Server drift monitoring

US10038702B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10038702-B2
Application numberUS-201715681501-A
CountryUS
Kind codeB2
Filing dateAug 21, 2017
Priority dateDec 15, 2014
Publication dateJul 31, 2018
Grant dateJul 31, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Threat detection is improved by monitoring variations in observable events and correlating these variations to malicious activity. The disclosed techniques can be usefully employed with any attribute or other metric that can be instrumented on an endpoint and tracked over time including observable events such as changes to files, data, software configurations, operating systems, and so forth. Correlations may be based on historical data for a particular machine, or a group of machines such as similarly configured endpoints. Similar inferences of malicious activity can be based on the nature of a variation, including specific patterns of variation known to be associated with malware and any other unexpected patterns that deviate from normal behavior. Embodiments described herein use variations in, e.g., server software updates or URL cache hits on an endpoint, but the techniques are more generally applicable to any endpoint attribute that varies in a manner correlated with malicious activity.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: configuring a plurality of servers in a group of similarly configured servers with one or more executables in a known configuration, each one of the plurality of servers configured to provide services across a network to remote clients; instrumenting each of the plurality of servers to detect changes in the one or more executables in the plurality of servers, and to periodically or continuously provide updates with information about the changes; receiving the changes in the one or more executables at a threat management facility for an enterprise network that includes the plurality of servers; detecting a drift in a first one of the plurality of servers, the drift including a deviation of the changes in the one or more executables in the first one of the plurality of servers relative to the changes in the one or more executables in other ones of the plurality of servers, wherein detecting includes detecting by a number of classes of changes each specifying an actor initiating one of the changes; and initiating a remedial action when the drift in the first one of the plurality of servers deviates beyond a predetermined threshold, wherein the predetermined threshold is a different threshold for each of the number of classes of changes. 2. The method of claim 1 wherein the actor is selected from a group consisting of an application, a user of the application, a passive authorized user, an active authorized user, and a trusted updater. 3. The method of claim 1 wherein the one or more executables include at least one of a native executable file, an interpreted file, a script, a dynamic linked library, and an Adobe flash file. 4. The method of claim 1 wherein the changes include updates to an application. 5. The method of claim 1 wherein the changes include installations of a new application. 6. The method of claim 1 wherein the changes include additions of at least one of a new dynamic linked library, a resource file, interpreted data file, and configuration file. 7. The method of claim 1 wherein the remedial action includes at least one of a quarantine, a deactivation, and a notification. 8. The method of claim 1 further comprising filtering at least one change initiated by a trusted updater. 9. A computer program product comprising non-transitory computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of: configuring a plurality of servers in a group of similarly configured servers with one or more executables in a known configuration, each one of the plurality of servers configured to provide services across a network to remote clients; instrumenting each of the plurality of servers to detect changes in the one or more executables in the plurality of servers, and to periodically or continuously update a database with information about the changes; receiving the changes in the one or more executables at a threat management facility for an enterprise network that includes the plurality of servers; detecting a drift in a first one of the plurality of servers, the drift including a deviation of the changes in the one or more executables in the first one of the plurality of servers relative to the changes in the one or more executables in other ones of the plurality of servers, wherein detecting includes detecting by a number of classes of changes; and initiating a remedial action when the drift in the first one of the plurality of servers deviates beyond a predetermined threshold, wherein the predetermined threshold is a different threshold for each of the number of classes of changes. 10. The computer program product of claim 9 wherein the number of classes specify one or more actors. 11. The computer program product of claim 10 wherein the one or more actors are selected from a group consisting of an application, a user of the application, a passive authorized user, an active authorized user, and a trusted updater. 12. The computer program product of claim 9 wherein the one or more executables include at least one of a native executable file, an interpreted file, a script, a dynamic linked library, and an Adobe flash file. 13. The computer program product of claim 9 wherein the changes include updates to an application. 14. The computer program product of claim 9 wherein the changes include installations of a new application. 15. The computer program product of claim 9 wherein the changes include additions of at least one of a new dynamic linked library, a resource file, interpreted data file, and configuration file. 16. The computer program product of claim 9 further comprising filtering at least one change initiated by a trusted updater. 17. The computer program product of claim 9 wherein detecting includes detecting by a number of classes of changes, wherein the predetermined threshold is a different threshold for each of the number of classes. 18. The computer program product of claim 17 wherein the number of classes specify one or more actors initiating changes selected from a group consisting of an application, a user of the application, a passive authorized user, an active authorized user, and a trusted updater. 19. A system comprising: a server farm including a plurality of similarly configured servers with one or more executables in a known configuration, each one of the plurality of servers configured to provide services across a network to remote clients, and each one of the plurality of servers including a processor and associated memory, the memory storing instructions which, when executed by the processor, detect a local drift including a change in the one or more executables on the server; and a threat management facility coupled in a communicating relationship with each one of the plurality of servers, the threat management facility including a processor and associated memory, the memory storing instructions which, when executed by the processor, monitor periodic or continuous updates of local drift corresponding to each one of the plurality of servers, to detect a deviation of the local drift in a first one of the plurality of servers relative to the local drift in other ones of the plurality of servers wherein detecting includes detecting by a number of classes of changes, and to initiate a remedial action when the deviation in the local drift in the first one of the plurality of servers exceeds a predetermined threshold, wherein the predetermined threshold is a different threshold for each of the number of classes of changes.

Assignees

Inventors

Classifications

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10038702B2 cover?
Threat detection is improved by monitoring variations in observable events and correlating these variations to malicious activity. The disclosed techniques can be usefully employed with any attribute or other metric that can be instrumented on an endpoint and tracked over time including observable events such as changes to files, data, software configurations, operating systems, and so forth. C…
Who is the assignee on this patent?
Sophos Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/1408. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 31 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).