Malware analysis and recovery

US2018167403A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018167403-A1
Application numberUS-201715837942-A
CountryUS
Kind codeA1
Filing dateDec 11, 2017
Priority dateDec 12, 2016
Publication dateJun 14, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method detects malware by processing notifications from an intrusion detection system and baseline snapshots from an image capture utility. The image capture utility constructs an image of the suspected malware intrusion and links the suspected malware intrusion to the baseline snapshots. The system and method propagates the image of the suspected malware intrusion across multiple networks before it distinguishes malicious code, device state, and files from benign code, device state, and files. Some systems and methods include a malware recovery system that executes machine learning instructions and heuristics to revert a client and/or a remote server to one or more baseline snapshots.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: receiving baseline snapshots of a remote client and/or a remote server from a remote image capture utility; receiving from the remote client and/or the remote server a notification of a suspected malware intrusion on the remote client and/or the remote server; constructing an image of the suspected malware intrusion at the remote client and/or the remote server; linking by the remote image capture utility the image of the suspected malware intrusion to the baseline snapshots at the remote client and/or the remote server before the malware intrusion is confirmed; propagating the image of the suspected malware intrusion across a first network and a second network; and distinguishing malicious code, device state, and files from benign code, device state, and files. 2 . The method of claim 1 wherein the image of the suspected malware intrusion is linked to the baseline snapshots via attachment. 3 . The method of claim 1 wherein the image of the suspected malware intrusion is linked to the baseline snapshots via a pointer. 4 . The method of claim 1 wherein the act of receiving baseline snapshots of the remote client and/or the remote server occurs in response to an asynchronous event. 5 . The method of claim 1 wherein receiving baseline snapshots of the remote client and/or the remote server occurs in response to a synchronous schedule. 6 . The method of claim 1 wherein the notification of the suspected malware intrusion is generated by a remote intrusion detection system. 7 . The method of claim 1 wherein the notification of the suspected malware intrusion is generated by a distributed intrusion detection system. 8 . The method of claim 1 wherein the notification of the suspected malware intrusion is generated by a network intrusion detection system that detects the suspected malware intrusion by monitoring only network traffic. 9 . The method of claim 1 further comprising evaluating the notification of the suspected malware intrusion based on state information from other remote clients and/or other remote servers. 10 . A non-transitory machine-readable medium encoded with machine-executable instructions, wherein execution of the machine-executable instructions is for: receiving baseline snapshots of a remote client and/or a remote server from a remote image capture utility; receiving from the remote client and/or the remote server a notification of a suspected malware intrusion on the remote client and/or the remote server; constructing an image of the suspected malware intrusion at the remote client and/or the remote server; linking by the remote image capture utility the image of the suspected malware intrusion to the baseline snapshots at the remote client and/or the remote server before the malware intrusion is confirmed; propagating the image of the suspected malware intrusion across a first network and a second network; and distinguishing malicious code and files from benign code and files. 11 . The non-transitory machine-readable medium of claim 10 wherein the image of the suspected malware intrusion is linked to the baseline snapshots via attachment. 12 . The non-transitory machine-readable medium of claim 10 wherein the image of the suspected malware intrusion is linked to the baseline snapshots via a pointer. 13 . The non-transitory machine-readable medium of claim 10 wherein the act of receiving baseline snapshots of the remote client and/or the remote server occurs in response to an asynchronous event. 14 . The non-transitory machine readable medium of claim 10 wherein receiving baseline snapshots of the remote client and/or the remote server occurs in response to a synchronous schedule. 15 . The non-transitory machine-readable medium of claim 10 wherein the notification of the suspected malware intrusion is generated by a remote intrusion detection system. 16 . The non-transitory machine-readable medium of claim 10 wherein the notification of the suspected malware intrusion is generated by a distributed intrusion detection system. 17 . The non-transitory machine-readable medium of claim 10 wherein the notification of the suspected malware intrusion is generated by a network intrusion detection system that detects the suspected malware intrusion by monitoring only network traffic. 18 . The non-transitory machine-readable medium of claim 10 further comprising evaluating the notification of the suspected malware intrusion on the remote client and/or the remote server based on state information from other remote clients and/or the remote servers. 19 . A system comprising: an application program interface configured to receive baseline snapshots of a remote client and/or a remote server; an intrusion detection system configured to transmit a notification of a suspected malware intrusion on the remote client and/or the remote server; a remote image capture utility configured to construct an image of the suspected malware intrusion at the remote client and/or the remote server; and a malware impact engine configured to receive the image of the suspected malware attack from a first network and a second network; where the malware impact engine is configured to distinguish malicious code and files from benign code and files; and where the remote image capture utility is further configured to link the image of the suspected malware intrusion to the baseline snapshots of the remote client and/or the remote server. 20 . The system of claim 19 wherein the notification of the suspected malware intrusion is generated by a network intrusion detection system that detects the suspected malware intrusion by monitoring only network traffic. 21 . The system of claim 19 further comprising a malware recovery system that executes machine learning and heuristic that reverts the remote client and/or a remote server to the baseline image.

Assignees

Inventors

Classifications

  • Traffic logging, e.g. anomaly detection · CPC title

  • Physics · mapped topic

  • Event detection, e.g. attack signature detection · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • G06N20/00Primary

    Machine learning · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018167403A1 cover?
A system and method detects malware by processing notifications from an intrusion detection system and baseline snapshots from an image capture utility. The image capture utility constructs an image of the suspected malware intrusion and links the suspected malware intrusion to the baseline snapshots. The system and method propagates the image of the suspected malware intrusion across multiple …
Who is the assignee on this patent?
Ut Battelle Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 14 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).