Malware and exploit campaign detection system and method

4 downloads 42088 Views 2MB Size Report
Mar 12, 2015 - vices (BDS) employ virtual “sandboxes” or “honey nets” that operate in a cloud (virtual) ..... sions of OS X, iOS, and Android. One key feature for ...
US 20150074810A1

(19) United States (12) Patent Application Publication (10) Pub. N0.: US 2015/0074810 A1 SAHER et al. (54)

(43) Pub. Date:

MALWARE AND EXPLOIT CAMPAIGN

(52)

DETECTION SYSTEM AND METHOD _

(71)

Mar. 12, 2015

US. Cl. CPC ...... .. H04L 63/1466 (2013.01); H04L 63/1416

_

(2013.01); G06F 9/45558 (2013.01)

Apphcant NSS Labs’ Inc" Ausnn’ TX (Us)

USPC .......................................................... .. 726/23

(72) Inventors: Mohamed SAHER, Austin, TX (U S); J ayendra PATHAK, Austin, TX (US)

(57)

ABSTRACT

(73) Assignee: NSS Labs, Inc. (21) Appl' NO': 14/482’696

A malware and exploit campaign detection system and

(22)

method are provided that cannot be detected by the malware or exploit campaign. The system may provide threat feed data to the vendors that produce in-line network security and end

Filed,

sep_ 10, 2014 Related US, Application Data

. .

.

.

point protection (anti virus) technologies. The system may

(60) ?oélslgnal apphcanon NO' 61/876’704’ ?led on sep' ’

also be used as a testing platform for 3rd party products. Due

'

to the massive footprint of the system’s cloud infrastructure

Publication Classi?cation

and disparate network connections and geo-location obfus cation techniques, NSS can locate and monitor malware

(51)

Int, Cl, H04L 29/06

(2006.01)

across the globe and provide detailed threat analysis for each speci?c region, as they often support and host different mal

G06F 9/455

(2006.01)

ware/cybercrime campaigns.

CONTROLLER PROCESS

EXPLENT FEEDS CAPTUHE

PROCESS

{Fad‘vlunuatn '~ , mum DATABASE 5;

.... _‘ 11.81%? ~~~~~~~~~~ -~

REPLAY

A

"

; THREADS 5 THREAD4 :

,.ENUMEHATiUN PHUCESS

GETREMUTE " ‘

;'PAHAMATEHS ;

H

Patent Application Publication

Mar. 12, 2015 Sheet 1 0f 9

FIGURE 1

US 2015/0074810 A1

Patent Application Publication

Mar. 12, 2015 Sheet 2 0f 9

CUNTRDLLERPHUCESS

US 2015/0074810 A1

EXRARREEERR ..

.......... ..

,

~

I

y

E

BURRELATE

THREADA O .............

FEEDS

E

RARRARE

PROCESS

I

THREADE V

,

A

~ FETCH LIST OF M ‘

V,

AWVM'SAREPLAY]

i, ....................................... ..

A EErcR FROM DATABASE VALID i URL ,A'%

Suggest Documents