Cookies watermarking in malware analysis

US10489581B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10489581-B2
Application numberUS-201615141742-A
CountryUS
Kind codeB2
Filing dateApr 28, 2016
Priority dateMar 8, 2016
Publication dateNov 26, 2019
Grant dateNov 26, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for cookies watermarking in malware analysis are disclosed. In some embodiments, a system, process, and/or computer program product for cookies watermarking in malware analysis includes receiving a sample at a cloud security service; detonating the sample in an instrumented virtual environment; and determining that the sample is malware based on detecting an attempt to access a watermark cookie during an automated malware analysis using the instrumented virtual environment.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising: a processor configured to: receive a sample at a cloud security service for executing in an instrumented virtual environment to perform an automated malware analysis; inject a plurality of watermark cookies in the instrumented virtual environment to provide a modified instrumented virtual environment, wherein each of the plurality of watermark cookies comprises a distinct cookie file that is associated with one or more decoy accounts of a distinct web site; detonate the sample in the modified instrumented virtual environment; and determine that the sample is malware based on detecting an attempt to access at least one of the plurality of watermark cookies during the automated malware analysis using the modified instrumented virtual environment; and a memory coupled to the processor and configured to provide the processor with instructions. 2. The system recited in claim 1 , wherein the at least one of the plurality of watermark cookies is an HTTP cookie. 3. The system recited in claim 1 , wherein the at least one of the plurality of watermark cookies is an HTTP cookie associated with a web site. 4. The system recited in claim 1 , wherein the at least one of the plurality of watermark cookies is stored in a predetermined location in the instrumented virtual environment. 5. The system recited in claim 1 , wherein the processor is further configured to: detect whether the at least one of the plurality of watermark cookies was opened, modified, or sent in the modified instrumented virtual environment; and automatically generate a cookie-based signature for the sample if the sample is determined to be malware. 6. The system recited in claim 1 , wherein the processor is further configured to: detect whether the at least one of the plurality of watermark cookies was accessed in the modified instrumented virtual environment. 7. The system recited in claim 1 , wherein the processor is further configured to: automatically generate a signature for the sample if the sample is determined to be malware. 8. A method, comprising: receiving a sample at a cloud security service for executing in an instrumented virtual environment to perform an automated malware analysis; injecting a plurality of watermark cookies in the instrumented virtual environment to provide a modified instrumented virtual environment, wherein each of the plurality of watermark cookies comprises a distinct cookie file that is associated with one or more decoy accounts of a distinct web site; detonating the sample in the modified instrumented virtual environment; and determining that the sample is malware based on detecting an attempt to access at least one of the plurality of watermark cookies during the automated malware analysis using the modified instrumented virtual environment. 9. The method of claim 8 , wherein the at least one of the plurality of watermark cookies is an HTTP cookie. 10. The method of claim 8 , wherein the at least one of the plurality of watermark cookies is an HTTP cookie associated with a web site. 11. The method of claim 8 , wherein the at least one of the plurality of watermark cookies is stored in a predetermined location in the instrumented virtual environment. 12. The method of claim 8 , further comprising: detecting whether the at least one of the plurality of watermark cookies was opened, modified, or sent in the modified instrumented virtual environment; and automatically generating a cookie-based signature for the sample if the sample is determined to be malware. 13. The method of claim 8 , further comprising: detecting whether the at least one of the plurality of watermark cookies was accessed in the modified instrumented virtual environment. 14. The method of claim 8 , further comprising: automatically generating a signature for the sample if the sample is determined to be malware. 15. A computer program product, the computer program product being embodied in a tangible computer readable storage medium and comprising computer instructions for: receiving a sample at a cloud security service for executing in an instrumented virtual environment to perform an automated malware analysis; injecting a plurality of watermark cookies in the instrumented virtual environment to provide a modified instrumented virtual environment, wherein each of the plurality of watermark cookies comprises a distinct cookie file that is associated with one or more decoy accounts of a distinct web site; detonating the sample in the modified instrumented virtual environment; and determining that the sample is malware based on detecting an attempt to access at least one of the plurality of watermark cookies during the automated malware analysis using the modified instrumented virtual environment. 16. The computer program product recited in claim 15 , wherein the at least one of the plurality of watermark cookies is an HTTP cookie associated with a web site. 17. The computer program product recited in claim 15 , wherein the at least one of the plurality of watermark cookies is stored in a predetermined location in the instrumented virtual environment. 18. The computer program product recited in claim 15 , further comprising computer instructions for: detecting whether the at least one of the plurality of watermark cookies was opened, modified, or sent in the modified instrumented virtual environment; and automatically generating a cookie-based signature for the sample if the sample is determined to be malware. 19. The computer program product recited in claim 15 , further comprising computer instructions for: detecting whether the at least one of the plurality of watermark cookies was accessed in the modified instrumented virtual environment. 20. The computer program product recited in claim 15 , further comprising computer instructions for: automatically generating a signature for the sample if the sample is determined to be malware. 21. The computer program product recited in claim 15 , wherein the at least one of the plurality of watermark cookies is an HTTP cookie.

Assignees

Inventors

Classifications

  • G06F21/53Primary

    by executing in a restricted environment, e.g. sandbox or secure virtual machine · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • by adding security routines or objects to programs · CPC title

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10489581B2 cover?
Techniques for cookies watermarking in malware analysis are disclosed. In some embodiments, a system, process, and/or computer program product for cookies watermarking in malware analysis includes receiving a sample at a cloud security service; detonating the sample in an instrumented virtual environment; and determining that the sample is malware based on detecting an attempt to access a water…
Who is the assignee on this patent?
Palo Alto Networks Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/53. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Nov 26 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).