Method and apparatus for detecting malicious software using handshake information

US9854000B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9854000-B2
Application numberUS-201414534429-A
CountryUS
Kind codeB2
Filing dateNov 6, 2014
Priority dateNov 6, 2014
Publication dateDec 26, 2017
Grant dateDec 26, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In one embodiment, a method includes identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint that are included in a network, and determining whether the unusual behavior with respect to the handshake indicates presence of malicious software. The method also includes identifying at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of malicious software.

First claim

Opening claim text (preview).

What is claimed is: 1. A tangible, non-transitory computer-readable medium comprising computer program code, the computer program code, when executed, configured to: identify unusual behavior with respect to a handshake between a first endpoint and a second endpoint, wherein the first endpoint and the second endpoint are included in a network, wherein the unusual behavior is identified by an observer node included in the network, the observer node being inline on the network between the first endpoint and the second endpoint, the observer node being arranged to obtain communications between the first endpoint and the second endpoint, and wherein the handshake is one selected from a group including a Transport Layer Security (TLS) handshake, a Secure Sockets Layer (SSL) handshake, and a Datagram Transport Layer Security {DTLS} protocol handshake; determine whether the unusual behavior with respect to the handshake indicates presence of malicious software, wherein the computer program code configured to determine whether the unusual behavior with respect to the handshake indicates the presence of the malicious software includes computer program code configured to use at least one selected from a group including telemetry data and historical data associated with the network to determine a likelihood that the unusual behavior with respect to the handshake indicates the presence of the malicious software; and identify at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of the malicious software, wherein the at least one selected from the group including the telemetry data and the historical data includes an indication of whether at least one previous connection between the first endpoint and the second endpoint that leveraged an interception proxy was successful, wherein if the at least one previous connection was successful, the presence of the malicious software is indicated. 2. An apparatus comprising: logic, the logic including a monitoring module, a detection module, and an identification module, the monitoring module being configured to monitor communications on a network by intercepting the communications between endpoints in the network, the communications on the network including handshake communications, wherein the detection module is configured to detect when the handshake communications include an unusual handshake communication, and wherein the identification module is arranged to determine when the unusual handshake communication indicates that at least one endpoint is compromised by malicious software; a processing arrangement, wherein the logic includes computer program code and wherein the processing arrangement is configured to execute the computer program code; and a data storage arrangement, the data storage arrangement being configured to store least one selected from a group including historical information associated with the network and telemetry information associated with the network, wherein the identification module is configured to use the at least one selected from the group including the historical information associated with the network and the telemetry information associated with the network to determine when the unusual handshake communication indicates that the at least one endpoint is compromised by the malicious software, wherein the at least one selected from the group including the telemetry data and the historical data includes an indication of whether at least one previous connection between the first endpoint and the second endpoint that leveraged an interception proxy was successful, wherein if the at least one previous connection was successful, the presence of the malicious software is indicated. 3. A method comprising: identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint, wherein the first endpoint and the second endpoint are included in a network, wherein the unusual behavior is identified by an observer node included in the network, the observer node being inline on the network between the first endpoint and the second endpoint, the observer node being arranged to obtain communications between the first endpoint and the second endpoint and wherein the handshake is one selected from a group including a Transport Layer Security (TLS) handshake, a Secure Sockets Layer (SSL) handshake, and a Datagram Transport Layer Security {DTLS} protocol handshake; determining whether the unusual behavior with respect to the handshake indicates presence of malicious software, wherein determining whether the unusual behavior with respect to the handshake indicates the presence of the malicious software includes using at least one selected from a group including telemetry data and historical data associated with the network to determine a likelihood that the unusual behavior with respect to the handshake indicates the presence of the malicious software; and identifying at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of the malicious software, wherein the at least one selected from the group including the telemetry data and the historical data includes an indication of whether at least one previous connection between the first endpoint and the second endpoint that leveraged an interception proxy was successful, wherein if the at least one previous connection was successful, the presence of the malicious software is indicated.

Assignees

Inventors

Classifications

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • H04L63/166Primary

    at the transport layer · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9854000B2 cover?
In one embodiment, a method includes identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint that are included in a network, and determining whether the unusual behavior with respect to the handshake indicates presence of malicious software. The method also includes identifying at least one of the first endpoint and the second endpoint as potentia…
Who is the assignee on this patent?
Wing Daniel G, Andreasen Flemming S, Leung Kent K, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/166. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 26 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).