US 9,846,776 B1Grant
System and method for detecting file altering behaviors pertaining to a malicious attack
Issue Date:2017-12-19
•37 Claims
•11 Drawing Sheets
Abstract
According to one embodiment, a computerized method for detecting malware is described. The method includes receiving configuration information that identifies (i) at least one type of lure data and (ii) one or more locations of a system operating within a virtual machine for placement of the lure data into the system. The lure data is configured to entice interaction of the lure data by malware associated with an object under analysis. Thereafter, the lure data is placed within the system according to the configuration information and lure data information is selectively modified. The information may include a name or content within a directory including the lure data. During processing of an object within the virtual machine, a determination is made whether the object exhibits file altering behavior based on a comparison of actions performed that are associated with the lure data and one more known file activity patterns.
Metadata
Assignee
- FireEye, Inc.
Inventors
- Sushant Paithane
- Sai Vashist
- Raymond Yang
- Yasir Khalid
Application Information
Application Number:US 15/339,459
Filing Date:2016-10-31
Priority Date:2015-03-31
Art Unit:2493
Classifications
IPC:
G06F21/56G06F17/30
Field of Search:
G06F 21/56G06F 17/30144G06F 2221/034
Patent Drawings (11 sheets)
Description
Cross-Reference to Related Application
[0001] This Patent Application is a continuation application of U.S. patent application Ser. No. 14/675,648 filed Mar. 31, 2015, now U.S. Pat. No. 9,483,644, the entire contents of all of which are incorporated herein by reference.
Field
[0002] Embodiments of the disclosure relate to the field of cyber security. More specifically, embodiments of the disclosure relate to a system for detecting anomalous, or more specifically, malicious behavior using one or more lure files and a file system within a virtual machine.
General Background
[0003] Over the last decade, malicious software has become a pervasive problem for Internet users as many networked resources include vulnerabilities that are subject to attack. For instance, over the past few years, more and more vulnerabilities are being discovered in software that is loaded onto endpoint devices present on a network. These vulnerabilities may be exploited by allowing a third-party, e.g., through computer software, to gain access to one or more areas within the network not typically accessible. For example, a third-party may exploit a software vulnerability to gain unauthorized access to email accounts and/or data files.
[0004] While some software vulnerabilities continue to be addressed through software patches, prior to the release of such software patches, network devices will continue to be targeted for attack by exploits, namely malicious computer code that attempts to acquire sensitive information, adversely influence, or attack normal operations of the network device or the entire enterprise network by taking advantage of a vulnerability in computer software. Herein, a network device may be any device with data processing and network connectivity such as, for example, a security appliance, a server, a mainframe, a computer such as a desktop or laptop, netbook, tablet, firewall, smart phone, router, switch, bridge, etc.
[0005] In particular, one type of malware may exhibit behaviors such as infecting, encrypting, deleting and/or stealing files (hereinafter generally referred to as “file altering malware”). File altering malware targets computer systems in order to, at least, (i) restrict access to one or more portions of a computer system and demand a payment for the removal of the restriction (e.g., in some instances, file altering malware may encrypt files within the computer system and in other instances, may prohibit access to the entire computer system) or (ii) infect computer systems with information theft routines, which may seek to steal information such as (1) login credentials to one or more applications (e.g., Microsoft® Outlook, Google® Chrome, Spotify, etc.), (2) system information (e.g., Windows product keys, volume serial numbers, etc.), (3) file transport protocol (FTP) credentials, or the like.
[0006] In some instances, file altering malware may enter a computer system, for example, when a user of an endpoint device activates a uniform resource locator (URL) in an Internet-browser application or downloads a file from a network or opens an e-mail attachment. Subsequently, the file altering malware may alter various files within the computer, which may include encrypting one or more files thereby restricting access to the one or more files. The file altering malware may then request a payment for a key to decrypt one or more files.
[0007] In some cases, the file altering malware may target particular data storage locations, such as files and/or folders containing sensitive personal or corporate information, financial information or even content related to military services. Targeting particular files and/or folders containing sensitive information creates a sense of urgency with the user of the infected endpoint device and/or a corporation associated with the infected endpoint device to adhere to the requests of the malware writers.
[0008] Currently, malware detection systems attempting to detect file altering malware have difficulty identifying files affected by file altering malware, as non-malicious applications may affect files and folders in a similar manner as file altering malware. For example, non-malicious file scanners or non-malicious encryption programs may, for example, open, rename, encrypt and/or password protect the same files and/or folders affected by file altering malware (e.g., files and/or folders containing sensitive information). In one example, a corporation deploying an enterprise network may propagate updates to a file encryption program that is intended to encrypt particular directories within a file system on each endpoint device (e.g., a “My Documents” directory on all corporate computers). Upon receiving the updates and launching the corporate-approved file encryption program, current malware detection systems cannot distinguish between the approved file encryption program and file altering malware. Therefore, current malware detection systems may return numerous false-positives and/or false-negatives.
Brief Description of the Drawings
[0009] Embodiments of the invention are illustrated by way of example and not by way of limitation in the figures of the accompanying drawings, in which like references indicate similar elements and in which:
[0010] FIG. 1 is an exemplary block diagram of a network deploying a plurality of threat detection platforms (TDPs) deploying the invention.
[0011] FIG. 2 is a block diagram of an exemplary dynamic analysis engine within the TDP of FIG. 1 .
[0012] FIG. 3 is an exemplary block diagram of logic associated with the TDP of FIG. 1 .
[0013] FIG. 4 is a flowchart illustrating an exemplary method for analyzing an object with the TDP of FIG. 1 .
[0014] FIG. 5A is an illustration of an exemplary file system prior to placement of one or more lure files.
[0015] FIG. 5B is an illustration of the exemplary file system of FIG. 5A following placement of a plurality of lure files.
[0016] FIG. 5C is an illustration of the exemplary file system of FIG. 5B following pseudo-randomization of the names of the plurality of lure files.
[0017] FIG. 6A is a flowchart illustrating a first exemplary method for analyzing a file system after processing an object with the TDP of FIG. 1 .
[0018] FIG. 6B is a flowchart illustrating a second exemplary method for analyzing a file system after processing an object with the TDP of FIG. 1 .
[0019] FIG. 7 is an illustration of exemplary graphical user interface associated with the TDP of FIG. 1 .
Detailed Description
[0020] Various embodiments of the disclosure relate to a threat detection platform (TDP) that improves malware detection, particularly, in the case of malware including file altering malware. In one embodiment of the disclosure, the TDP determines whether an object is associated with a malicious attack involving file altering malware through a dynamic analysis of an object within a virtual run-time environment. Herein, the virtual run-time environment features one or more virtual machine instances (VMs), which may be provisioned with a guest image associated with a prescribed software profile. Each guest image may include a software application and/or an operating system (OS). Each guest image may further include one or more monitors, namely software components that are configured to observe and capture run-time behavior of an object under analysis during processing within the virtual machine. In another embodiment, the TDP may also perform a static analysis of the object (e.g., rules-based analysis using heuristics and/or comparisons of one or more signatures).
[0021] Herein, each of the VMs may be configured with a guest image to simulate a particular endpoint device. Specifically, each VM may be configured with different operating systems, different applications, different versions of a common operating system and/or different versions of a common application. Additionally, each VM may include a file system that is monitored during the dynamic processing. Herein, one or more lure configuration files may be provided to the virtual run-time environment, wherein the configuration files set-forth information that enables each VM to configure the file system therein. For example, a lure configuration file may include, but is not limited or restricted to, the number of lure files that are to be placed in the file system prior to processing the object, the location of the placement of each of the lure files, time and date information for each VM, etc. Additionally, one or more lure files may be provided to each VM to be added to its file system. Alternatively, each VM may generate one or more lure files according to the information set forth in the lure configuration file.
[0022] In one embodiment, the TDP may receive an object via a network connection and one or more VMs may perform a dynamic analysis on the object to determine whether the object is associated with malware, particularly file altering malware. Specifically, a method for analyzing an object with the TDP may be divided into three phases: (A) an installation phase; (B) a configuration phase; and (C) a processing and analysis phase.
[0023] The installation phase includes receiving, at least, a lure configuration file, identifying lure file types and locations in the file system for which to place the lure files, generating the lure files (if not provided), and placing the lure files in the file system. The configuration phase may include, at least, receiving an object to analyze, selectively modifying the file names and/or content of one or more lure files (e.g., generating random or pseudo-random file names for the lure files and, optionally, randomizing or pseudo-randomizing the lure file contents). Third, the processing and analysis phase may include capturing a snapshot of the file system prior to processing the object; processing the object, monitoring (i) the actions performed during processing associated with one or more of the lure files and (ii) changes to the file system; and analyzing, at least, the changes to determine whether the object exhibits file altering behavior. Optionally, a determination of the malware family to which the malware belongs may be made (e.g., an object may be sub-classified as an infector, stealer, cryptor or destructor). Additionally, and also optionally, an alert may be generated detailing the detection of the file altering malware. Throughout the specification, claims and figures, the term “network traffic” will be used in the discussion but any form of incoming data may be substituted.
[0024] Herein, the phrase, “actions performed during processing associated with one or more of the lure files,” should be understood as being any direct or indirect interaction with the lure file. Additionally, hereinafter, the phrase “changes to the file system” should be interpreted as meaning one or more actions performed during processing of the object inclusive of changes to the file system.
[0025] I. Terminology
[0026] In the following description, certain terminology is used to describe features of the invention. For example, in certain situations, both terms “logic” and “engine” are representative of hardware, firmware and/or software that is configured to perform one or more functions. As hardware, logic (or engine) may include circuitry having data processing or storage functionality. Examples of such circuitry may include, but are not limited or restricted to a microprocessor, one or more processor cores, a programmable gate array, a microcontroller, a controller, an application specific integrated circuit, wireless receiver, transmitter and/or transceiver circuitry, semiconductor memory, or combinatorial logic.
[0027] Logic (or engine) may be software in the form of one or more software modules, such as executable code in the form of an executable application, an application programming interface (API), a subroutine, a function, a procedure, an applet, a servlet, a routine, source code, object code, a shared library/dynamic link library, or one or more instructions. These software modules may be stored in any type of a suitable non-transitory storage medium, or transitory storage medium (e.g., electrical, optical, acoustical or other form of propagated signals such as carrier waves, infrared signals, or digital signals). Examples of non-transitory storage medium may include, but are not limited or restricted to a programmable circuit; a semiconductor memory; non-persistent storage such as volatile memory (e.g., any type of random access memory “RAM”); persistent storage such as non-volatile memory (e.g., read-only memory “ROM”, power-backed RAM, flash memory, phase-change memory, etc.), a solid-state drive, hard disk drive, an optical disc drive, or a portable memory device. As firmware, the executable code is stored in persistent storage.
[0028] An “exploit” may be construed broadly as information (e.g., executable code, data, command(s), etc.) that attempts to take advantage of a software vulnerability and/or an action by a person gaining unauthorized access to one or more areas of a network device to cause the network device to experience undesirable or anomalous behaviors. The undesirable or anomalous behaviors may include a communication-based anomaly or an execution-based anomaly, which, for example, could (1) alter the functionality of an network device executing application software in an atypical manner (a file is opened by a first process where the file is configured to be opened by a second process and not the first process); (2) alter the functionality of the network device executing that application software without any malicious intent; and/or (3) provide unwanted functionality which may be generally acceptable in another context.
[0029] According to one embodiment, “malware” may be construed broadly as computer code that executes an exploit to take advantage of a vulnerability, for example, to harm or co-opt operation of a network device or misappropriate, modify or delete data. Conventionally, malware is often said to be designed with malicious intent. Hereinafter, reference to “malware” includes malware and/or exploits.
[0030] The term “object” generally refers to a collection of data, whether in transit (e.g., over a network) or at rest (e.g., stored), often having a logical structure or organization that enables classification for purposes of analysis. During analysis, for example, the object may exhibit a set of expected characteristics and, during processing, a set of expected behaviors. The object may also exhibit a set of unexpected characteristics and a set of unexpected behaviors that may evidence the presence of malware and potentially allow the object to be classified as malicious, and more specifically, as file altering malware. One type of object is a “file” that constitutes a self-contained collection of data having a logical structure or organization that enables classification for purposes of analysis. A second example of an object is a “flow” generally refers to related packets that are received, transmitted, or exchanged within a communication session. For convenience, a packet is broadly referred to as a series of bits or bytes having a prescribed format, which may, according to one embodiment, include packets, frames, or cells. Further, an “object” may also refer to collective payloads of a number of related packets, e.g., a single webpage received over a network.
[0031] As an illustrative example, a file may be a self-contained element, where different types of such files may include, for example, an executable file, non-executable file, a document (for example, a Microsoft Office® document), a dynamically linked library (DLL), a Portable Document Format (PDF) document, Zip file, a Flash Video (FLV) file, an electronic mail (email) message or a HyperText Markup Language (HTML) file.
[0032] The term “file system” may refer to any structural system for storing, organizing and/or retrieving data. Various file systems may be structured according to various structural and logical rules for storing, organizing and/or retrieving data. Examples of file systems may include, but are not limited or restricted to, disk file systems (File Allocation Table (FAT), New File Technology File System (NTFS), Universal Disk Format (UDF), ZFS, etc.), optical disk file systems, flash file systems and/or database file systems (wherein segments of data may be additionally stored, organized and/or retrieved according to one or more characteristics).
[0033] A “platform” generally refers to an electronic device with network connectivity that typically includes a housing that protects, and sometimes encases, circuitry with data processing and/or data storage. Examples of a platform may include a server or an endpoint device that may include, but is not limited or restricted to a stationary or portable computer including a desktop computer, laptop, electronic reader, netbook or tablet; a smart phone; a video-game console; or wearable technology (e.g., watch phone, etc.).
[0034] The terms “suspicious” and “malicious” may both represent a probability (or level of confidence) that the object is associated with a malicious attack. For instance, the probability may be based, at least in part, on (i) pattern matches; (ii) analyzed deviations in messaging practices set forth in applicable communication protocols, e.g., HTTP, TCP, etc.); (iii) analyzed compliance with certain message formats established for the protocol (e.g., out-of-order commands); (iv) analyzed header or payload parameters to determine compliance, (v) attempts to communicate with external servers during dynamic processing, and/or (vi) attempts to access predetermined (e.g., secure) locations in memory during dynamic processing.
[0035] The term “snapshot” should be interpreted as the capturing of the state of a file system at a particular point in time. For example, a snapshot may be taken of a file system within a virtual machine by recording the file system structure and contents therein (e.g., the contents of each directory within the file system including any sub-directories, folders and files located therein). The snapshot may be then stored within a storage device as, for example, a hash value.
[0036] The term “interacting” (and all other tenses) should be interpreted as any action taken during processing of an object that involves, or is associated with, a particular data (e.g., represented as a file or folder within a file system). Examples of actions or events that may interact with a file or folder include, but are not limited or restricted to, opening the file or folder, copying the file or folder, renaming the file or folder, encrypting the filer or folder, password protecting the file or folder creating the file or folder, editing the file or folder, etc. In addition, the interaction may be direct (e.g., an action is performed on a file or folder) or indirect (e.g., an action is performed that results in an action being performed on a file or folder).
[0037] Lastly, the terms “or” and “and/or” as used herein are to be interpreted as inclusive or meaning any one or any combination. Therefore, “A, B or C” or “A, B and/or C” mean “any of the following: A; B; C; A and B; A and C; B and C; A, B and C.” An exception to this definition will occur only when a combination of elements, functions, steps or acts are in some way inherently mutually exclusive.
[0038] The invention may be utilized for detecting malware, specifically malware typically known as file altering malware through the use of dynamic analysis in virtual machine. As this invention is susceptible to embodiments of many different forms, it is intended that the present disclosure is to be considered as an example of the principles of the invention and not intended to limit the invention to the specific embodiments shown and described.
[0039] II. General Architectures of Threat Detection Platform
[0040] Referring to FIG. 1 , an exemplary block diagram of a network 100 deploying a plurality of threat detection platforms (TDPs) 1101-110N (N>1, where N=3 for this embodiment) communicatively coupled to a management system 107 via a network 106 is shown. In general, the management system 107 is adapted to manage each TDP 1101-1103. For instance, the management system 107 may be configured to provide content updates (e.g., updates to a lure configuration file, upload new rules/signatures or modified rules/signatures, delete rules/signatures, modify parameters that are utilized by the rules/signatures) to logic included within each TDP 1101-1103. Additionally, content updates may be obtained as a result of information received through communications with the cloud computing services 105.
[0041] As shown in FIG. 1 , a first TDP 1101 is an electronic device that is adapted to analyze information associated with incoming data (e.g., network traffic, input data over a communication network 102, input data from another type of transmission medium, etc.) from/to one or more endpoint devices 130. In this illustrative embodiment, the communication network 102 may include a public network such as the Internet, a private network (e.g., a local area network “LAN”, wireless LAN, etc.), or a combination thereof.
[0042] According to the embodiment of FIG. 1 , the first TDP 1101 may be communicatively coupled with one or more endpoint devices 104 (hereinafter referred to as “endpoint device(s)”). As shown, the first TDP 1101 may be communicatively coupled with the network 102 via the communication interface 111, which directs signaling on the communication network 102 to the scheduler 112 which in turn directs signaling to the static analysis engine 120, the dynamic analysis engine 130 and/or the storage device 113. The communication interface 111 is configured to receive at least a portion of network traffic propagating to/from the endpoint device(s) 104 and provide information associated with the received portion of the network traffic to the first TDP 1101. This information may include metadata and may be a portion of the received network traffic or a duplicated copy of the portion of the received network traffic. The metadata may be used, at least in part, to determine protocols, application types and other information that may be subsequently used by logic, such as the scheduler 112 for example, to configure one or more VM1-VMK (K≧1) with selected software profiles. For instance, the metadata may be used to determine which software images (e.g., application(s)), if any, and/or operating systems to be fetched from the storage device 113 for configuring operability of the VM1-VMK.
[0043] Alternatively, although not shown, the communication interface 111 may be configured to receive files or other objects that are not provided over a network. For instance, as an example, the communication interface 111 may be a data capturing device that automatically (or on command), accessing data stored in a storage system or another type of interface, such as a port, for receiving objects manually provided via a suitable dedicated communication link or from storage media such as portable flash drives. Additionally, although not shown, the communication interface 111 may be integrated into an intermediary device in the communication path (e.g., a firewall, router, switch or other networked electronic device) or may be a standalone component, such as a commercially available network tap.
[0044] As further shown in FIG. 1 , the first TDP 1101 comprises the communication interface 111, the static analysis engine 120, the dynamic analysis engine 130, the classification engine 140 and the reporting engine 150. Herein, the communication interface 111 receives an object from the network 102 and converts the object into a format, as needed or appropriate, on which analysis by the static analysis engine 120 may be conducted. This conversion may involve decompression of the object, decompilation of the object, extraction of specific data associated with the object, and/or emulation of the extracted data (like Javascript™).
[0045] The static analysis engine 120 may include one or more controllers (e.g., processing circuitry such as one or more processors) that feature, at least, heuristics logic 121 and signature matching logic 122. Further, the static analysis engine 120 may include one or more software modules that, when executed by the controller(s), analyzes characteristics associated with the object, which may be a portion of network traffic (or downloaded data) according to an embodiment of the disclosure. Such static analysis may include one or more checks being conducted on the object without its execution. Examples of the checks may include (i) heuristics, performed by the heuristic logic 121, which are based on rules or policies as applied to the object and may determine whether one or more portions of the object are associated with anomalous or suspicious characteristics associated with known malware (e.g., a particular URL associated with known malware, or a particular source or destination address etc.); and/or (ii) signature matching, performed by the signature matching logic 122, which may include determinative rule-based analysis such as comparisons with entries on a blacklist and/or a whitelist.
[0046] The static analysis engine 120 may route the object to the virtual run-time environment 131 within the dynamic analysis engine 130. The virtual run-time environment 131 may include a virtual machine monitor (VMM) 132, a monitoring logic 133, an analysis logic 134, storage device 136 and the VM1-VMK (K≧1). The virtual run-time environment 131 provides for the processing of an object in one or more VM1-VMK managed by the VMM 132.
[0047] The monitoring logic 133 monitors the processing of the one or more VM1-VMK. In particular, the monitoring logic 133 may monitor the launching process of the object within the VMK and all changes to the file system 205 while the object is processing. In one embodiment, the monitoring logic 133 may track the processing of each application by the process identification (PID) of the application. The monitoring logic 133 may also monitor any effects processing the object may have on the operating system and application(s) 206.
[0048] The analysis logic 134 is configured to analyze changes to the file system 205 monitored by the monitoring logic 133 during the processing of the object by VMK. The analysis logic 134 may operate in conjunction with the monitoring logic 133, and compare one or more of (i) one or more changes to the file system 205 associated with a lure file, (ii) one or more changes to the file system 205 conducted within the VMK prior to the change associated with the lure file, and/or (iii) one or more changes to the file system 205 conducted within the VMK after the change associated with the lure file with one or more known file activity patterns. The comparison may determine the extent to which the actions associated with a lure file match one or more known file activity patterns. In one embodiment, actions associated with a lure file may include a singular change to the file system 205 associated with a lure file (e.g., copying of a lure file) and/or a series of changes to the file system 205 that are associated with the lure file (e.g., copying of a lure file, placement of the copy of the lure file, renaming of the copy of the lure file and encryption of the original lure file).
[0049] As shown, the monitoring logic 133 and the analysis logic 134 are included within the virtual run-time environment 131 wherein the monitoring logic 133 may monitor the processing and the analysis logic 134 may analyze the results of the processing within each of the VM1-VMK. In an alternative embodiment, although not shown, each of the VM1-VMK may include a separate instance of the monitoring logic 133 and/or the analysis logic 134. In such an embodiment, for example, an instance of the monitoring logic 133 (e.g., monitoring logic 1331) may monitor the processing within the VM1 and an instance of the analysis logic 134, (e.g., analysis logic 1341) may analyze the results of the processing within the VW1. Furthermore, an instance of the monitoring logic 133 (e.g., the monitoring logic 133K) may further monitor the processing within the VMK and an instance of the analysis logic 134 (e.g., analysis logic 1341) may analyze the results of the processing within the VMK.
[0050] The classification engine 140 may be configured to receive the static analysis results (e.g., results from a static analysis, metadata associated with the incoming network traffic, etc.) and/or the dynamic analysis results. According to one embodiment of the disclosure, the classification engine 140 comprises the prioritization logic 141 and the score determination logic 142. The prioritization logic 141 may be configured to apply weighting to results provided from dynamic analysis engine 130 and/or static analysis engine 120. The score determination logic 142 is configured to determine a probability (or level of confidence) that the document object is part of a malicious attack. More specifically, based on the dynamic analysis of the document object and one or more detected actions associated with one or more lure files, the score determination logic 142 generates a value that may be used, in part, to identify the likelihood that the object is part of a malicious attack, in particular, including file altering malware. Thereafter, the classification engine 140 may route classification results comprising the weighting and/or prioritization applied to the static analysis results and/or dynamic analysis results to the reporting engine 150. The classification results may include the classification of any malware detected into a family of malware, describe the malware and further include the metadata associated with any object(s) within which the malware were detected.
[0051] As shown in FIG. 1 , the reporting engine 150 includes an interface rendering logic 151, an alert generation logic 152 and a classification storage 153. The reporting engine 150 is adapted to receive information from the classification engine 140 and generate alerts 154 that identify to a user of an endpoint device, network administrator or an expert network analyst that the object is associated with a malicious attack. The alerts may include various types of messages, which may include text messages and/or email messages, video or audio stream, or other types of information over a wired or wireless communication path. The reporting engine 150 features an optional user interface 155 (e.g., touch pad, keyed inputs, etc.) for customization as to the reporting configuration. The interface rendering logic 151 is configured to render and generate one or more graphical user interfaces (GUIs) to enable, for example, a network administrator to configure the virtual run-time environment 131 through one or more configuration files, as will be discussed in detail below. In addition, the reporting engine 150 may store the classification results in the classification storage 153 for future reference.
[0052] Although FIG. 1 illustrates the TDP 1101 as a dedicated network device and the discussion of FIG. 1 explains examples based on an object received by the communication interface 111, the TDP 1101 may be implemented on an endpoint device. In such an embodiment, prior to actual execution of the object, the TDP 1101 may launch the object in a sandboxed environment and conduct simulated human interaction and simulated device controls. Responsive to non-anomalous behaviors by the object, the endpoint is allowed to utilize the object. In addition, the TDP 1101 may be implemented in the cloud computing services 105, where the below described simulated human and device control interactions may be fully or partially conducted therein.
[0053] Referring now to FIG. 2 , a block diagram of the dynamic analysis engine 130 within the TDP 1101 of FIG. 1 is shown. The dynamic analysis engine 130 includes a virtual run-time environment 131 that, as mentioned above, provides for the processing of an object through one or more VM1-VMK. As shown, the VMK may be provisioned with an installation logic 202, a configuration logic 203, a snapshot logic 204, a file system 205 and operating system (OS) and one or more applications 206. In addition, prior to beginning processing of the object, the VMK receives the object to analyze and a lure configuration file 200. In some embodiments, one or more lure files 2011-201N (N≧1). Alternatively, in one embodiment, when one or more lure files 2011-201N are not provided to the VMK, the installation logic 202 may generate the one or more lure files 2011-201N according to information included in the lure configuration file 200.
[0054] The lure files 2011-201N may be files of one or more various types that may be placed within the file system 205 in order to entice, or “lure,” malware, specifically file altering malware, to interact with one or more of the lure files 2011-201N. Examples of file types include, but are not limited or restricted to, Microsoft® Office documents/files, PDF documents, text files, help files such as a Microsoft® Compiled HTML Help file (CHM), Extensible Markup Language (XML) files, etc.). The lure files 2011-201N are placed within the file system 205 such that typical, non-anomalous processing by the operating and applications 206 does not result in an interaction with the lure files 2011-201N, or that an interaction is non-anomalous. For example, when the VMK is provisioned with Microsoft® Windows® XP operating system, one or more of the lure files 2011-201N may be placed among the Program Files on the “C: drive” (e.g., “C:\Program Files”). In such an example, it may be unlikely that the operating system and applications 206 would interact with the one or more lure files 2011-201N. Therefore, if an interaction with the lure files 2011-201N occurs, the interaction may be indicative of the presence of file altering malware.
[0055] Alternatively, an interaction with the one or more lure files 2011-201N placed among the “Program Files” on the “C: drive” may be occur in a non-anomalous manner. For example, a non-malicious file scanner and/or a non-malicious cryptor may interact with one or more of the files and/or folders located among the “Program Files” on the “C: drive.” Therefore, as will be discussed below, the dynamic processing of the one or more lure files 2011-201N includes an analysis of the changes to the file system 205 that are associated with the one or more lure files 2011-201N when determining whether the object is malicious (e.g., includes file altering malware).
[0056] The one or more lure files 2011-201N may include a specified file name, a pseudo-random file name or a random file name. The file name of each of the lure files 2011-201N is generated to entice malware such as file altering malware to interact with the one or more lure files 2011-201N. Similarly, the lure files 2011-201N may include specified content, no content, pseudo-randomized content or randomized content. In addition, the lure files 2011-201N may be encrypted and/or include a password protection system prior to processing per the information included in the lure configuration file 200, wherein the malware may be enticed by files that include one or more security measures.
[0057] The lure configuration file 200 includes configuration information associated with the one or more lure files 2011-201N and the file system 205. In one embodiment wherein, the lure files 2011-201N are not received by the VMK, the lure configuration file 200 includes information regarding attributes of the lure files 2011-201N such as, file-type, content-type, security measures to include with one or more of the lure files 2011-201N and placement location(s) for the one or more lure files 2011-201N within in the file system 205. The placement of the one or more lure files 2011-201N within the file system 205 will be described below in accordance with FIGS. 5A and 5B .
[0058] The file system 205 may be configured based on information included in the lure configuration file 200. For example, the lure configuration file 200 may include details of the file system of a particular endpoint device. In such an example, the file system 205 may be configured, prior to the processing of the object, to replicate the file system of the particular endpoint device thereby providing tailored detection of malware, specifically file altering malware.
[0059] The storage device 136 may store a snapshot of the file system 205, actions performed and events that occurred within the VMK, and one or more known file activity patterns of changes to the file system 205 caused by malware such as file altering malware.
[0060] Referring to FIG. 3 , an exemplary block diagram of logic associated with the TDP 1101 of FIG. 1 is shown. The TDP 1101 includes one or more processors 300 that are coupled to the communication interface logic 310 via a first transmission medium 320. Communication interface logic 310 enables communication with the TDPs 1102-1103 and management system 107 of FIG. 1 . According to one embodiment of the disclosure, the communication interface logic 310 may be implemented as a physical interface including one or more ports for wired connectors. Additionally, or in the alternative, communication interface logic 310 may be implemented with one or more radio units for supporting wireless communications with other network devices.
[0061] The one or more processors 300 are further coupled to the persistent storage 330 via the transmission medium 325. According to one embodiment of the disclosure, the persistent storage 330 may include (i) the static analysis engine 120 including the heuristics logic 121 and the signature matching logic 122; (ii) the virtual run-time environment including the VM1-VMK, the virtual machine manager (VMM) 132, the monitoring logic 133 and the analysis logic 134; (iii) the classification engine 140; and (iv) the reporting engine 150. Of course, when implemented as hardware (such as circuitry and/or programmable logic arrays), one or more of these logic units could be implemented separately from each other. In addition, one or more of these logic units may be implemented in hardware while one or more logic units may be implemented as software.
[0062] III. Operational Flow of the Threat Detection Platform
[0063] Referring to FIG. 4 , a flowchart illustrating an exemplary method for analyzing an object with the TDP 1101 of FIG. 1 is shown. Each block illustrated in FIG. 4 represents an operation performed in the method 400 of detecting malware based on the use of TDP 1101 of FIG. 1 wherein the object and a lure configuration file 200 are received by the TDP 1101 for processing. At block 401, the TDP 1101 receives the object to analyze and at block 402, the TDP 1101 receives the lure configuration file 200. At block 403, one or more lure files 2011-201N are placed in the file system 205 of the VMK within the TDP 1101 according to the contents of the lure configuration 200.
[0064] At block 404, the file names of the lure files 2011-201N are randomized (e.g., undergo random or pseudo-random operations) according to the lure configuration file 200. In addition, the information included in the lure configuration file 200 may also specify that the contents of the lure files 2011-201N are to be randomized or pseudo-randomized. At block 405, a snapshot of the file system 205 is taken to preserve the state of the file system 205 prior to processing. The snapshot is to be used in the analysis of changes to the file system 205 that are associated with one or more of the lure files 2011-201N during, or subsequent, to the processing of the object.
[0065] In one embodiment, the randomization of the lure file names is performed by the configuration logic 203 generating a hash value (e.g., MD5 hash) based on a time and date included in the lure configuration file 200. The hash value is provided to a random number generator function included within the configuration logic 203. The output of the random number generator may then be used to pseudo-randomize the names of the lure files 2011-201N. For example, if the output of the random number generator is “PO730,” the configuration logic 203 may pseudo-randomize the lure file name “Sensitive_Corporate_Financial_Matters.docx” to be “Sensitive_Corporate_Financial_MattersPO730.docx.” In one embodiment in which the lure file names are pseudo-randomized instead of completely randomized, the processing of the object in the VMK is done to entice the file altering malware to interact with the lure file based on, at least in part, the lure file name. As an additional note, the time and date information that is included in the configuration file 200 may not be the same for each of VM1-VMK. When each of VM1-VMK receives a different time and date, the random number generator of each of VM1-VMK will not generate the same random number because the hash value provided as an input to the random number generator of each of VM1-VMK will not be the same when the date and time are not the same for each of VM1-VMK.
[0066] At block 406, the received object is processed in the VMK and the processing is monitored for changes to the file system 205, specifically changes associated with one or more of the lure files 2011-201N. In particular, the object is “launched” using an application and actions typical of processing using the application on an endpoint device are performed. For example, the object may be a binary object such as an application (.APK), a batch file (.BAT), a command script (.CMD), an executable (.EXE, and/or .DLL) or the like. The monitoring logic 133 monitors any effects on the run-time environment within the VMK the processing of the object may have (e.g., changes to the file system 205 that are associated with one or more of the lure files 2011-201N).
[0067] At block 407, the changes to the file system 205 are analyzed by the analysis logic 134 to determine whether the object includes malware such as file altering malware. In one embodiment, the analysis logic 134 may retrieve one or more known file activity patterns of one or more changes to the file system 205 caused by file altering malware (hereinafter referred to as “known file activity patterns”) and compare the one or more known file activity patterns to the actions monitored by the monitoring logic 133. The analysis logic 134 may determine whether the changes to the file system 205 monitored in the VMK is involved or associated with one or more of the lure files 2011-201N match at least a portion of the one or more of the known file activity patterns.
[0068] The analysis of the processing of the object and the effects on the file system may be performed in a plurality of methods. In a first embodiment, the processing of the object in the VMK and the analysis by the analysis logic 134 may execute concurrently (wherein, the term “concurrently” should be interrupted as “at least partially overlapping at the same time”). For example, upon detection of an action interacting with one or more of the lure files 2011-201N, the analysis logic 134 may begin to compare actions prior to the interaction with the one or more of the lure files 2011-201N, the actual interaction with the one or more of the lure files 2011-201N, actions subsequent to the interaction with the one or more of the lure files 2011-201N and any effects on the file system 205. In one embodiment, the one or more lure files 2011-201N may include hooks that notify the monitoring logic 133 and the analysis logic 134 of any actions taken involving the one or more of the lure files 2011-201N.
[0069] In a second embodiment, the processing of the object may be completed (e.g., a predetermined number of actions were performed within the VMK, or the processing occurred for a predetermined amount of time) prior to analysis by the analysis logic 134. In such an embodiment, the snapshot of the file system 205 and the changes to the file system 205 monitored by the monitoring logic 133 may be stored in the storage device 136. Upon completion of the processing of the object, the analysis logic 134 may retrieve the known file activity patterns, the snapshot of the file system 205 and the changes to the file system 205 by the monitoring logic 133 and compare the state of the file system 205 after processing the object with the state of the file system 205 captured by the snapshot (e.g., analyze the changes made to the file system 205).
[0070] Additionally, as discussed above, the dynamic analysis results are provided to the classification engine wherein the dynamic analysis results may be combined with the static analysis results. Furthermore, when the object is determined to include malware such as file altering malware, the classification engine 140 may classify the malware by malware family based on experiential knowledge. For example, based on details of malware families stored within the storage device 113, the classification engine 140 may determine a threat level of the object based on the static analysis results and the dynamic results and determine the malware family of the file altering malware, when applicable.
[0071] Still referring to FIG. 4 , at block 408, when an object is determined to include file altering malware, an optional alert may be generated by the reporting engine 150 to notify one or more of a user of an endpoint device, a network administrator and/or an expert network analyst of the file altering malware included in the object and, if applicable, the family of malware to which the file altering malware belongs. Additionally, the results of the processing and classification may be stored within the classification storage 153 for future reference.
[0072] The method 400 illustrated in FIG. 4 may be divided into three phases: (A) an installation phase; (B) a configuration phase; and (C) a processing and analysis phase. Each of the phases will be discussed in detail below, in accordance with the discussion of FIGS. 5A-5C, 6A and 6B .
[0073] A. Installation Phase
[0074] Referring now to FIG. 5A , an illustration of an exemplary file system prior to placement of one or more lure files is shown. Herein, the example file system 500 includes a “Home Directory” folder 501 that includes a “My Documents” folder 502, a “My Pictures” folder 504, a “Confidential Matters” folder 505 and a “Music” folder 507. As is shown, the “My Documents” folder 502 includes a “Recipe.docx” file 503 and the “Confidential Matters” folder 505 includes a “Training.pptx” file 506.
[0075] Referring back to FIG. 2 , during the installation phase, the lure configuration file 200 is received by the VMK. Assuming the lure files 2011-201N are not received by the VMK and need to be generated, the installation logic 202 contains logic to analyze the lure configuration file 200 and determine (i) the number of lure files that are to be generated, (ii) the type of each lure file, (iii) the characteristics of each (e.g., contents, security measures, pseudo-randomization of file name, etc.), and (iv) the location in the file system 205 of each of the lure files to be generated. Further, the installation logic 202 may generate the lure files 2011-201N and place the lure files 2011-201N in the appropriate locations within the file system 205.
[0076] Referring now to FIG. 5B , an illustration of the exemplary file system of FIG. 5A following placement of the lure files 2011-201N (N=5 for this embodiment) is illustrated. Herein, the lure file 2011 is a PDF document titled “Bank_Statement.PDF,” the lure file 2012 is a Microsoft® Excel® file titled “Passwords.XLSX,” the lure file 2013 is a Microsoft® Excel® file titled “Passwords.XLSX,” the lure file 2014 is a Microsoft® Word® file titled “Top-Secret_Military_Plans.DOCX,” and the lure file 2015 is a PDF document titled “Tax_Return.PDF.” Although in the embodiment disclosed herein, the lure files 2011-5 are illustrated as “files,” a “lure file” may also be a folder itself that optionally includes one or more lure files.
[0077] B. Configuration Phase
[0078] During the configuration phase, the VMK may receive the object to analyze. Referring back to FIG. 2 , once the lure files 2011-201N are present within the VMK (whether they were received or generated therein), and placed in the appropriate locations within the file system 205, the file names may be randomized, or pseudo-randomized (in addition, the content may be randomized, or pseudo-randomized as well). By randomizing, or pseudo-randomizing, the file names, malware writers will be unable to merely identify a file by name that is routinely part of the file system that detects the malware. For example, when a malware writer attempts to determine that a detection system is being used to detect malware, the malware writer may attempt to identify a particular file name that is always present and thereby develop malware that avoids the particular file name. Therefore, by randomizing, or pseudo-randomizing, the file names of one or more of the lure files 2011-201N, detection by the malware that it is being processed in a VM becomes more difficult as a singular file name will not continually reoccur.
[0079] Referring to FIG. 5C , an illustration of the exemplary file system of FIG. 5B following the pseudo-randomization of the names of the lure files 2011-2015 is shown. Herein, the lure files 2011-2015 of the example file system 500 of FIG. 5B that were added to the file system 205 during the installation phase are seen to be configured with pseudo-randomized file names. Herein, the lure file 2011 is titled, “Bank_Statement_A2CF.PDF”; the lure file 2012 is titled, “Passwords_6LP2.XLSX”; the lure file 2013 is titled, “Passwords_20FB.XLSX”; the lure file 2014 is titled, “742_Top-Secret_Military_Plans.DOCX”; and the lure file 2015 is titled, “Tax_Return_084. PDF.”
[0080] C. Processing and Analysis Phase
[0081] Referring now to FIG. 6A , a flowchart illustrating a first exemplary method for analyzing a file system after processing an object with the TDP 1101 of FIG. 1 is shown. Each block illustrated in FIG. 6A represents an operation performed in the method 600A of processing the object based on the use of TDP 1101 wherein the processing of the object and the analysis of one or more changes to the file system 205 associated with one or more lure files are done concurrently. At block 601, the TDP 1101 begins processing the object in the VMK. At block 602, a determination is made as to whether a change to the file system 205 associated with a lure file is detected. When a change to the file system 205 is detected but the change is not associated with one or more of the lure files 2011-201N (no at block 602), a determination is made as to whether the processing is complete (block 603). When the processing is complete (e.g., and no change associated with a lure file was detected) (yes at block 603), a determination is made that the object does not include file altering malware (block 604).
[0082] When a change to the file system 205 associated with a lure file is detected (yes at block 602), the processing performs two concurrent steps: (1) at block 605, the processing of the object continues and the monitoring logic 133 continues to monitor for additional changes to the file system 205 associated with a lure file, and (2) the detected change associated with the lure file is monitored (block 606). Referring to (1), the processing of the object continues at block 605 and the method 600A subsequently returns to block 602 to determine whether a change to the file system 205 associated with a lure file is detected. Referring to (2), the detected change associated with the lure file is monitored (block 606) and, subsequently, a determination is made as to whether the detected change(s) associated with the one or more lure files matches one or more known file activity patterns (block 607).
[0083] When the one or more change to the file system 205 associated with the one or more lure files do not match one or more known file activity patterns (no at block 607), a determination is made as to whether the processing is complete (block 603) and, if so, it is determined that the object does not include file altering malware (block 604), or, if not (no at block 603), the processing continues at block 602.
[0084] Additionally, when one or more changes to the file system 205 that are associated with a lure file are not determined to match one or more known file activity patterns, the one or more changes to the file system 205 may be provided to, for example, an expert network analyst for further analysis. In such an instance, a new pattern may be developed if it is determined by the network analyst that the one or more changes to the file system 205 that did not match any known file activity patterns is a result of file altering malware. Alternatively, the change to the file system 205 that is associated with a lure file but does not match a known pattern may be the result of a non-malicious file scanner, a non-malicious encryption application and/or another non-malicious application.
[0085] When the one or more change to the file system 205 associated with the one or more lure files matches a known pattern (yes at block 607), a determination is made as to whether the object includes file altering malware based on the matched known pattern (block 608). At block 608, the analysis logic 134, operating in conjunction with the monitoring logic 133, compares one or more of (i) change to the file system 205 associated with a lure file, (ii) one or more changes to the file system 205 conducted within the VMK prior to the change associated with the lure file, and/or (iii) one or more changes to the file system 205 conducted within the VMK after the change associated with the lure file with the known pattern. The comparison may determine the extent to which the actions associated with a lure file match the known pattern. The comparison of the known pattern with the information associated with the detected change to the file system 205 may be included in the dynamic analysis results provided to the classification engine 140. In one embodiment, the dynamic analysis results may include, at least, one or more of: the extent to which one or more detected actions associated with a lure file match one or more known file activity patterns; information associated with the detected actions associated with a lure file; and/or metadata associated with the each detected action.
[0086] Subsequently, the score determination logic 142 may determine (i) a score for each detected change to the file system 205 and (ii) whether one or more of the scores exceeds a predetermined threshold wherein the predetermined threshold represents a threat level (e.g., “suspicious,” “malicious,” or “benign”). Alternatively, a score may be a certain threat level (e.g., “suspicious,” “malicious,” or “benign,” being an indication of the likelihood of including file altering malware) or a value that signifies a likelihood of including file altering malware that may be compared to one or more predefined thresholds to determine the likelihood of including file altering malware.
[0087] Optionally, when the object is determined to include file altering malware, the family of malware to which the object belongs may be determined (block 609). Herein, the classification logic 140 may compare the one or more changes to the file system 205 associated with the one or more lure files with information pertaining to malware families stored in, for example, the storage device 113. Finally, and also optionally, an alert may be generated to notify one or more of a user of an endpoint device, a network administrator and/or an expert network analyst of the detection of the inclusion of file altering malware within the object (block 610).
[0088] Referring now to FIG. 6B , a flowchart illustrating a second exemplary method for analyzing a file system after processing an object with the configuration of the TDP 1101 of FIG. 1 is shown. Each block illustrated in FIG. 6B represents an operation performed in the method 600B of processing an object based on the use of the TDP 1101 of FIG. 1 wherein the processing of the object is completed prior to the analysis of one or more changes to the file system 205 associated with one or more lure files. At block 620, a snapshot is taken of a configured file system that will be used to process the object, as discussed above. At block 621, the object is processed in the VMK until completion and changes to the file system 205 conducted during the processing (e.g., as monitored by the monitoring logic 133) are stored in a storage medium. At block 622, the state of the file system captured in the snapshot is compared with the state of the file system after processing the object (e.g., the changes made to the file system 205 during processing are analyzed to determine whether an interaction with one or more lure files occurred).
[0089] At block 623, a determination is made as to whether a change to the file system 205 caused an interaction with a lure file. When the action did not interact with a lure file (no at block 623), a determination is made as to whether all changes to the file system 205 that were detected and stored have been analyzed (block 625).
[0090] When all changes have not been analyzed (no at block 625), the next change detected during processing is analyzed (block 626). When all changes have been analyzed (i.e., and none of the analyses resulted in a determination that the object includes file altering malware) (yes at block 625), it is determined the object does not include file altering malware (block 627).
[0091] When a change involved an interaction with a lure file (yes at block 623), a determination is made as to whether the detected change(s) associated with the lure file match one or more known file activity patterns (block 624). When the change(s) associated with the lure file do not match one or more known file activity patterns (no at block 624), a determination is made as to whether all actions monitored and stored have been analyzed (at block 625), as discussed above.
[0092] Additionally, when one or more changes to the file system 205 that are associated with a lure file are not determined to match one or more known file activity patterns, the one or more changes to the file system 205 may be provided to, for example, an expert network analyst for further analysis. In such an instance, a new pattern may be developed if it is determined by the network analyst that the one or more changes to the file system 205 that did not match any known file activity patterns is a result of file altering malware. Alternatively, the change to the file system 205 that is associated with a lure file but does not match a known pattern may be the result of a non-malicious file scanner, a non-malicious cryptor and/or another non-malicious application.
[0093] When the one or more changes to the file system 205 associated with the one or more lure files match one or more known file activity patterns (yes at block 624), a determination is made as to whether the object includes file altering malware based on the match with one or more known file activity patterns (block 628). Subsequently, the dynamic analysis results may be provided to the classification engine 140 such that a determination as to whether the object includes file altering malware based on, at least, the dynamic analysis results can be made. For example, a score or threat level indicating the likelihood of the inclusion of file altering malware within the object may be determined by the score determination logic 142.
[0094] Optionally, a determination of the malware family to which the malware belongs may be made (block 629). Additionally, and also optionally, an alert may be generated detailing the detection of the file altering malware (block 630).
[0095] IV. Graphical User Interface Configuration
[0096] Referring now to FIG. 7 , an illustration of an exemplary graphical user interface associated with the configuration of the TDP 1101 of FIG. 1 is shown. Herein, rendered by the interface rendering logic 151, the display screen 700 features a plurality of display areas 7101-710P (P≧1, where P=3 for this embodiment) that illustrates information directed to configuring the file system 205 and the lure files 2011-201N prior to the dynamic analysis of one or more objects within one or more of VM1-VMK.
[0097] The display screen 700 may be rendered in order to enable, for example, a network administrator to configure one or more of the VM1-VMK. A network administrator may configure one or more of the VM1-VMK according to the specifications of the file system of the endpoint device(s), or the file system of an enterprise.
[0098] According to one embodiment of the disclosure, a first display area 7101 provides an option to include the directory path of the location to which the selected options of the display area 7101 are to apply. Assuming the TDP 1101 is to generate the lure files, the display area 7101 may provide a plurality of configurable options such as (i) an option to place content in the lure files, (ii) an option to randomize the content in the lure files, and (iii) the file type of the lure files. In addition, options to provide security measures may be provided (e.g., password protection and/or encryption). The display area 7101 may provide an option to use prepared lure files and one or more text boxes for the location of the one or more lure files 2011-201N. Finally, the display area 7101 may provide an option to specify one or more lure file names. Additional display areas 7102-710P may provide one or more of the same options or provide alternate options.
[0099] In the foregoing description, the invention is described with reference to specific exemplary embodiments thereof. It will, however, be evident that various modifications and changes may be made thereto without departing from the broader spirit and scope of the invention as set forth in the appended claims.
Claims
What is claimed is:
1. A system comprising:
one or more processors; and
a storage module communicatively coupled to the one or more processors, the storage module comprising logic that, upon execution by the one or more processors, performs operations comprising:
receiving configuration information that identifies at least one or more locations of a system operating within a virtual machine for placement of lure data in the system, the lure data being configured to entice interaction of the lure data by malware associated with an object under analysis,
placing the lure data within the system according to the configuration information,
subsequent to placing the lure data within the system, selectively modifying information associated with the lure data,
processing the object within the virtual machine, and
determining whether the object exhibits one or more behaviors that alter the lure data or a portion of the system based on a comparison of one or more actions performed while processing the object that are associated with the lure data and one more patterns that represent one or more changes to the system associated with the lure data caused by known malware.
2. The system of claim 1, wherein the placing of the lure data within the system comprises generating one or more lure files according to the configuration information and placing a lure file of the one or more lure files into the one or more locations of a file system being the system configured at least for data storage.
3. The system of claim 2, wherein the selectively modifying the information associated with the lure data comprises modifying a name of the lure file.
4. The system of claim 2, wherein the selectively modifying the information associated with the lure data comprises modifying content of (i) a directory within the file system, (ii) the content includes a sub-directory, (iii) a folder, or (iv) a file located within the directory.
5. The system of claim 2, wherein the logic further performs the operations including analyzing the configuration information including a lure configuration file and determining (i) a number of lure files to be generated, (ii) a type of each lure file of the one or more lure files, (iii) characteristics of each lure file of the one or more lure files, and (iv) a location in the file system for each of the one or more lure files.
6. The system of claim 2 further comprising:
prior to processing the object received from a network, capturing a snapshot of a state of the file system including the lure data having the selectively modified information.
7. The system of claim 6, wherein determining whether the object exhibits file altering behavior includes a comparison of the state of the file system captured in the snapshot and a state of the file system after beginning processing the object.
8. The system of claim 1, wherein the configuration information is part of a lure configuration file that includes configuration information associated with one or more lure files being part of the lure data and information associated with placement of the one or more lure files in the system operating as a file system.
9. The system of claim 1, wherein the selectively modifying of the information associated with the lure data comprises adding one or more characters to a name assigned to the lure data.
10. The system of claim 9, wherein the name of the lure data is modified into a pseudo-random name.
11. The system of claim 1, wherein the logic, prior to placing the lure data within the system, performs an operation of configuring the system to replicate a file system of a particular endpoint device.
12. The system of claim 1, wherein the system corresponds to one of a disk file systems, an optical disk file system, a flash file system, or a database file system.
13. The system of claim 1, wherein the lure data includes a lure file with one or more security measures being utilized to appear that contents of the lure file are being protected, the one or more security measures include encryption or password protection.
14. The system of claim 1, wherein the configuration information further includes at least one attribute of the lure data.
15. The system of claim 14, wherein the selectively modifying the information associated with the lure data comprises modifying an attribute of the at least one attribute of the lure data.
16. The system of claim 14, wherein the lure data is a lure file and the at least one attribute includes a name of the lure file.
17. A non-transitory computer readable medium that is executed by one or more hardware processors, the medium comprising:
a virtual machine installed with a file system, a configuration file, and one or more lure files;
a first software module that, upon execution by the one or more hardware processors, selectively modifies information associated with a lure file of the one or more lure files;
a second software module that, upon execution by the one or more hardware processors, processes an object received from a network within the virtual machine; and
a third software module that, upon execution by the one or more hardware processors, determines the object includes file altering malware when one or more actions performed while processing the object that are associated with the lure file match a known pattern.
18. The non-transitory computer readable medium of claim 17, wherein the first software module to selectively modify the information associated with the lure file by at least modifying a name of the lure file.
19. The non-transitory computer readable medium of claim 17, wherein the first software module to selectively modify the information associated with the lure file by at least modifying content of a directory within the file system, the content includes one of a sub-directory, a folder or a file located within the directory.
20. The non-transitory computer readable medium of claim 17, wherein the configuration file being used by the one or more hardware processors to determine (i) a number of lure files to be generated, and (ii) a location in the file system for each of the one or more lure files.
21. The non-transitory computer readable medium of claim 20, wherein the configuration file being further used by the one or more hardware processors to determine (iii) a type of each lure file of the one or more lure files, and (iv) characteristics of each lure file of the one or more lure files.
22. The non-transitory computer readable medium of claim 17 further comprising:
a snapshot of a state of the file system including the lure file having the selectively modified information.
23. The non-transitory computer readable medium of claim 22, wherein the third software module, upon execution by the one or more hardware processors, determines the object includes file altering malware upon a comparison of the state of the file system captured in the snapshot and a state of the file system after beginning processing of the object.
24. A computerized method, comprising:
receiving configuration information that identifies least one or more locations of a system configured at least for data storage that is operating within a virtual machine for placement of the lure data into the system, the lure data being configured to entice interaction of the lure data by malware associated with an object under analysis;
placing the lure data within the system according to the configuration information;
subsequent to placing the lure data within the system, selectively modifying information associated with the lure data;
processing the object within the virtual machine; and
determining whether the object exhibits one or more behaviors that alter (i) the lure data or (ii) a portion of the system based on a comparison of one or more actions performed while processing the object that are associated with the lure data and one more patterns that represent one or more system changes caused by known malware.
25. The computerized method of claim 24, wherein the placing of the lure data within the system comprises generating one or more lure files according to the configuration information and placing a lure file of the one or more lure files into the one or more locations of the system operating as a file system.
26. The computerized method of claim 25, wherein the selectively modifying of the information associated with the lure data comprises modifying a name of the lure file.
27. The computerized method of claim 25, wherein the selectively modifying of the information associated with the lure data comprises modifying content of a directory within the file system, the content includes a sub-directory, a folder or a file located within the directory.
28. The computerized method of claim 25, further comprising analyzing the configuration information including a lure configuration file and determining (i) a number of lure files to be generated, (ii) a type of each lure file of the one or more lure files, (iii) characteristics of each lure file of the one or more lure files, and (iv) a location in the file system for each of the one or more lure files.
29. The computerized method of claim 25 further comprising:
prior to processing the object received over a network, capturing a snapshot of a state of the file system including the lure data having the selectively modified information.
30. The computerized method of claim 29, wherein the determining whether the object exhibits file altering behavior includes a comparison of the state of the file system captured in the snapshot and a state of the file system after beginning processing the object.
31. The computerized method of claim 25, wherein the selectively modifying of the information associated with the lure data comprises adding one or more characters to a name assigned to the lure data.
32. The computerized method of claim 31, wherein the name of the lure data is modified into a pseudo-random name.
33. The computerized method of claim 24, wherein the logic, prior to placing the lure data within the system, performs an operation of configuring the system to replicate a file system of a particular endpoint device.
34. The computerized method of claim 24, wherein the lure data includes a lure file, the system includes a file system, and the system changes includes changes to the lure file that is associated with the file system.
35. The computerized method of claim 24, wherein the configuration information further includes at least one attribute of the lure data.
36. The computerized method of claim 35, wherein the selectively modifying the information associated with the lure data comprises modifying an attribute of the at least one attribute of the lure data.
37. The computerized method of claim 35, wherein the lure data is a lure file and the at least one attribute includes a name of the lure file.
Patent Citations (582)
| Patent | Date | Inventor | Cited By |
|---|---|---|---|
| US4292580(A) | 1981-09-01 | Ott et al. | Applicant |
| US5175732(A) | 1992-12-01 | Hendel et al. | Applicant |
| US5278901(A) | 1994-01-01 | Shieh et al. | Applicant |
| US5440723(A) | 1995-08-01 | Arnold et al. | Applicant |
| US5452442(A) | 1995-09-01 | Kephart | Applicant |
| US5490249(A) | 1996-02-01 | Miller | Applicant |
| US5657473(A) | 1997-08-01 | Killean et al. | Applicant |
| US5842002(A) | 1998-11-01 | Schnurer et al. | Applicant |
| US5889973(A) | 1999-03-01 | Moyer | Applicant |
| US5960170(A) | 1999-09-01 | Chen et al. | Applicant |
| US5978917(A) | 1999-11-01 | Chi | Applicant |
| US6088803(A) | 2000-07-01 | Tso et al. | Applicant |
| US6094677(A) | 2000-07-01 | Capek et al. | Applicant |
| US6108799(A) | 2000-08-01 | Boulay et al. | Applicant |
| US6154844(A) | 2000-11-01 | Touboul et al. | Applicant |
| US6269330(B1) | 2001-07-01 | Cidon et al. | Applicant |
| US6272641(B1) | 2001-08-01 | Ji | Applicant |
| US6279113(B1) | 2001-08-01 | Vaidya | Applicant |
| US6298445(B1) | 2001-10-01 | Shostack et al. | Applicant |
| US6357008(B1) | 2002-03-01 | Nachenberg | Applicant |
| US6424627(B1) | 2002-07-01 | Sørhaug et al. | Applicant |
| US6442696(B1) | 2002-08-01 | Wray et al. | Applicant |
| US6484315(B1) | 2002-11-01 | Ziese | Applicant |
| US6487666(B1) | 2002-11-01 | Shanklin et al. | Applicant |
| US6493756(B1) | 2002-12-01 | O'Brien et al. | Applicant |
| US6550012(B1) | 2003-04-01 | Villa et al. | Applicant |
| US6775657(B1) | 2004-08-01 | Baker | Applicant |
| US6831893(B1) | 2004-12-01 | Ben Nun et al. | Applicant |
| US6832367(B1) | 2004-12-01 | Choi et al. | Applicant |
| US6895550(B2) | 2005-05-01 | Kanchirayappa et al. | Applicant |
| US6898632(B2) | 2005-05-01 | Gordy et al. | Applicant |
| US6907396(B1) | 2005-06-01 | Muttik et al. | Applicant |
| US6941348(B2) | 2005-09-01 | Petry et al. | Applicant |
| US6971097(B1) | 2005-11-01 | Wallman | Applicant |
| US6981279(B1) | 2005-12-01 | Arnold et al. | Applicant |
| US7007107(B1) | 2006-02-01 | Ivchenko et al. | Applicant |
| US7028179(B2) | 2006-04-01 | Anderson et al. | Applicant |
| US7043757(B2) | 2006-05-01 | Hoefelmeyer et al. | Applicant |
| US7069316(B1) | 2006-06-01 | Gryaznov | Applicant |
| US7080407(B1) | 2006-07-01 | Zhao et al. | Applicant |
| US7080408(B1) | 2006-07-01 | Pak et al. | Applicant |
| US7093002(B2) | 2006-08-01 | Wolff et al. | Applicant |
| US7093239(B1) | 2006-08-01 | van der Made | Applicant |
| US7096498(B2) | 2006-08-01 | Judge | Applicant |
| US7100201(B2) | 2006-08-01 | Izatt | Applicant |
| US7107617(B2) | 2006-09-01 | Hursey et al. | Applicant |
| US7159149(B2) | 2007-01-01 | Spiegel et al. | Applicant |
| US7213260(B2) | 2007-05-01 | Judge | Applicant |
| US7231667(B2) | 2007-06-01 | Jordan | Applicant |
| US7240364(B1) | 2007-07-01 | Branscomb et al. | Applicant |
| US7240368(B1) | 2007-07-01 | Roesch et al. | Applicant |
| US7243371(B1) | 2007-07-01 | Kasper et al. | Applicant |
| US7249175(B1) | 2007-07-01 | Donaldson | Applicant |
| US7287278(B2) | 2007-10-01 | Liang | Applicant |
| US7308716(B2) | 2007-12-01 | Danford et al. | Applicant |
| US7328453(B2) | 2008-02-01 | Merkle, Jr. et al. | Applicant |
| US7346486(B2) | 2008-03-01 | Ivancic et al. | Applicant |
| US7356736(B2) | 2008-04-01 | Natvig | Applicant |
| US7386888(B2) | 2008-06-01 | Liang et al. | Applicant |
| US7392542(B2) | 2008-06-01 | Bucher | Applicant |
| US7418729(B2) | 2008-08-01 | Szor | Applicant |
| US7428300(B1) | 2008-09-01 | Drew et al. | Applicant |
| US7441272(B2) | 2008-10-01 | Durham et al. | Applicant |
| US7448084(B1) | 2008-11-01 | Apap et al. | Applicant |
| US7458098(B2) | 2008-11-01 | Judge et al. | Applicant |
| US7464404(B2) | 2008-12-01 | Carpenter et al. | Applicant |
| US7464407(B2) | 2008-12-01 | Nakae et al. | Applicant |
| US7467408(B1) | 2008-12-01 | O'Toole, Jr. | Applicant |
| US7478428(B1) | 2009-01-01 | Thomlinson | Applicant |
| US7480773(B1) | 2009-01-01 | Reed | Applicant |
| US7487543(B2) | 2009-02-01 | Arnold et al. | Applicant |
| US7496960(B1) | 2009-02-01 | Chen et al. | Applicant |
| US7496961(B2) | 2009-02-01 | Zimmer et al. | Applicant |
| US7519990(B1) | 2009-04-01 | Xie | Applicant |
| US7523493(B2) | 2009-04-01 | Liang et al. | Applicant |
| US7530104(B1) | 2009-05-01 | Thrower et al. | Applicant |
| US7540025(B2) | 2009-05-01 | Tzadikario | Applicant |
| US7565550(B2) | 2009-07-01 | Liang et al. | Applicant |
| US7568233(B1) | 2009-07-01 | Szor et al. | Applicant |
| US7584455(B2) | 2009-09-01 | Ball | Applicant |
| US7603715(B2) | 2009-10-01 | Costa et al. | Applicant |
| US7607171(B1) | 2009-10-01 | Marsden et al. | Applicant |
| US7639714(B2) | 2009-12-01 | Stolfo et al. | Applicant |
| US7644441(B2) | 2010-01-01 | Schmid et al. | Applicant |
| US7657419(B2) | 2010-02-01 | van der Made | Applicant |
| US7676841(B2) | 2010-03-01 | Sobchuk et al. | Applicant |
| US7698548(B2) | 2010-04-01 | Shelest et al. | Applicant |
| US7707633(B2) | 2010-04-01 | Danford et al. | Applicant |
| US7712136(B2) | 2010-05-01 | Sprosts et al. | Applicant |
| US7730011(B1) | 2010-06-01 | Deninger et al. | Applicant |
| US7739740(B1) | 2010-06-01 | Nachenberg et al. | Applicant |
| US7779463(B2) | 2010-08-01 | Stolfo et al. | Applicant |
| US7784097(B1) | 2010-08-01 | Stolfo et al. | Applicant |
| US7832008(B1) | 2010-11-01 | Kraemer | Applicant |
| US7836502(B1) | 2010-11-01 | Zhao et al. | Applicant |
| US7849506(B1) | 2010-12-01 | Dansey et al. | Applicant |
| US7854007(B2) | 2010-12-01 | Sprosts et al. | Applicant |
| US7869073(B2) | 2011-01-01 | Oshima | Applicant |
| US7877803(B2) | 2011-01-01 | Enstone et al. | Applicant |
| US7904959(B2) | 2011-03-01 | Sidiroglou et al. | Applicant |
| US7908660(B2) | 2011-03-01 | Bahl | Applicant |
| US7930738(B1) | 2011-04-01 | Petersen | Applicant |
| US7937761(B1) | 2011-05-01 | Bennett | Applicant |
| US7949849(B2) | 2011-05-01 | Lowe et al. | Applicant |
| US7996556(B2) | 2011-08-01 | Raghavan et al. | Applicant |
| US7996836(B1) | 2011-08-01 | McCorkendale et al. | Applicant |
| US7996904(B1) | 2011-08-01 | Chiueh et al. | Applicant |
| US7996905(B2) | 2011-08-01 | Arnold et al. | Applicant |
| US8006305(B2) | 2011-08-01 | Aziz | Applicant |
| US8010667(B2) | 2011-08-01 | Zhang et al. | Applicant |
| US8020206(B2) | 2011-09-01 | Hubbard et al. | Applicant |
| US8028338(B1) | 2011-09-01 | Schneider et al. | Applicant |
| US8042184(B1) | 2011-10-01 | Batenin | Applicant |
| US8045094(B2) | 2011-10-01 | Teragawa | Applicant |
| US8045458(B2) | 2011-10-01 | Alperovitch et al. | Applicant |
| US8069484(B2) | 2011-11-01 | McMillan et al. | Applicant |
| US8087086(B1) | 2011-12-01 | Lai et al. | Applicant |
| US8171553(B2) | 2012-05-01 | Aziz et al. | Applicant |
| US8176049(B2) | 2012-05-01 | Deninger et al. | Applicant |
| US8176480(B1) | 2012-05-01 | Spertus | Applicant |
| US8201072(B2) | 2012-06-01 | Matulic | Applicant |
| US8201246(B1) | 2012-06-01 | Wu et al. | Applicant |
| US8204984(B1) | 2012-06-01 | Aziz et al. | Applicant |
| US8214905(B1) | 2012-07-01 | Doukhvalov et al. | Applicant |
| US8220055(B1) | 2012-07-01 | Kennedy | Applicant |
| US8225288(B2) | 2012-07-01 | Miller et al. | Applicant |
| US8225373(B2) | 2012-07-01 | Kraemer | Applicant |
| US8233882(B2) | 2012-07-01 | Rogel | Applicant |
| US8234640(B1) | 2012-07-01 | Fitzgerald et al. | Applicant |
| US8234709(B2) | 2012-07-01 | Viljoen et al. | Applicant |
| US8239944(B1) | 2012-08-01 | Nachenberg et al. | Applicant |
| US8260914(B1) | 2012-09-01 | Ranjan | Applicant |
| US8266091(B1) | 2012-09-01 | Gubin et al. | Applicant |
| US8286251(B2) | 2012-10-01 | Eker et al. | Applicant |
| US8291198(B2) | 2012-10-01 | Mott et al. | Applicant |
| US8291499(B2) | 2012-10-01 | Aziz et al. | Applicant |
| US8307435(B1) | 2012-11-01 | Mann et al. | Applicant |
| US8307443(B2) | 2012-11-01 | Wang et al. | Applicant |
| US8312545(B2) | 2012-11-01 | Tuvell et al. | Applicant |
| US8321240(B2) | 2012-11-01 | Lorsch | Applicant |
| US8321936(B1) | 2012-11-01 | Green et al. | Applicant |
| US8321941(B2) | 2012-11-01 | Tuvell et al. | Applicant |
| US8332571(B1) | 2012-12-01 | Edwards, Sr. | Applicant |
| US8365286(B2) | 2013-01-01 | Poston | Applicant |
| US8365297(B1) | 2013-01-01 | Parshin et al. | Applicant |
| US8370938(B1) | 2013-02-01 | Daswani et al. | Applicant |
| US8370939(B2) | 2013-02-01 | Zaitsev et al. | Applicant |
| US8375444(B2) | 2013-02-01 | Aziz et al. | Applicant |
| US8381299(B2) | 2013-02-01 | Stolfo et al. | Applicant |
| US8402529(B1) | 2013-03-01 | Green et al. | Applicant |
| US8464340(B2) | 2013-06-01 | Ahn et al. | Applicant |
| US8479174(B2) | 2013-07-01 | Chiriac | Applicant |
| US8479276(B1) | 2013-07-01 | Vaystikh et al. | Applicant |
| US8479291(B1) | 2013-07-01 | Bodke | Applicant |
| US8510827(B1) | 2013-08-01 | Leake et al. | Applicant |
| US8510828(B1) | 2013-08-01 | Guo et al. | Applicant |
| US8510842(B2) | 2013-08-01 | Amit et al. | Applicant |
| US8516478(B1) | 2013-08-01 | Edwards et al. | Applicant |
| US8516590(B1) | 2013-08-01 | Ranadive et al. | Applicant |
| US8516593(B2) | 2013-08-01 | Aziz | Applicant |
| US8522348(B2) | 2013-08-01 | Chen et al. | Applicant |
| US8528086(B1) | 2013-09-01 | Aziz | Applicant |
| US8533824(B2) | 2013-09-01 | Hutton et al. | Applicant |
| US8539582(B1) | 2013-09-01 | Aziz et al. | Applicant |
| US8549638(B2) | 2013-10-01 | Aziz | Applicant |
| US8555391(B1) | 2013-10-01 | Demir et al. | Applicant |
| US8561177(B1) | 2013-10-01 | Aziz et al. | Applicant |
| US8566946(B1) | 2013-10-01 | Aziz et al. | Applicant |
| US8584094(B2) | 2013-11-01 | Dadhia et al. | Applicant |
| US8584234(B1) | 2013-11-01 | Sobel et al. | Applicant |
| US8584239(B2) | 2013-11-01 | Aziz et al. | Applicant |
| US8595834(B2) | 2013-11-01 | Xie et al. | Applicant |
| US8627476(B1) | 2014-01-01 | Satish et al. | Applicant |
| US8635696(B1) | 2014-01-01 | Aziz | Applicant |
| US8682054(B2) | 2014-03-01 | Xue et al. | Applicant |
| US8682812(B1) | 2014-03-01 | Ranjan | Applicant |
| US8689333(B2) | 2014-04-01 | Aziz | Applicant |
| US8695096(B1) | 2014-04-01 | Zhang | Applicant |
| US8713631(B1) | 2014-04-01 | Pavlyushchik | Applicant |
| US8713681(B2) | 2014-04-01 | Silberman et al. | Applicant |
| US8726392(B1) | 2014-05-01 | McCorkendale et al. | Applicant |
| US8739280(B2) | 2014-05-01 | Chess et al. | Applicant |
| US8776229(B1) | 2014-07-01 | Aziz | Applicant |
| US8782792(B1) | 2014-07-01 | Bodke | Examiner |
| US8789172(B2) | 2014-07-01 | Stolfo | Examiner |
| US8789178(B2) | 2014-07-01 | Kejriwal et al. | Applicant |
| US8793787(B2) | 2014-07-01 | Ismael | Examiner |
| US8805947(B1) | 2014-08-01 | Kuzkin et al. | Applicant |
| US8806647(B1) | 2014-08-01 | Daswani et al. | Applicant |
| US8832829(B2) | 2014-09-01 | Manni et al. | Applicant |
| US8850570(B1) | 2014-09-01 | Ramzan | Applicant |
| US8850571(B2) | 2014-09-01 | Staniford | Examiner |
| US8881234(B2) | 2014-11-01 | Narasimhan et al. | Applicant |
| US8881282(B1) | 2014-11-01 | Aziz et al. | Applicant |
| US8898788(B1) | 2014-11-01 | Aziz et al. | Applicant |
| US8935779(B2) | 2015-01-01 | Manni et al. | Applicant |
| US8959428(B2) | 2015-02-01 | Majidian | Applicant |
| US8984638(B1) | 2015-03-01 | Aziz et al. | Applicant |
| US8990939(B2) | 2015-03-01 | Staniford et al. | Applicant |
| US8990944(B1) | 2015-03-01 | Singh et al. | Applicant |
| US8997219(B2) | 2015-03-01 | Staniford et al. | Applicant |
| US9009822(B1) | 2015-04-01 | Ismael et al. | Applicant |
| US9009823(B1) | 2015-04-01 | Ismael et al. | Applicant |
| US9027135(B1) | 2015-05-01 | Aziz | Applicant |
| US9071638(B1) | 2015-06-01 | Aziz et al. | Applicant |
| US9104867(B1) | 2015-08-01 | Thioux et al. | Applicant |
| US9106694(B2) | 2015-08-01 | Aziz et al. | Applicant |
| US9118715(B2) | 2015-08-01 | Staniford et al. | Applicant |
| US9159035(B1) | 2015-10-01 | Ismael et al. | Applicant |
| US9171160(B2) | 2015-10-01 | Vincent et al. | Applicant |
| US9176843(B1) | 2015-11-01 | Ismael et al. | Applicant |
| US9189627(B1) | 2015-11-01 | Islam | Applicant |
| US9195829(B1) | 2015-11-01 | Goradia et al. | Applicant |
| US9197664(B1) | 2015-11-01 | Aziz et al. | Applicant |
| US9223972(B1) | 2015-12-01 | Vincent et al. | Applicant |
| US9225740(B1) | 2015-12-01 | Ismael et al. | Applicant |
| US9241010(B1) | 2016-01-01 | Bennett et al. | Applicant |
| US9251343(B1) | 2016-02-01 | Vincent et al. | Applicant |
| US9262635(B2) | 2016-02-01 | Paithane et al. | Applicant |
| US9282109(B1) | 2016-03-01 | Aziz et al. | Applicant |
| US9294501(B2) | 2016-03-01 | Mesdaq et al. | Applicant |
| US9300686(B2) | 2016-03-01 | Pidathala et al. | Applicant |
| US9306960(B1) | 2016-04-01 | Aziz | Applicant |
| US9306974(B1) | 2016-04-01 | Aziz et al. | Applicant |
| US9311479(B1) | 2016-04-01 | Manni et al. | Applicant |
| US2001/0005889(A1) | 2001-06-01 | Albrecht | Applicant |
| US2001/0047326(A1) | 2001-11-01 | Broadbent et al. | Applicant |
| US2002/0018903(A1) | 2002-02-01 | Kokubo et al. | Applicant |
| US2002/0038430(A1) | 2002-03-01 | Edwards et al. | Applicant |
| US2002/0091819(A1) | 2002-07-01 | Melchione et al. | Applicant |
| US2002/0095607(A1) | 2002-07-01 | Lin-Hendel | Applicant |
| US2002/0116627(A1) | 2002-08-01 | Tarbotton et al. | Applicant |
| US2002/0144156(A1) | 2002-10-01 | Copeland | Applicant |
| US2002/0162015(A1) | 2002-10-01 | Tang | Applicant |
| US2002/0166063(A1) | 2002-11-01 | Lachman et al. | Applicant |
| US2002/0169952(A1) | 2002-11-01 | DiSanto et al. | Applicant |
| US2002/0184528(A1) | 2002-12-01 | Shevenell et al. | Applicant |
| US2002/0188887(A1) | 2002-12-01 | Largman et al. | Applicant |
| US2002/0194490(A1) | 2002-12-01 | Halperin et al. | Applicant |
| US2003/0074578(A1) | 2003-04-01 | Ford et al. | Applicant |
| US2003/0084318(A1) | 2003-05-01 | Schertz | Applicant |
| US2003/0101381(A1) | 2003-05-01 | Mateev et al. | Applicant |
| US2003/0115483(A1) | 2003-06-01 | Liang | Applicant |
| US2003/0188190(A1) | 2003-10-01 | Aaron et al. | Applicant |
| US2003/0191957(A1) | 2003-10-01 | Hypponen et al. | Applicant |
| US2003/0200460(A1) | 2003-10-01 | Morota et al. | Applicant |
| US2003/0212902(A1) | 2003-11-01 | van der Made | Applicant |
| US2003/0229801(A1) | 2003-12-01 | Kouznetsov et al. | Applicant |
| US2003/0237000(A1) | 2003-12-01 | Denton et al. | Applicant |
| US2004/0003323(A1) | 2004-01-01 | Bennett et al. | Applicant |
| US2004/0015712(A1) | 2004-01-01 | Szor | Applicant |
| US2004/0019832(A1) | 2004-01-01 | Arnold et al. | Applicant |
| US2004/0047356(A1) | 2004-03-01 | Bauer | Applicant |
| US2004/0083408(A1) | 2004-04-01 | Spiegel et al. | Applicant |
| US2004/0088581(A1) | 2004-05-01 | Brawn et al. | Applicant |
| US2004/0093513(A1) | 2004-05-01 | Cantrell et al. | Applicant |
| US2004/0111531(A1) | 2004-06-01 | Staniford et al. | Applicant |
| US2004/0117478(A1) | 2004-06-01 | Triulzi et al. | Applicant |
| US2004/0117624(A1) | 2004-06-01 | Brandt et al. | Applicant |
| US2004/0128355(A1) | 2004-07-01 | Chao et al. | Applicant |
| US2004/0128529(A1) | 2004-07-01 | Blake | Examiner |
| US2004/0165588(A1) | 2004-08-01 | Pandya | Applicant |
| US2004/0236963(A1) | 2004-11-01 | Danford et al. | Applicant |
| US2004/0243349(A1) | 2004-12-01 | Greifeneder et al. | Applicant |
| US2004/0249911(A1) | 2004-12-01 | Alkhatib et al. | Applicant |
| US2004/0255161(A1) | 2004-12-01 | Cavanaugh | Applicant |
| US2004/0268147(A1) | 2004-12-01 | Wiederin et al. | Applicant |
| US2005/0005159(A1) | 2005-01-01 | Oliphant | Applicant |
| US2005/0021740(A1) | 2005-01-01 | Bar et al. | Applicant |
| US2005/0033960(A1) | 2005-02-01 | Vialen et al. | Applicant |
| US2005/0033989(A1) | 2005-02-01 | Poletto et al. | Applicant |
| US2005/0050148(A1) | 2005-03-01 | Mohammadioun et al. | Applicant |
| US2005/0086523(A1) | 2005-04-01 | Zimmer et al. | Applicant |
| US2005/0091513(A1) | 2005-04-01 | Mitomo et al. | Applicant |
| US2005/0091533(A1) | 2005-04-01 | Omote et al. | Applicant |
| US2005/0091652(A1) | 2005-04-01 | Ross et al. | Applicant |
| US2005/0108562(A1) | 2005-05-01 | Khazan et al. | Applicant |
| US2005/0114663(A1) | 2005-05-01 | Cornell et al. | Applicant |
| US2005/0125195(A1) | 2005-06-01 | Brendel | Applicant |
| US2005/0149726(A1) | 2005-07-01 | Joshi et al. | Applicant |
| US2005/0157662(A1) | 2005-07-01 | Bingham et al. | Applicant |
| US2005/0183143(A1) | 2005-08-01 | Anderholm et al. | Applicant |
| US2005/0201297(A1) | 2005-09-01 | Peikari | Applicant |
| US2005/0210533(A1) | 2005-09-01 | Copeland et al. | Applicant |
| US2005/0238005(A1) | 2005-10-01 | Chen et al. | Applicant |
| US2005/0240781(A1) | 2005-10-01 | Gassoway | Applicant |
| US2005/0262562(A1) | 2005-11-01 | Gassoway | Applicant |
| US2005/0265331(A1) | 2005-12-01 | Stolfo | Applicant |
| US2005/0283839(A1) | 2005-12-01 | Cowburn | Applicant |
| US2006/0010495(A1) | 2006-01-01 | Cohen et al. | Applicant |
| US2006/0015416(A1) | 2006-01-01 | Hoffman et al. | Applicant |
| US2006/0015715(A1) | 2006-01-01 | Anderson | Applicant |
| US2006/0015747(A1) | 2006-01-01 | Van de Ven | Applicant |
| US2006/0021029(A1) | 2006-01-01 | Brickell et al. | Applicant |
| US2006/0021054(A1) | 2006-01-01 | Costa et al. | Applicant |
| US2006/0031476(A1) | 2006-02-01 | Mathes et al. | Applicant |
| US2006/0047665(A1) | 2006-03-01 | Neil | Applicant |
| US2006/0070130(A1) | 2006-03-01 | Costea et al. | Applicant |
| US2006/0075496(A1) | 2006-04-01 | Carpenter et al. | Applicant |
| US2006/0095968(A1) | 2006-05-01 | Portolani et al. | Applicant |
| US2006/0101516(A1) | 2006-05-01 | Sudaharan et al. | Applicant |
| US2006/0101517(A1) | 2006-05-01 | Banzhof et al. | Applicant |
| US2006/0117385(A1) | 2006-06-01 | Mester et al. | Applicant |
| US2006/0123477(A1) | 2006-06-01 | Raghavan et al. | Applicant |
| US2006/0143709(A1) | 2006-06-01 | Brooks et al. | Applicant |
| US2006/0150249(A1) | 2006-07-01 | Gassen et al. | Applicant |
| US2006/0161983(A1) | 2006-07-01 | Cothrell et al. | Applicant |
| US2006/0161987(A1) | 2006-07-01 | Levy-Yurista | Applicant |
| US2006/0161989(A1) | 2006-07-01 | Reshef et al. | Applicant |
| US2006/0164199(A1) | 2006-07-01 | Gilde et al. | Applicant |
| US2006/0173992(A1) | 2006-08-01 | Weber et al. | Applicant |
| US2006/0179147(A1) | 2006-08-01 | Tran et al. | Applicant |
| US2006/0184632(A1) | 2006-08-01 | Marino et al. | Applicant |
| US2006/0190561(A1) | 2006-08-01 | Conboy et al. | Applicant |
| US2006/0191010(A1) | 2006-08-01 | Benjamin | Applicant |
| US2006/0221956(A1) | 2006-10-01 | Narayan et al. | Applicant |
| US2006/0236393(A1) | 2006-10-01 | Kramer et al. | Applicant |
| US2006/0242709(A1) | 2006-10-01 | Seinfeld et al. | Applicant |
| US2006/0248519(A1) | 2006-11-01 | Jaeger et al. | Applicant |
| US2006/0248582(A1) | 2006-11-01 | Panjwani et al. | Applicant |
| US2006/0251104(A1) | 2006-11-01 | Koga | Applicant |
| US2006/0288417(A1) | 2006-12-01 | Bookbinder et al. | Applicant |
| US2007/0006288(A1) | 2007-01-01 | Mayfield et al. | Applicant |
| US2007/0006313(A1) | 2007-01-01 | Porras et al. | Applicant |
| US2007/0011174(A1) | 2007-01-01 | Takaragi et al. | Applicant |
| US2007/0016951(A1) | 2007-01-01 | Piccard et al. | Applicant |
| US2007/0033645(A1) | 2007-02-01 | Jones | Applicant |
| US2007/0038943(A1) | 2007-02-01 | FitzGerald et al. | Applicant |
| US2007/0064689(A1) | 2007-03-01 | Shin et al. | Applicant |
| US2007/0074169(A1) | 2007-03-01 | Chess et al. | Applicant |
| US2007/0094730(A1) | 2007-04-01 | Bhikkaji et al. | Applicant |
| US2007/0101435(A1) | 2007-05-01 | Konanka et al. | Applicant |
| US2007/0128855(A1) | 2007-06-01 | Cho et al. | Applicant |
| US2007/0142030(A1) | 2007-06-01 | Sinha et al. | Applicant |
| US2007/0143827(A1) | 2007-06-01 | Nicodemus et al. | Applicant |
| US2007/0156895(A1) | 2007-07-01 | Vuong | Applicant |
| US2007/0157180(A1) | 2007-07-01 | Tillmann et al. | Applicant |
| US2007/0157306(A1) | 2007-07-01 | Elrod et al. | Applicant |
| US2007/0168988(A1) | 2007-07-01 | Eisner et al. | Applicant |
| US2007/0171824(A1) | 2007-07-01 | Ruello et al. | Applicant |
| US2007/0174915(A1) | 2007-07-01 | Gribble et al. | Applicant |
| US2007/0192500(A1) | 2007-08-01 | Lum | Applicant |
| US2007/0192858(A1) | 2007-08-01 | Lum | Applicant |
| US2007/0198275(A1) | 2007-08-01 | Malden et al. | Applicant |
| US2007/0208822(A1) | 2007-09-01 | Wang et al. | Applicant |
| US2007/0220607(A1) | 2007-09-01 | Sprosts et al. | Applicant |
| US2007/0240218(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0240219(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0240220(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0240222(A1) | 2007-10-01 | Tuvell et al. | Applicant |
| US2007/0250930(A1) | 2007-10-01 | Aziz et al. | Applicant |
| US2007/0256132(A2) | 2007-11-01 | Oliphant | Applicant |
| US2007/0271446(A1) | 2007-11-01 | Nakamura | Applicant |
| US2007/0289015(A1) | 2007-12-01 | Repasi | Examiner |
| US2008/0005782(A1) | 2008-01-01 | Aziz | Applicant |
| US2008/0028463(A1) | 2008-01-01 | Dagon et al. | Applicant |
| US2008/0040710(A1) | 2008-02-01 | Chiriac | Applicant |
| US2008/0046781(A1) | 2008-02-01 | Childs et al. | Applicant |
| US2008/0066179(A1) | 2008-03-01 | Liu | Applicant |
| US2008/0072326(A1) | 2008-03-01 | Danford et al. | Applicant |
| US2008/0077793(A1) | 2008-03-01 | Tan et al. | Applicant |
| US2008/0080518(A1) | 2008-04-01 | Hoeflin et al. | Applicant |
| US2008/0086720(A1) | 2008-04-01 | Lekel | Applicant |
| US2008/0098476(A1) | 2008-04-01 | Syversen | Applicant |
| US2008/0120722(A1) | 2008-05-01 | Sima et al. | Applicant |
| US2008/0134178(A1) | 2008-06-01 | Fitzgerald et al. | Applicant |
| US2008/0134334(A1) | 2008-06-01 | Kim et al. | Applicant |
| US2008/0141376(A1) | 2008-06-01 | Clausen et al. | Applicant |
| US2008/0181227(A1) | 2008-07-01 | Todd | Applicant |
| US2008/0184367(A1) | 2008-07-01 | McMillan et al. | Applicant |
| US2008/0184373(A1) | 2008-07-01 | Traut et al. | Applicant |
| US2008/0189787(A1) | 2008-08-01 | Arnold et al. | Applicant |
| US2008/0201778(A1) | 2008-08-01 | Guo et al. | Applicant |
| US2008/0209557(A1) | 2008-08-01 | Herley et al. | Applicant |
| US2008/0215742(A1) | 2008-09-01 | Goldszmidt et al. | Applicant |
| US2008/0222729(A1) | 2008-09-01 | Chen et al. | Applicant |
| US2008/0263665(A1) | 2008-10-01 | Ma et al. | Applicant |
| US2008/0295172(A1) | 2008-11-01 | Bohacek | Applicant |
| US2008/0301810(A1) | 2008-12-01 | Lehane et al. | Applicant |
| US2008/0307524(A1) | 2008-12-01 | Singh et al. | Applicant |
| US2008/0313738(A1) | 2008-12-01 | Enderby | Applicant |
| US2008/0320594(A1) | 2008-12-01 | Jiang | Applicant |
| US2009/0003317(A1) | 2009-01-01 | Kasralikar et al. | Applicant |
| US2009/0007100(A1) | 2009-01-01 | Field et al. | Applicant |
| US2009/0013408(A1) | 2009-01-01 | Schipka | Applicant |
| US2009/0031423(A1) | 2009-01-01 | Liu et al. | Applicant |
| US2009/0036111(A1) | 2009-02-01 | Danford et al. | Applicant |
| US2009/0037835(A1) | 2009-02-01 | Goldman | Applicant |
| US2009/0044024(A1) | 2009-02-01 | Oberheide et al. | Applicant |
| US2009/0044274(A1) | 2009-02-01 | Budko et al. | Applicant |
| US2009/0064332(A1) | 2009-03-01 | Porras et al. | Applicant |
| US2009/0077666(A1) | 2009-03-01 | Chen et al. | Applicant |
| US2009/0083369(A1) | 2009-03-01 | Marmor | Applicant |
| US2009/0083855(A1) | 2009-03-01 | Apap et al. | Applicant |
| US2009/0089879(A1) | 2009-04-01 | Wang et al. | Applicant |
| US2009/0094697(A1) | 2009-04-01 | Provos et al. | Applicant |
| US2009/0113425(A1) | 2009-04-01 | Ports et al. | Applicant |
| US2009/0125976(A1) | 2009-05-01 | Wassermann et al. | Applicant |
| US2009/0126015(A1) | 2009-05-01 | Monastyrsky et al. | Applicant |
| US2009/0126016(A1) | 2009-05-01 | Sobko et al. | Applicant |
| US2009/0133125(A1) | 2009-05-01 | Choi et al. | Applicant |
| US2009/0144823(A1) | 2009-06-01 | Lamastra et al. | Applicant |
| US2009/0158430(A1) | 2009-06-01 | Borders | Applicant |
| US2009/0172815(A1) | 2009-07-01 | Gu et al. | Applicant |
| US2009/0187992(A1) | 2009-07-01 | Poston | Applicant |
| US2009/0193293(A1) | 2009-07-01 | Stolfo et al. | Applicant |
| US2009/0198651(A1) | 2009-08-01 | Shiffer et al. | Applicant |
| US2009/0198670(A1) | 2009-08-01 | Shiffer et al. | Applicant |
| US2009/0198689(A1) | 2009-08-01 | Frazier et al. | Applicant |
| US2009/0199274(A1) | 2009-08-01 | Frazier et al. | Applicant |
| US2009/0199296(A1) | 2009-08-01 | Xie et al. | Applicant |
| US2009/0228233(A1) | 2009-09-01 | Anderson et al. | Applicant |
| US2009/0241187(A1) | 2009-09-01 | Troyansky | Applicant |
| US2009/0241190(A1) | 2009-09-01 | Todd et al. | Applicant |
| US2009/0265692(A1) | 2009-10-01 | Godefroid et al. | Applicant |
| US2009/0271867(A1) | 2009-10-01 | Zhang | Applicant |
| US2009/0300415(A1) | 2009-12-01 | Zhang et al. | Applicant |
| US2009/0300761(A1) | 2009-12-01 | Park et al. | Applicant |
| US2009/0328185(A1) | 2009-12-01 | Berg et al. | Applicant |
| US2009/0328221(A1) | 2009-12-01 | Blumfield et al. | Applicant |
| US2010/0005146(A1) | 2010-01-01 | Drako et al. | Applicant |
| US2010/0011205(A1) | 2010-01-01 | McKenna | Applicant |
| US2010/0017546(A1) | 2010-01-01 | Poo et al. | Applicant |
| US2010/0030996(A1) | 2010-02-01 | Butler, II | Applicant |
| US2010/0031353(A1) | 2010-02-01 | Thomas et al. | Applicant |
| US2010/0037314(A1) | 2010-02-01 | Perdisci et al. | Applicant |
| US2010/0043073(A1) | 2010-02-01 | Kuwamura | Applicant |
| US2010/0054278(A1) | 2010-03-01 | Stolfo et al. | Applicant |
| US2010/0058474(A1) | 2010-03-01 | Hicks | Applicant |
| US2010/0064044(A1) | 2010-03-01 | Nonoyama | Applicant |
| US2010/0077481(A1) | 2010-03-01 | Polyakov et al. | Applicant |
| US2010/0083376(A1) | 2010-04-01 | Pereira et al. | Applicant |
| US2010/0115621(A1) | 2010-05-01 | Staniford et al. | Applicant |
| US2010/0132038(A1) | 2010-05-01 | Zaitsev | Applicant |
| US2010/0154056(A1) | 2010-06-01 | Smith et al. | Applicant |
| US2010/0180344(A1) | 2010-07-01 | Malyshev et al. | Applicant |
| US2010/0192057(A1) | 2010-07-01 | Majidian | Applicant |
| US2010/0192223(A1) | 2010-07-01 | Ismael et al. | Applicant |
| US2010/0220863(A1) | 2010-09-01 | Dupaquis et al. | Applicant |
| US2010/0235831(A1) | 2010-09-01 | Dittmer | Applicant |
| US2010/0251104(A1) | 2010-09-01 | Massand | Applicant |
| US2010/0275210(A1) | 2010-10-01 | Phillips et al. | Applicant |
| US2010/0281102(A1) | 2010-11-01 | Chinta et al. | Applicant |
| US2010/0281541(A1) | 2010-11-01 | Stolfo et al. | Applicant |
| US2010/0281542(A1) | 2010-11-01 | Stolfo et al. | Applicant |
| US2010/0287260(A1) | 2010-11-01 | Peterson et al. | Applicant |
| US2010/0299754(A1) | 2010-11-01 | Amit et al. | Applicant |
| US2010/0306173(A1) | 2010-12-01 | Frank | Applicant |
| US2011/0004737(A1) | 2011-01-01 | Greenebaum | Applicant |
| US2011/0025504(A1) | 2011-02-01 | Lyon et al. | Applicant |
| US2011/0041179(A1) | 2011-02-01 | St Hlberg | Applicant |
| US2011/0047594(A1) | 2011-02-01 | Mahaffey et al. | Applicant |
| US2011/0047620(A1) | 2011-02-01 | Mahaffey et al. | Applicant |
| US2011/0055907(A1) | 2011-03-01 | Narasimhan et al. | Applicant |
| US2011/0078794(A1) | 2011-03-01 | Manni et al. | Applicant |
| US2011/0093951(A1) | 2011-04-01 | Aziz | Applicant |
| US2011/0099620(A1) | 2011-04-01 | Stavrou et al. | Applicant |
| US2011/0099633(A1) | 2011-04-01 | Aziz | Applicant |
| US2011/0099635(A1) | 2011-04-01 | Silberman et al. | Applicant |
| US2011/0113231(A1) | 2011-05-01 | Kaminsky | Applicant |
| US2011/0145918(A1) | 2011-06-01 | Jung et al. | Applicant |
| US2011/0145920(A1) | 2011-06-01 | Mahaffey et al. | Applicant |
| US2011/0145934(A1) | 2011-06-01 | Abramovici et al. | Applicant |
| US2011/0167493(A1) | 2011-07-01 | Song et al. | Applicant |
| US2011/0167494(A1) | 2011-07-01 | Bowen et al. | Applicant |
| US2011/0173178(A1) | 2011-07-01 | Conboy et al. | Applicant |
| US2011/0173213(A1) | 2011-07-01 | Frazier et al. | Applicant |
| US2011/0173460(A1) | 2011-07-01 | Ito et al. | Applicant |
| US2011/0219449(A1) | 2011-09-01 | St. Neitzel et al. | Applicant |
| US2011/0219450(A1) | 2011-09-01 | McDougal et al. | Applicant |
| US2011/0225624(A1) | 2011-09-01 | Sawhney et al. | Applicant |
| US2011/0225655(A1) | 2011-09-01 | Niemela et al. | Applicant |
| US2011/0247072(A1) | 2011-10-01 | Staniford et al. | Applicant |
| US2011/0265182(A1) | 2011-10-01 | Peinado et al. | Applicant |
| US2011/0289582(A1) | 2011-11-01 | Kejriwal et al. | Applicant |
| US2011/0302587(A1) | 2011-12-01 | Nishikawa et al. | Applicant |
| US2011/0307954(A1) | 2011-12-01 | Melnik et al. | Applicant |
| US2011/0307955(A1) | 2011-12-01 | Kaplan | Examiner |
| US2011/0307956(A1) | 2011-12-01 | Yermakov et al. | Applicant |
| US2011/0314546(A1) | 2011-12-01 | Aziz et al. | Applicant |
| US2012/0023593(A1) | 2012-01-01 | Puder et al. | Applicant |
| US2012/0054869(A1) | 2012-03-01 | Yen et al. | Applicant |
| US2012/0066698(A1) | 2012-03-01 | Yanoo | Applicant |
| US2012/0079596(A1) | 2012-03-01 | Thomas | Examiner |
| US2012/0084859(A1) | 2012-04-01 | Radinsky et al. | Applicant |
| US2012/0110667(A1) | 2012-05-01 | Zubrilin et al. | Applicant |
| US2012/0117652(A1) | 2012-05-01 | Manni et al. | Applicant |
| US2012/0121154(A1) | 2012-05-01 | Xue et al. | Applicant |
| US2012/0124426(A1) | 2012-05-01 | Maybee et al. | Applicant |
| US2012/0174186(A1) | 2012-07-01 | Aziz et al. | Applicant |
| US2012/0174196(A1) | 2012-07-01 | Bhogavilli et al. | Applicant |
| US2012/0174218(A1) | 2012-07-01 | McCoy et al. | Applicant |
| US2012/0198279(A1) | 2012-08-01 | Schroeder | Applicant |
| US2012/0210423(A1) | 2012-08-01 | Friedrichs et al. | Applicant |
| US2012/0222121(A1) | 2012-08-01 | Staniford et al. | Applicant |
| US2012/0255015(A1) | 2012-10-01 | Sahita et al. | Applicant |
| US2012/0255017(A1) | 2012-10-01 | Sallam | Applicant |
| US2012/0260342(A1) | 2012-10-01 | Dube et al. | Applicant |
| US2012/0266244(A1) | 2012-10-01 | Green et al. | Applicant |
| US2012/0278886(A1) | 2012-11-01 | Luna | Applicant |
| US2012/0297489(A1) | 2012-11-01 | Dequevy | Applicant |
| US2012/0330801(A1) | 2012-12-01 | McDougal et al. | Applicant |
| US2012/0331553(A1) | 2012-12-01 | Aziz et al. | Applicant |
| US2013/0014259(A1) | 2013-01-01 | Gribble et al. | Applicant |
| US2013/0036472(A1) | 2013-02-01 | Aziz | Applicant |
| US2013/0047257(A1) | 2013-02-01 | Aziz | Applicant |
| US2013/0074185(A1) | 2013-03-01 | McDougal et al. | Applicant |
| US2013/0086684(A1) | 2013-04-01 | Mohler | Applicant |
| US2013/0097699(A1) | 2013-04-01 | Balupari et al. | Applicant |
| US2013/0097706(A1) | 2013-04-01 | Titonis et al. | Applicant |
| US2013/0111587(A1) | 2013-05-01 | Goel et al. | Applicant |
| US2013/0117852(A1) | 2013-05-01 | Stute | Applicant |
| US2013/0117855(A1) | 2013-05-01 | Kim et al. | Applicant |
| US2013/0139264(A1) | 2013-05-01 | Brinkley et al. | Applicant |
| US2013/0160125(A1) | 2013-06-01 | Likhachev et al. | Applicant |
| US2013/0160127(A1) | 2013-06-01 | Jeong et al. | Applicant |
| US2013/0160130(A1) | 2013-06-01 | Mendelev et al. | Applicant |
| US2013/0160131(A1) | 2013-06-01 | Madou et al. | Applicant |
| US2013/0167236(A1) | 2013-06-01 | Sick | Applicant |
| US2013/0174214(A1) | 2013-07-01 | Duncan | Applicant |
| US2013/0185789(A1) | 2013-07-01 | Hagiwara et al. | Applicant |
| US2013/0185795(A1) | 2013-07-01 | Winn et al. | Applicant |
| US2013/0185798(A1) | 2013-07-01 | Saunders et al. | Applicant |
| US2013/0191915(A1) | 2013-07-01 | Antonakakis et al. | Applicant |
| US2013/0196649(A1) | 2013-08-01 | Paddon et al. | Applicant |
| US2013/0227691(A1) | 2013-08-01 | Aziz et al. | Applicant |
| US2013/0246370(A1) | 2013-09-01 | Bartram et al. | Applicant |
| US2013/0247186(A1) | 2013-09-01 | LeMasters | Applicant |
| US2013/0263260(A1) | 2013-10-01 | Mahaffey et al. | Applicant |
| US2013/0291109(A1) | 2013-10-01 | Staniford et al. | Applicant |
| US2013/0298243(A1) | 2013-11-01 | Kumar et al. | Applicant |
| US2013/0318038(A1) | 2013-11-01 | Shiffer et al. | Applicant |
| US2013/0318073(A1) | 2013-11-01 | Shiffer et al. | Applicant |
| US2013/0325791(A1) | 2013-12-01 | Shiffer et al. | Applicant |
| US2013/0325792(A1) | 2013-12-01 | Shiffer et al. | Applicant |
| US2013/0325871(A1) | 2013-12-01 | Shiffer et al. | Applicant |
| US2013/0325872(A1) | 2013-12-01 | Shiffer et al. | Applicant |
| US2014/0032875(A1) | 2014-01-01 | Butler | Applicant |
| US2014/0053260(A1) | 2014-02-01 | Gupta et al. | Applicant |
| US2014/0053261(A1) | 2014-02-01 | Gupta et al. | Applicant |
| US2014/0130158(A1) | 2014-05-01 | Wang et al. | Applicant |
| US2014/0137180(A1) | 2014-05-01 | Lukacs et al. | Applicant |
| US2014/0169762(A1) | 2014-06-01 | Ryu | Applicant |
| US2014/0179360(A1) | 2014-06-01 | Jackson et al. | Applicant |
| US2014/0181131(A1) | 2014-06-01 | Ross | Applicant |
| US2014/0181975(A1) | 2014-06-01 | Spernow et al. | Applicant |
| US2014/0189687(A1) | 2014-07-01 | Jung et al. | Applicant |
| US2014/0189866(A1) | 2014-07-01 | Shiffer et al. | Applicant |
| US2014/0189882(A1) | 2014-07-01 | Jung et al. | Applicant |
| US2014/0237600(A1) | 2014-08-01 | Silberman et al. | Applicant |
| US2014/0280245(A1) | 2014-09-01 | Wilson | Applicant |
| US2014/0283037(A1) | 2014-09-01 | Sikorski et al. | Applicant |
| US2014/0283063(A1) | 2014-09-01 | Thompson et al. | Applicant |
| US2014/0325344(A1) | 2014-10-01 | Bourke et al. | Applicant |
| US2014/0328204(A1) | 2014-11-01 | Klotsche et al. | Applicant |
| US2014/0337836(A1) | 2014-11-01 | Ismael | Applicant |
| US2014/0344926(A1) | 2014-11-01 | Cunningham et al. | Applicant |
| US2014/0351935(A1) | 2014-11-01 | Shao et al. | Applicant |
| US2014/0380473(A1) | 2014-12-01 | Bu et al. | Applicant |
| US2014/0380474(A1) | 2014-12-01 | Paithane et al. | Applicant |
| US2015/0007312(A1) | 2015-01-01 | Pidathala et al. | Applicant |
| US2015/0096022(A1) | 2015-04-01 | Vincent et al. | Applicant |
| US2015/0096023(A1) | 2015-04-01 | Mesdaq et al. | Applicant |
| US2015/0096024(A1) | 2015-04-01 | Haq et al. | Applicant |
| US2015/0096025(A1) | 2015-04-01 | Ismael | Applicant |
| US2015/0180886(A1) | 2015-06-01 | Staniford et al. | Applicant |
| US2015/0186645(A1) | 2015-07-01 | Aziz et al. | Applicant |
| US2015/0220735(A1) | 2015-08-01 | Paithane et al. | Applicant |
| US2015/0372980(A1) | 2015-12-01 | Eyada | Applicant |
| US2016/0044000(A1) | 2016-02-01 | Cunningham | Applicant |
| US2016/0127393(A1) | 2016-05-01 | Aziz et al. | Applicant |
| GB2439806(A) | 2008-01-01 | Applicant | |
| GB2490431(A) | 2012-10-01 | Applicant | |
| WO206928 | 2002-01-01 | Applicant | |
| WO223805(A2) | 2002-03-01 | Applicant | |
| WO2007117636(A2) | 2007-10-01 | Applicant | |
| WO2008041950(A2) | 2008-04-01 | Applicant | |
| WO2011084431(A2) | 2011-07-01 | Applicant | |
| WO2011/112348(A1) | 2011-09-01 | Applicant | |
| WO2012/075336(A1) | 2012-06-01 | Applicant | |
| WO2012145066(A1) | 2012-10-01 | Applicant | |
| WO2013/067505(A1) | 2013-05-01 | Applicant |
Non-Patent Literature (89)
- William Martin, “Honey Pots and Honey Nets—Security Through Deception”, Retrieved From https://www.sans.org/reading-room/whitepapers/attacking/honeypots-honey-nets-security-deception-41, Published May 25, 2001.Examiner
- Marchette, David J., Computer Intrusion Detection and Network Monitoring: A Statistical (“Marchette”), (2001).Applicant
- Margolis, P.E., “Random House Webster's 'Computer & Internet Dictionary 3rd Edition”, ISBN 0375703519, p. 595 (Dec. 1998).Applicant
- Moore, D., et al., “Internet Quarantine: Requirements for Containing Self-Propagating Code”, INFOCOM, vol. 3, (Mar. 30-Apr. 3, 2003), pp. 1901-1910.Applicant
- Morales, Jose A., et al., ““Analyzing and exploiting network behaviors of malware.””, Security and Privacy in Communication Networks. Springer Berlin Heidelberg, 2010. 20-34.Applicant
- Mori, Detecting Unknown Computer Viruses, 2004, Springer-Verlag Berlin Heidelberg.Applicant
- Natvig, Kurt, “SandBoxII: Internet”, Virus Bulletin Conference, (“Natvig”), (Sep. 2002).Applicant
- NetBIOS Working Group. Protocol Standard for a NetBIOS Service on a TCP/UDP transport: Concepts and Methods. STD 19, RFC 1001, Mar. 1987.Applicant
- Newsome, J., et al., “Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software”, In Proceedings of the 12th Annual Network and Distributed System Security, Symposium (NDSS '05), (Feb. 2005).Applicant
- Newsome, J., et al., “Polygraph: Automatically Generating Signatures for Polymorphic Worms”, In Proceedings of the IEEE Symposium on Security and Privacy, (May 2005).Applicant
- Nojiri, D. , et al., “Cooperation Response Strategies for Large Scale Attack Mitigation”, DARPA Information Survivability Conference and Exposition, vol. 1, (Apr. 22-24, 2003), pp. 293-302.Applicant
- Oberheide et al., CloudAV.sub.-N-Version Antivirus in the Network Cloud, 17th USENIX Security Symposium USENIX Security '08 Jul. 28-Aug. 1, 2008 San Jose, CA.Applicant
- PCT/US2014/043726 filed Jun. 23, 2014 International Search Report and Written Opinion dated Oct. 9, 2014.Applicant
- PCT/US2015/067082 filed Dec. 21, 2015 International Search Report and Written Opinion dated Feb. 24, 2016.Applicant
- Peter M. Chen, and Brian D. Noble, “When Virtual is Better Than Real, Department of Electrical Engineering and Computer Science”, University of Michigan (“Chen”), (2001).Applicant
- Reiner Sailer, Enriquillo Valdez, Trent Jaeger, Roonald Perez, Leendert van Doom, John Linwood Griffin, Stefan Berger., sHype: Secure Hypervisor Approach to Trusted Virtualized Systems (Feb. 2, 2005) (“Sailer”).Applicant
- Silicon Defense, “Worm Containment in the Internal Network”, (Mar. 2003), pp. 1-25.Applicant
- Singh, S., et al., “Automated Worm Fingerprinting”, Proceedings of the ACM/USENIX Symposium on Operating System Design and Implementation, San Francisco, California, (Dec. 2004).Applicant
- Spitzner, Lance, “Honeypots: Tracking Hackers”, (“Spizner”), (Sep. 17, 2002).Applicant
- The Sniffers's Guide to Raw Traffic available at: yuba.stanford.edu/˜casado/pcap/sectionl.html, (Jan. 6, 2014).Applicant
- Thomas H. Ptacek, and Timothy N. Newsham , “Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection”, Secure Networks, (“Ptacek”), (Jan. 1998).Applicant
- U.S. Appl. No. 11/717,475. filed Mar. 12, 2007 Final Office Action dated Feb. 27, 2013.Applicant
- U.S. Appl. No. 11/717,475, filed Mar. 12, 2007 Final Office Action dated Nov. 22, 2010.Applicant
- U.S. Appl. No. 11/717,475, filed Mar. 12, 2007 Non-Final Office Action dated Aug. 28, 2012.Applicant
- U.S. Appl. No. 11/717,475, filed Mar. 12, 2007 Non-Final Office Action dated May 6, 2010.Applicant
- U.S. Appl. No. 13/925,688, filed Jun. 24, 2013 Final Office Action dated Jan. 12, 2017.Applicant
- U.S. Appl. No. 13/925,688, filed Jun. 24, 2013 Final Office Action dated Mar. 11, 2016.Applicant
- U.S. Appl. No. 13/925,688, filed Jun. 24, 2013 Non-Final Office Action dated Jun. 2, 2015.Applicant
- U.S. Appl. No. 13/925,688, filed Jun. 24, 2013 Non-Final Office Action dated Sep. 16, 2016.Applicant
- U.S. Appl. No. 14/059,381, filed Oct. 21, 2013 Non-Final Office Action dated Oct. 29, 2014.Applicant
- U.S. Appl. No. 14/620,060, filed Feb. 11, 2015, Non-Final Office Action dated Apr. 3, 2015.Applicant
- U.S. Pat. No. 8,171,553 filed Apr. 20, 2006, Inter Parties Review Decision dated Jul. 10, 2015.Applicant
- U.S. Pat. No. 8,291,499 filed Mar. 16, 2012, Inter Parties Review Decision dated Jul. 10, 2015.Applicant
- Venezia, Paul, “NetDetector Captures Intrusions”, InfoWorld Issue 27, (“Venezia”), (Jul. 14, 2003).Applicant
- Wahid et al., Characterising the Evolution in Scanning Activity of Suspicious Hosts, Oct. 2009, Third International Conference on Network and System Security, pp. 344-350.Applicant
- Whyte, et al., “DNS-Based Detection of Scanning Works in an Enterprise Network”, Proceedings of the 12th Annual Network and Distributed System Security Symposium, (Feb. 2005), 15 pages.Applicant
- Williamson, Mathew M., “Throttling Virses: Restricting Propagation to Defeat Malicious Mobile Code”, ACSAC Conference, Las Vegas, NV, USA, (Dec. 2002), pp. 1-9.Applicant
- Yuhei Kawakoya et al: “Memory behavior-based automatic malware unpacking in stealth debugging environment”, Malicious and Unwanted Software (Malware), 2010 5th International Conference on, IEEE, Piscataway, NJ, USA, Oct. 19, 2010, pp. 39-46, XP031833827, ISBN:978-1-4244-8-9353-1.Applicant
- Zhang et al., The Effects of Threading, Infection Time, and Multiple-Attacker Collaboration on Malware Propagation, Sep. 2009, IEEE 28th International Symposium on Reliable Distributed Systems, pp. 73-82.Applicant
- “Network Security: NetDetector—Network Intrusion Forensic System (NIFS) Whitepaper”, (“NetDetector Whitepaper”), (2003).Applicant
- “Packet”, Microsoft Computer Dictionary Microsoft Press, (Mar. 2002), 1 page.Applicant
- “When Virtual is Better Than Real”, IEEEXplore Digital Library, available at, http://ieeexplore.ieee.org/xpl/articleDetails.iso?reload=true&arnumber=990073, (Dec. 7, 2013).Applicant
- Abdullah, et al., Visualizing Network Data for Intrusion Detection, 2005 IEEE Workshop on Information Assurance and Security, pp. 100-108.Applicant
- Adetoye, Adedayo, et al., “Network Intrusion Detection & Response System”, (“Adetoye”) (Sep. 2003).Applicant
- Adobe Systems Incorporated, “PDF 32000-1:2008, Document management—Portable document format—Part1:PDF 1.7”, First Edition, Jul. 1, 2008, 756 pages.Applicant
- AltaVista Advanced Search Results (subset). “attack vector identifier” Http://www.altavista.com/web/results?Itag=ody&pg=aq&aqmode=aqa=Event+Orchestrator . . . , (Accessed on Sep. 15, 2009).Applicant
- AltaVista Advanced Search Results (subset). “Event Orchestrator”. Http://www.altavista.com/web/results?Itag=ody&pg=aq&aqmode=aqa=Event+Orchesrator . . . , (Accessed on Sep. 3, 2009).Applicant
- Apostolopoulos, George; hassapis, Constantinos; “V-eM: A cluster of Virtual Machines for Robust, Detailed, and High-Performance Network Emulation”, 14th IEEE International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems, Sep. 11-14, 2006, pp. 117-126.Applicant
- Aura, Tuomas, “Scanning electronic documents for personally identifiable information”, Proceedings of the 5th ACM workshop on Privacy in electronic society. ACM, 2006.Applicant
- Baecher, “The Nepenthes Platform: An Efficient Approach to collect Malware”, Springer-verlaq Berlin Heidelberg, (2006), pp. 165-184.Applicant
- Baldi, Mario; Risso, Fulvio; “A Framework for Rapid Development and Portable Execution of Packet-Handling Applications”, 5th IEEE International Symposium Processing and Information Technology, Dec. 21, 2005, pp. 233-238.Applicant
- Bayer, et al., “Dynamic Analysis of Malicious Code”, J Comput Virol, Springer-Verlag, France., (2006), pp. 67-77.Applicant
- Boubalos, Chris , “extracting syslog data out of raw pcap dumps, seclists.org, Honeypots mailing list archives”, available at http://seclists,org/honeypots/2003/q2/319 (“Boubalos”), (Jun. 5, 2003).Applicant
- Bowen, B. M. et al “ BotSwindler: Tamper Resistant Injection of Believable Decoys in VM-Based Hosts for Crimeware Detection”, in Recent Advances in Intrusion Detection, Springer ISBN: 978-3-642-15511-6 (pp. 118-137) (Sep. 15, 2010).Applicant
- Chaudet, C., et al., “Optimal Positioning of Active and Passive Monitoring Devices”, International Conference on Emerging Networking Experiments and Technologies, Proceedings of the 2005 ACM Conference on Emerging Network Experiment and Technology, CoNEXT '05, Toulousse, France, (Oct. 2005), pp. 71-82.Applicant
- Cisco “Intrusion Prevention for the Cisco ASA 5500-x Series” Data Sheet (2012).Applicant
- Cisco, Configuring the Catalyst Switched Port Analyzer (SPAN) (“Cisco”), (1992-2003).Applicant
- Clark, John, Sylvian Leblanc,and Scott Knight. “Risks associated with usb hardware trojan devices used by insiders.” Systems Conference (SysCon), 2011 IEEE International. IEEE, 2011.Applicant
- Cohen, M.I., “PyFlag—An advanced network forensic framework”, Digital investigation 5, Elsevier, (2008), pp. S112-S120.Applicant
- Costa, M., et al., “Vigilante: End-to-End Containment of Internet Worms”, SOSP '05 Association for Computing Machinery, Inc., Brighton U.K., (Oct. 23-26, 2005).Applicant
- Crandall, J.R., et al., “Minos:Control Data Attack Prevention Orthogonal to Memory Model”, 37th International Symposium on Microarchitecture, Portland, Oregon, (Dec. 2004).Applicant
- Deutsch, P., ““Zlib compressed data format specification version 3.3” RFC 1950, (1996)”.Applicant
- Distler, “Malware Analysis: An Introduction”, SANS Institute InfoSec Reading Room, SANS Institute, (2007).Applicant
- Dunlap, George W. , et al., “ReVirt: Enabling Intrusion Analysis through Virtual-Machine Logging and Replay”, Proceeding of the 5th Symposium on Operating Systems Design and Implementation, USENIX Association, (“Dunlap”), (Dec. 9, 2002).Applicant
- Excerpt regarding First Printing Date for Merike Kaeo, Designing Network Security (“Kaeo”), (2005).Applicant
- Filiol, Eric , et al., “Combinatorial Optimisation of Worm Propagation on an Unknown Network”, International Journal of Computer Science 2.2 (2007).Applicant
- FireEye Malware Analysis & Exchange Network, Malware Protection System, FireEye Inc., 2010.Applicant
- FireEye Malware Analysis, Modern Malware Forensics, FireEye Inc., 2010.Applicant
- FireEye v.6.0 Security Target, pp. 1-35, Version 1.1, FireEye Inc., May 2011.Applicant
- Gibler, Clint, et al. AndroidLeaks: automatically detecting potential privacy leaks in android applications on a large scale. Springer Berlin Heidelberg, 2012.Applicant
- Goel, et al., Reconstructing System State for Intrusion Analysis, Apr. 2008 SIGOPS Operating Systems Review vol. 42 Issue 3, pp. 21-28.Applicant
- Gregg Keizer: “Microsoft's HoneyMonkeys Show Patching Windows Works”, Aug. 8, 2005, XP055143386, Retrieved from the Internet: URL:http://www.informationweek.com/microsofts-honeymonkeys-show-patching-windows-works/d/d-id/1035069? [retrieved on Jun. 1, 2016].Applicant
- Heng Yin et al, Panorama: Capturing System-Wide Information Flow for Malware Detection and Analysis, Research Showcase © CMU, Carnegie Mellon University, 2007.Applicant
- Hjelmvik, Erik, “Passive Network Security Analysis with NetworkMiner”, (IN)SECURE, Issue 18, (Oct. 2008), pp. 1-100.Applicant
- Idika et al., A-Survey-of-Malware-Detection-Techniques, Feb. 2, 2007, Department of Computer Science, Purdue University.Applicant
- IEEE Xplore Digital Library Sear Results (subset) for “detection of unknown computer worms”. Http//ieeexplore.ieee.org/searchresult.jsp?SortField=Score&SortOrder=desc&ResultC . . . (Accessed on Aug. 28, 2009).Applicant
- Isohara, Takamasa, Keisuke Takemori, and Ayumu Kubota. “Kernel-based behavior analysis for android malware detection.” Computational intelligence and Security (CIS), 2011 Seventh International Conference on. IEEE, 2011.Applicant
- Kaeo, Merike, “Designing Network Security”, (“Kaeo”), (Nov. 2003).Applicant
- Kevin A Roundy et al: “Hybrid Analysis and Control of Malware”, Sep. 15, 2010, Recent Advances in Intrusion Detection, Springer Berlin Heidelberg, Berlin, Heidelberg, pp. 317-338, XP019150454 ISBN:978-3-642-15511-6.Applicant
- Kim, H., et al., “Autograph: Toward Automated, Distributed Worm Signature Detection”, Proceedings of the 13th Usenix Security Symposium (Security 2004), San Diego, (Aug. 2004), pp. 271-286.Applicant
- King, Samuel T., et al., “Operating System Support for Virtual Machines”, (“King”), (Dec. 2002).Applicant
- Kasnyansky, Max, et al., Universal TUN/TAP driver, available at https://www.kernel.org/doc/Documentation/networking/tuntap.txt (2002) (“Krasnyansky”).Applicant
- Kreibich, C., et al., “Honeycomb-Creating Intrusion Detection Signatures Using Honeypots”, 2nd Workshop on Hot Topics in Networks (HotNets-11), Boston, USA, (2003).Applicant
- Kristoff, J., “Botnets, Detection and Mitigation: DNS-Based Techniques”, NU Security Day, (2005), 23 pages.Applicant
- Leading Colleges Select FireEye to Stop Malware-Related Data Breaches, FireEye Inc., 2009.Applicant
- Li et al., A VMM-Based System Call Interposition Framework for Program Monitoring, Dec. 2010, IEEE 16th International Conference on Parallel and Distributed Systems, pp. 706-711.Applicant
- Liljenstam, Michael, et al., “Simulating Realistic Network Traffic for Worm Warning System Design and Testing”, Institute for Security Technology studies, Dartmouth College, (“Liljenstam”), (Oct. 27, 2003).Applicant
- Lindorfer, Martina, Clemens Kolbitsch, and Paolo Milani Compare& “Detecting environment-sensitive malware.” Recent Advances in Intrusion Detection. Springer Berlin Heidelberg, 2011.Applicant
- Lok Kwong et al: “DroidScope: Seamlessly Reconstructing the OS and Dalvik Semantic Views for Dynamic Android Malware Analysis”, Aug. 10, 2012, XP055158513, Retrieved from the Internet: URL:https://www.usenix.org/system/files/conference/usenixsecurity12/sec12--final107.pdf [retrieved on Dec. 15, 2014].Applicant