mailing list archives”, available at http://seclists.org/honeypots/2003/q2/319 (“Boubalos”), (Jun. 5, 2003).Applicant
- Chaudet, C. , et al., “Optimal Positioning of Active and Passive Monitoring Devices”, International Conference on Emerging Networking Experiments and Technologies, Proceedings of the 2005 ACM Conference on Emerging Network Experiment and Technology, CoNEXT '05, Toulousse, France, (Oct. 2005), pp. 71-82.Applicant
- Chen, P. M. and Noble, B. D., “When Virtual is Better Than Real, Department of Electrical Engineering and Computer Science”, University of Michigan (“Chen”) (2001).Applicant
- Cisco “Intrusion Prevention for the Cisco ASA 5500-x Series” Data Sheet (2012).Applicant
- Cisco, Configuring the Catalyst Switched Port Analyzer (SPAN) (“Cisco”), (1992).Applicant
- Clark, John, Sylvian Leblanc,and Scott Knight. “Risks associated with usb hardware trojan devices used by insiders.” Systems Conference (SysCon), 2011 IEEE International. IEEE, 2011.Applicant
- Cohen, M.I. , “PyFlag—An advanced network forensic framework”, Digital investigation 5, Elsevier, (2008), pp. S112-S120.Applicant
- “Network Security: NetDetector—Network Intrusion Forensic System (NIFS) Whitepaper”, (“NetDetector Whitepaper”), (2003).Applicant
- “Packet”, Microsoft Computer Dictionary, Microsoft Press, (Mar. 2002), 1 page.Applicant
- “When Virtual is Better Than Real”, IEEEXplore Digital Library, available at, http://ieeexplore.ieee.org/xpl/articleDetails.isp?reload=true&arnumbe- r=990073, (Dec. 7, 2013).Applicant
- Abdullah, et al., Visualizing Network Data for Intrusion Detection, 2005 IEEE Workshop on Information Assurance and Security, pp. 100-108.Applicant
- Adetoye, Adedayo , et al., “Network Intrusion Detection & Response System”, (“Adetoye”), (Sep. 2003).Applicant
- Adobe Systems Incorporated, “PDF 32000-1:2008, Document management—Portable document format—Part1:PDF 1.7”, First Edition, Jul. 1, 2008, 756 pages.Applicant
- AltaVista Advanced Search Results. “attack vector identifier”. Http://www.altavista.com/web/results?Itag=ody&pg=aq&aqmode=aqa=Event+Orch- estrator . . . , (Accessed on Sep. 15, 2009).Applicant
- AltaVista Advanced Search Results. “Event Orchestrator”. Http://www.altavista.com/web/results?Itag=ody&pg=aq&aqmode=aqa=Event+Orch- esrator . . . , (Accessed on Sep. 3, 2009).Applicant
- Apostolopoulos, George; hassapis, Constantinos; “V-eM: A cluster of Virtual Machines for Robust, Detailed, and High-Performance Network Emulation”, 14th IEEE International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems, Sep. 11-14, 2006, pp. 117-126.Applicant
- Krasnyansky, Max , et al., Universal TUN/TAP driver, available at https://www.kernel.org/doc/Documentation/networking/tuntap.txt (2002) (“Krasnyansky”).Applicant
- Kreibich, C. , et al., “Honeycomb-Creating Intrusion Detection Signatures Using Honeypots”, 2nd Workshop on Hot Topics in Networks (HotNets-11), Boston, USA, (2003).Applicant
- Kristoff, J. , “Botnets, Detection and Mitigation: DNS-Based Techniques”, NU Security Day, (2005), 23 pages.Applicant
- Leading Colleges Select FireEye to Stop Malware-Related Data Breaches, FireEye Inc., 2009.Applicant
- Li et al., A VMM-Based System Call Interposition Framework for Program Monitoring, Dec. 2010, IEEE 16th International Conference on Parallel and Distributed Systems, pp. 706-711.Applicant
- Liljenstam, Michael , et al., “Simulating Realistic Network Traffic for Worm Warning System Design and Testing”, Institute for Security Technology studies, Dartmouth College (“Liljenstam”), (Oct. 27, 2003).Applicant
- Lindorfer, Martina, Clemens Kolbitsch, and Paolo Milani Comparetti. “Detecting environment-sensitive malware.” Recent Advances in Intrusion Detection. Springer Berlin Heidelberg, 2011.Applicant
- Lok Kwong et al: “DroidScope: Seamlessly Reconstructing the OS and Dalvik Semantic Views for Dynamic Android Malware Analysis”, Aug. 10, 2012, XP055158513, Retrieved from the Internet: URL:https://www.usenix.org/system/files/conference/usenixsecurity12/sec12- -final107.pdf [retrieved on Dec. 15, 2014].Applicant
- Costa, M. , et al., “Vigilante: End-to-End Containment of Internet Worms”, SOSP '05, Association for Computing Machinery, Inc., Brighton U.K., (Oct. 23-26, 2005).Applicant
- Crandall, J.R. , et al., “Minos:Control Data Attack Prevention Orthogonal to Memory Model”, 37th International Symposium on Microarchitecture, Portland, Oregon, (Dec. 2004).Applicant
- Deutsch, P. , “Zlib compressed data format specification version 3.3” RFC 1950, (1996).Applicant
- Distler, “Malware Analysis: An Introduction”, SANS Institute InfoSec Reading Room, SANS Institute, (2007).Applicant
- Dunlap, George W. , et al., “ReVirt: Enabling Intrusion Analysis through Virtual-Machine Logging and Replay”, Proceeding of the 5th Symposium on Operating Systems Design and Implementation, USENIX Association, (“Dunlap”), (Dec. 9, 2002).Applicant
- Excerpt regarding First Printing Date for Merike Kaeo, Designing Network Security (“Kaeo”), (2005).Applicant
- Filiol, Eric , et al., “Combinatorial Optimisation of Worm Propagation on an Unknown Network”, International Journal of Computer Science 2.2 (2007).Applicant
- FireEye Malware Analysis & Exchange Network, Malware Protection System, FireEye Inc., 2010.Applicant
- FireEye Malware Analysis, Modern Malware Forensics, FireEye Inc., 2010.Applicant
- FireEye v.6.0 Security Target, pp. 1-35, Version 1.1, FireEye Inc., May 2011.Applicant
- Gibler, Clint, et al. AndroidLeaks: automatically detecting potential privacy leaks in android applications on a large scale. Springer Berlin Heidelberg, 2012.Applicant
- Goel, et al., Reconstructing System State for Intrusion Analysis, Apr. 2008 SIGOPS Operating Systems Review, vol. 12 Issue 3, pp. 21-28.Applicant
- Gregg Keizer: “Microsoft's HoneyMonkeys Show Patching Windows Works”, Aug. 8, 2005, XP055143386, Retrieved from the Internet: URL:http://www.informationweek.com/microsofts-honeymonkeys-show-patching-windows-works/d/d-id/1035069? [retrieved on Jun. 1, 2016].Applicant
- Heng Yin et al, Panorama: Capturing System-Wide Information Flow for Malware Detection and Analysis, Research Showcase @ CMU, Carnegie Mellon University, 2007.Applicant
- Hjelmvik, Erik , “Passive Network Security Analysis with NetworkMiner”, (IN)Secure, Issue 18, (Oct. 2008), pp. 1-100.Applicant
- Idika et al., A-Survey-of-Malware-Detection-Techniques, Feb. 2, 2007, Department of Computer Science, Purdue University.Applicant
- IEEE Xplore Digital Library Sear Results for “detection of unknown computer worms”. Http//ieeexplore.ieee.org/searchresult.jsp?SortField=Score&SortOrder=desc- &ResultC . . . , (Accessed on Aug. 28, 2009).Applicant
- Isohara, Takamasa, Keisuke Takemori, and Ayumu Kubota. “Kernel-based behavior analysis for android malware detection.” Computational intelligence and Security (CIS), 2011 Seventh International Conference on. IEEE, 2011.Applicant
- Kaeo, Merike , “Designing Network Security”, (“Kaeo”), (Nov. 2003).Applicant
- Kevin A Roundy et al: “Hybrid Analysis and Control of Malware”, Sep. 15, 2010, Recent Advances in Intrusion Detection, Springer Berlin Heidelberg, Berlin, Heidelberg, pp. 317-338, XP019150454 ISBN:978-3-642-15511-6.Applicant
- Kim, H. , et al., “Autograph: Toward Automated, Distributed Worm Signature Detection”, Proceedings of the 13th Usenix Security Symposium (Security 2004), San Diego, (Aug. 2004), pp. 271-286.Applicant
- King, Samuel T., et al., “Operating System Support for Virtual Machines”, (“King”) (2003).Applicant
- Marchette, David J., “Computer Intrusion Detection and Network Monitoring: A Statistical Viewpoint”, (“Marchette”), (2001).Applicant
- Margolis, P.E. , “Random House Webster's ‘Computer & Internet Dictionary 3rd Edition’”, ISBN 0375703519, (Dec. 1998).Applicant
- Moore, D. , et al., “Internet Quarantine: Requirements for Containing Self-Propagating Code”, INFOCOM, vol. 3, (Mar. 30-Apr. 3, 2003), pp. 1901-1910.Applicant
- Morales, Jose A., et al., ““Analyzing and exploiting network behaviors of malware.””, Security and Privacy in Communication Networks. Springer Berlin Heidelberg, 2010. 20-34.Applicant
- Mori, Detecting Unknown Computer Viruses, 2004, Springer-Verlag Berlin Heidelberg.Applicant
- Natvig, Kurt , “SANDBOXII: Internet”, Virus Bulletin Conference, (“Natvig”), (Sep. 2002).Applicant
- NetBIOS Working Group. Protocol Standard for a NetBIOS Service on a TCP/UDP transport: Concepts and Methods. STD 19, RFC 1001, Mar. 1987.Applicant
- Newsome, J. , et al., “Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software”, In Proceedings of the 12th Annual Network and Distributed System Security, Symposium (NDSS '05), (Feb. 2005).Applicant
- Newsome, J. , et al., “Polygraph: Automatically Generating Signatures for Polymorphic Worms”, In Proceedings of the IEEE Symposium on Security and Privacy, (May 2005).Applicant
- U.S. Pat. No. 8,291,499 filed Mar. 16, 2012, Inter Parties Review Decision dated Jul. 10, 2015.Applicant
- Venezia, Paul , “NetDetector Captures Intrusions”, InfoWorld Issue 27, (“Venezia”), (Jul. 14, 2003).Applicant
- Wahid et al., Characterising the Evolution in Scanning Activity of Suspicious Hosts, Oct. 2009, Third International Conference on Network and System Security, pp. 344-350.Applicant
- Whyte, et al., “DNS-Based Detection of Scanning Works in an Enterprise Network”, Proceedings of the 12th Annual Network and Distributed System Security Symposium, (Feb. 2005), 15 pages.Applicant
- Williamson, Matthew M., “Throttling Viruses: Restricting Propagation to Defeat Malicious Mobile Code”, ACSAC Conference, Las Vegas, NV, USA, (Dec. 2002), pp. 1-9.Applicant
- Yuhei Kawakoya et al: “Memory behavior-based automatic malware unpacking in stealth debugging environment”, Malicious and Unwanted Software (Malware), 2010 5th International Conference on, IEEE, Piscataway, NJ, USA, Oct. 19, 2010, pp. 39-46, XP031833827, ISBN:978-1-4244-8-9353-1.Applicant
- Zhang et al., The Effects of Threading, Infection Time, and Multiple-Attacker Collaboration on Malware Propagation, Sep. 2009, IEEE 28th International Symposium on Reliable Distributed Systems, pp. 73-82.Applicant
- Nojiri, D. , et al., “Cooperation Response Strategies for Large Scale Attack Mitigation”, DARPA Information Survivability Conference and Exposition, vol. 1, (Apr. 22-24, 2003), pp. 293-302.Applicant
- Oberheide et al., CloudAV.sub.—N-Version Antivirus in the Network Cloud, 17th USENIX Security Symposium USENIX Security '08 Jul. 28-Aug. 1, 2008 San Jose, CA.Applicant
- Reiner Sailer, Enriquillo Valdez, Trent Jaeger, Roonald Perez, Leendert van Doom, John Linwood Griffin, Stefan Berger., sHype: Secure Hypervisor Appraoch to Trusted Virtualized Systems (Feb. 2, 2005) (“Sailer”).Applicant
- Silicon Defense, “Worm Containment in the Internal Network”, (Mar. 2003), pp. 1-25.Applicant
- Singh, S. , et al., “Automated Worm Fingerprinting”, Proceedings of the ACM/USENIX Symposium on Operating System Design and Implementation, San Francisco, California, (Dec. 2004).Applicant
- Spitzner, Lance , “Honeypots: Tracking Hackers”, (“Spizner”), (Sep. 17, 2002).Applicant
- The Sniffers's Guide to Raw Traffic available at: yuba.stanford.edu/.about.casado/pcap/section1.html, (Jan. 6, 2014).Applicant
- Thomas H. Ptacek, and Timothy N. Newsham , “Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection”, Secure Networks, (“Ptacek”), (Jan. 1998).Applicant
- U.S. Appl. No. 13/828,785, filed Mar. 14, 2013 Non-Final Office Action dated Mar. 25, 2015.Applicant
- U.S. Appl. No. 15/096,088, filed Apr. 11, 2016 Non-Final Office Action dated Aug. 12, 2016.Applicant
- U.S. Appl. No. 8,171,553, filed Apr. 20, 2006, Inter Parties Review Decision dated Jul. 10, 2015.Applicant