Electronic crime detection and tracking

US9904955B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9904955-B2
Application numberUS-201414308686-A
CountryUS
Kind codeB2
Filing dateJun 18, 2014
Priority dateJun 3, 2008
Publication dateFeb 27, 2018
Grant dateFeb 27, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for electronic crime reduction is provided, comprising a computer system, a database, a malware de-compiler, a malware parser, and an inference engine. The database contains information that associates electronic crime attack signature data with at least one of an individual, a group, and a location. The malware de-compiler, when executed on the computer system, translates a first malware executable to an assembly language version. The first malware is associated with an electronic crime that has been committed. The malware parser, when executed on the computer system, analyzes the assembly language version to identify distinctive coding preferences used to develop the first malware. The inference engine, when executed on the computer system, analyzes the distinctive coding preferences identified by the malware parser application in combination with searching the database to identify one of an individual, a group, and a location associated with the electronic crime.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of analyzing and mitigating an electronic crime under investigation, comprising: maintaining a database that associates electronic crime attack signature data for each of a plurality of known electronic crime attacks with at least one of an individual and a group, analyzing, by one or more applications stored in a non-transitory memory and executed by a processor, at least one technique, wherein the analyzing comprises translating, by the one or more applications, an executable of a malware to a second version comprising assembly code of the malware or source code of the malware and analyzing, by the one or more applications, the second version of the malware to identify code attributes representing distinctive coding style preferences exhibited by a malware developer in coding the malware; identifying, by an inference engine application stored in a non-transitory memory and executed by a processor, at least one of a person of potential interest involved in committing the electronic crime under investigation or a group of potential interest involved in committing the electronic crime under investigation, the identifying comparing the identified distinctive coding style preferences of the electronic crime under investigation to the electronic crime signature data in the database to identify a known electronic crime attack corresponding to the electronic crime under investigation and the at least one person or group associated with the corresponding known electronic crime attack; and reporting, by a computer system, the electronic crime under investigation and the identified at least one person or group associated with the known electronic crime attack corresponding to the electronic crime under investigation. 2. The method of claim 1 , further comprising: investigating to confirm involvement of the at least one of the person and the group; and intervening to reduce the electronic crime threat posed by the at least one of the person and the group. 3. The method of claim 2 , wherein the intervening comprises at least one of moving to arrest at least one of the person and a member of the group, moving to freeze funds of an account associated with the electronic crime, moving to monitor communications of the at least one of the person and a member of the group, moving to monitor movements of at least one of the person and a member of the group, and moving to block an electronic crime technique that is a part of an attack signature associated by the database with at least one of the person and the group. 4. The method of claim 1 , wherein the at least one technique is a technique of monetization, and wherein the analyzing the technique of monetization includes analyzing a technique of compromised account authentication. 5. The method of claim 1 , further comprising implementing, by a computer system, at least one crime prevention or mitigation measure based in part on the corresponding known electronic crime attack, wherein the implementing the at least one crime prevention or mitigation measure comprises updating a fraud prevention application to reject intrusions by the malware. 6. The method of claim 1 , wherein the at least one technique is a technique of monetization, and wherein the analyzing the technique of monetizaton includes analyzing a technique of stealing funds from a compromised account. 7. The method of claim 1 , wherein the database comprises data gathered from at least one of a bank, a credit card issuer, an investment firm, a law enforcement agency, or a private investigation firm, and wherein the data comprises at least one of information about credential collection techniques, credential collection tools, monetization techniques, monetization tools, laundering techniques, laundering tools, identities of electronic criminals, identities of electronic crime groups, or identities of locations where electronic crime is initiated. 8. The method of claim 7 , wherein the database further comprises information linking at least one of the identities of electronic criminals, the identities of electronic crime groups, and the identities of locations where electronic crime is initiated with a combination of monetization techniques and laundering techniques. 9. The method of claim 1 , wherein analyzing the at least one technique further comprises determining, by an address locator application included in the one or more applications, a geographic location associated with a source of one or more computer messages suspected to be transmitted as part of the electronic crime, and wherein the geographic location determined by the address locator application identifies the source of the one or more computer messages that are suspected to be transmitted as part of the electronic crime to substantially an area of a city. 10. The method of claim 9 , further comprising implementing, by a computer system, at least one crime prevention or mitigation measure based in part on the corresponding known electronic crime attack, wherein the implementing the at least one crime prevention or mitigation measure comprises providing an additional level of authentication for one or more accounts. 11. The method of claim 10 , wherein the additional level of authentication comprises issuing an authentication challenge during set up of a transaction session to identify a geographic location of origin of an electronic message attempting to access an account. 12. The method of claim 11 , further comprising: receiving, by address locator application, a challenge response; comparing, by address locator application, a geographical location provided in the challenge response to the geographical location determined by the address locator application; and in response to the geographic location provided in the challenge response not matching the geographic location determined by the address locator application, rejecting the attempt to establish a communication session. 13. The method of claim 1 , further comprising implementing, by a computer system, at least one crime prevention or mitigation measure based in part on the corresponding known electronic crime attack, wherein implementing the at least crime prevention or mitigation measure comprises blocking an electronic crime technique that is a part of an attack signature associated by the database with the at least one of the person and the group identified by the inference engine. 14. The method of claim 1 , wherein the electronic crime attack signature data is related to at least one of a monetization phase and a laundering phase of an electronic crime business process. 15. The method of claim 1 , wherein the electronic crime signature data for each of the plurality of known electronic crime attacks specifies at least a set of actions taken and at least one of a technique and malware used in furtherance of the known electronic crime attack. 16. The method of claim 1 , wherein the distinctive coding style preferences comprises one or more of a preferred development programming language, a preferred development platform, a preferred compiler optimization setting or settings, a preferred obfuscation technique, a preferred structure statement method, and a preferred conditional jump trigger. 17. The method of claim 1 , wherein the one or more applications comprises an analysis application and a malware parser application, and wherein the analysis application translates the executable of the malware to the second version and the malware parser application analyzes the second version of the malware to identify code attributes representing

Assignees

Inventors

Classifications

  • G06Q40/00Primary

    Finance; Insurance; Tax strategies; Processing of corporate or income taxes · CPC title

  • by source code analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9904955B2 cover?
A system for electronic crime reduction is provided, comprising a computer system, a database, a malware de-compiler, a malware parser, and an inference engine. The database contains information that associates electronic crime attack signature data with at least one of an individual, a group, and a location. The malware de-compiler, when executed on the computer system, translates a first malw…
Who is the assignee on this patent?
Fireeye Inc
What technology area does this patent fall under?
Primary CPC classification G06Q40/00. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 27 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).