EP2963577B1

Method for malware analysis based on data clustering

Abstract

This record has no abstract on file.

EP2963577B1, drawing sheet 1
Sheet 1 of 37

Term

8.8 yearsleft in the term

Expires 2 July 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

12 claims: 6 independent, 6 dependent

  1. 1
    A computer system (110) comprising:one or more computer readable storage devices configured to store: a plurality of computer executable instructions;a data clustering strategy;and a plurality of data items including at least: file data items, each file data item associated with at least one suspected malware file and one or more network indicators;and network-related data items associated with captured communications between an internal network and an external network, the network-related data items including at least one of: external Internet Protocol addresses, external domains, external computerized devices, internal Internet Protocol addresses, internal computerized devices, users of particular computerized devices, or organizational positions associated with users of particular computerized devices;and one or more hardware computer processors (860) in communication with the one or more computer readable storage devices and configured to execute the plurality of computer executable instructions in order to cause the computer system to: access, from the one or more computer readable storage devices, the file data items;initiate an analysis of each file data item including the at least one suspected malware file, wherein the analysis of each file data item generates a plurality of analysis information items including at least one of calculated hashes, file properties, academic analysis information, file execution information, or third-party analysis information;wherein initiating an analysis of each file data item comprises: initiating an internal analysis of the file data item;and initiating an external analysis of the file data item, wherein the internal analysis includes analysis performed by the one or more hardware computer processors, and wherein the internal analysis includes at least one of calculation of an MD5 hash of the file data item, calculation of a SHA-1 hash of the file data item, or calculation of a size of the file data item, and wherein the external analysis includes analysis performed by at least a second computer system, and wherein the external analysis includes execution of the file data item in a sandboxed environment and analysis of the file data item by a third-party malware analysis service;associate the plurality of analysis information items with each file data item;and generate a user interface including one or more user selectable portions presenting various of the analysis information items, the user interface usable by the human analyst to determine one or more characteristics of the file data item and to mark the file data item as a seed;determine, for each file data item of the file data items, whether or not the file data item has been marked by a human analyst as a seed;and for each of the file data items marked as a seed, generate a data item cluster based on the data clustering strategy by at least: adding the seed to the data item cluster;identifying one or more of the network indicators that are associated with the seed;identifying one or more of the network-related data items associated with at least one of the identified one or more of the network indicators;adding, to the data item cluster, the one or more identified network-related data items;identifying an additional one or more data items, including file data items and/or network-related data items, associated with any data items of the data item cluster;and adding, to the data item cluster, the additional one or more data items.
  2. 2
    The computer system of Claim 1, wherein each of the data items of the data item cluster identify at least an internal computerized device, a user of the internal computerized device, and an organizational position associated with the user.
  3. 3
    The computer system of Claim 1 or 2, wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to cause the one or more hardware computer processors to:scan communications between the internal network and the external network so as to identify additional network-related data items;and store the additional network-related data items in the one or more computer readable storage devices;and optionally, wherein the communications are continuously scanned via a proxy.
  4. 4
    The computer system of any preceding Claim, wherein the one or more network indicators include at least an external Internet Protocol address or an external domain.
  5. 5
    The computer system of any preceding Claim, wherein the one or more of the network indicators that are associated with the seed comprise network indicators that are contacted by the at least one suspected malware file associated with the seed when the at least one suspected malware file is executed.
  6. 6
    The computer system of any preceding Claim, wherein the file data item is marked by a human analyst as a seed via a user interface of the computer system.
  7. 7
    The computer system of any preceding Claim, wherein:the one or more computer readable storage devices are further configured to store: a plurality of data cluster analysis rules associated with the data clustering strategy, and the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to cause the one or more hardware computer processors to: for each generated data item cluster: access the plurality of data cluster analysis rules associated with the data clustering strategy;analyze the data item cluster based on the accessed data cluster analysis rules;and based on the analysis of the data item cluster: determine an alert score for the data item cluster;and generate one or more human-readable conclusions regarding the data item cluster.
  8. 8
    The computer system of Claim 7, wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to cause the computer system to:for each generated data item cluster: generate an alert, the alert comprising the alert score, the one or more human-readable conclusions, the data items associated with the data item cluster, and metadata associated with the data items of the data item cluster.
  9. 9
    The computer system of Claim 8, wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to cause the computer system to:generate a user interface including a list of user-selectable alert indicators, an alert indicator being provided for each of the generated alerts, each of the alert indicators providing a summary of information associated with respective generated alerts.
  10. 10
    The computer system of Claim 9, wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to cause the computer system to:in response to a selection of an alert indicator by a human analyst: generate an alert display, the alert display including at least an indication of the alert score and a list of the one or more human-readable conclusions.
  11. 11
    The computer system of any of Claims 7-10, wherein the one or more human-readable conclusions each comprise a phrase or sentence including one or more indications of summary or aggregated data associated with a plurality of the data items of the data item cluster.
  12. 12
    The computer system of Claim 11, wherein generating the one or more human-readable conclusions comprises:selecting, based on the data cluster type associated with the particular data cluster, one or more conclusion templates;and populating the one or more conclusion templates with data associated with the particular data cluster.