EP3018879B1

Malicious software detection in a computing system

Abstract

This record has no abstract on file.

EP3018879B1, drawing sheet 1
Sheet 1 of 26

Term

9.1 yearsleft in the term

Expires 5 November 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

11 claims: 8 independent, 3 dependent

  1. 1
    A computer system to identify malicious Uniform Resource Locator (URL) data items from a plurality of unscreened data items that have not been previously identified as associated with malicious URLs, the system comprising:one or more computer readable storage devices configured to store: one or more software modules including computer executable instructions, the plurality of unscreened data items associated with communications between computerized devices within a local network and external resources, the unscreened data items comprising a plurality of device identifiers for the computerized devices and a plurality of URLs referencing the external resources, an expected distribution of n-grams for filepaths associated with a domain name having a rank indicating that the domain name is associated with an amount of Internet traffic, and an actual distribution of n-grams for filepaths associated with the domain name;a network connection configured to access (522), from a remote network not within the local network, a traffic rank list of domain names satisfying a traffic ranking condition based on Internet traffic data;and one or more hardware computer processors in communication with the one or more computer readable storage devices and configured to execute the one or more software modules in order to cause the computer system to: access, from the one or more computer readable storage devices, the plurality of unscreened data items;identify, from the plurality of unscreened data items, a plurality of connection records, each of the connection records indicating a communication from a computerized device to an external resource at a specific time, such that each of the connection records is associated with a device identifier and a URL, identify, from the plurality of connection records, one or more connection records having a common device identifier, the identified one or more connection records associated with one or more URLs;parse (524) the one or more URLs for one or more domain names, each of the one or more URLs associated with a domain name;based on a determination (526) that none of the one or more domain names satisfies a threshold position in the list of domain names, designate (528) the one or more URLs as possible malicious URL data items;compare (726) the expected distribution of n-grams for filepaths associated with a domain name of the one or more domain names to the actual distribution of n-grams for filepaths associated with the domain name;and assign a score based on a plurality of factors relating to the possible malicious URL data items, the factors comprising at least (i) the determination that none of the one or more domain names satisfies the threshold position in the list of domain names, and (ii) a variance between the distributions.
  2. 2
    The system of Claim 1, the plurality of unscreened data items comprising a plurality of beaconing malware-related data items and the one or more hardware computer processors further configured to execute the one or more software modules in order to cause the computer system to access, from the one or more computer readable storage devices, the plurality of beaconing malware-related data items; generate (304), based on the accessed beaconing malware-related data items, a plurality of connection pairs, each of the connection pairs indicating communications between an internal source within the local network and an external destination that is not within the local network; identify a plurality of connection pairs having a common internal source and a common external destination; generate (306) a time series of connection pairs based on the identified plurality of connection pairs; filter out noise (308) from the at least one time series to generate a filtered at least one time series; compute a variance (310A) in the filtered at least one time series; and based on a determination that the variance satisfies a threshold:designate (312) a connection pair associated with the filtered at least one time series as a seed, the designated connection pair including the common internal source and the common external source;generate (324) a data item cluster based on the designated seed, wherein generating the data item cluster comprises: adding the designated seed to the data item cluster;accessing, from the one or more computer readable storage devices, the clustering strategy;and adding to the data item cluster, based on the clustering strategy, one or more beaconing malware-related data items determined to be associated with the designated seed;and score the generated data item cluster, the factors comprising the data item cluster score.
  3. 3
    The system of Claim 1 or Claim 2, the one or more computer readable storage devices configured to store a plurality of domain names associated with URLs in communications from computerized devices within a local network from a period of time, and the one or more hardware computer processors further configured to execute the one or more software modules in order to cause the computer system to access (402), from the one or more computer readable storage devices, the plurality of domain names;based on a determination (406) that none of the one or more domain names is included in the plurality of domain names, designate (408) the one or more URLs as possible malicious URL data items, the factors comprising the determination that none of the one or more domain names is included in the plurality of domain names.
  4. 4
    The system of any of Claims 1-3, the one or more computer readable storage devices configured to store a plurality of dictionary words, and the one or more hardware computer processors further configured to execute the one or more software modules in order to cause the computer system to access (502), from the one or more computer readable storage devices, the plurality of dictionary words;based on a determination (506) that none of the one or more domain names is included in the plurality of dictionary words, designate (508) the one or more URLs as possible malicious URL data items, the factors comprising the determination that none of the one or more domain names is included in the plurality of dictionary words.
  5. 5
    The system of any of Claims 1-4, the one or more computer readable storage devices configured to store a plurality of filepaths associated with URLs in communications from computerized devices within a local network from a period of time, and the one or more hardware computer processors further configured to execute the one or more software modules in order to cause the computer system to access (422), from the one or more computer readable storage devices, the plurality of filepaths;parse (424) a URL for an associated filepath;based on a determination (426) that the filepath is included in the plurality of filepaths, designate (428) the URL as a possible malicious URL data item, the factors comprising the determination that the filepath is included in the plurality of filepaths.
  6. 6
    The system of any of Claims 1-5, the network connection configured to access, from a remote network not within the local network, an Internet search engine providing an autocomplete function that automatically displays words to complete a query entered into the search engine and to receive from the remote network the words suggested by the autocomplete function, the one or more computer readable storage devices configured to store a list of words associated with malicious software;and the one or more hardware computer processors further configured to execute the one or more software modules in order to cause the computer system to transmit (804) to the Internet search engine a query comprising a domain name associated with a URL, and receive (806) words displayed by the search engine in response to the query, the factors comprising the received words that are also included in the list of words.
  7. 7
    The system of any of Claims 1-6, the network connection configured to access, from a remote network not within the local network, an Internet service providing WHOIS and/or DNS registration data to receive from the remote network domain registration data, the one or more hardware computer processors further configured to execute the one or more software modules in order to cause the computer system to transmit (904) to the Internet service search engine a query comprising a domain name associated with a URL, and receive a domain registration date in response to the query;the factors comprising the received domain registration date.
  8. 8
    The system of any of Claims 1-7, the score based on a Support Vector Machine model, a Neural Network model, a Decision Tree model, a Naive Bayes model, or a Logistic Regression model.
  9. 9
    A method for identifying malicious Uniform Resource Locator (URL) data items from a plurality of unscreened data items that have not been previously identified as associated with malicious URLs, the method comprising:accessing, from one or more computer readable storage devices, the plurality of unscreened data items, wherein the plurality of unscreened data items are associated with communications between computerized devices within a local network and external resources, the unscreened data items comprising a plurality of device identifiers for the computerized devices and a plurality of URLs referencing the external resources;identifying, from the plurality of unscreened data items, a plurality of connection records, each of the connection records indicating a communication from a computerized device to an external resource at a specific time, such that each of the connection records is associated with a device identifier and a URL, identifying, from the plurality of connection records, one or more connection records having a common device identifier, the identified one or more connection records associated with one or more URLs;parsing (524) the one or more URLs for one or more domain names, each of the one or more URLs associated with a domain name;based on a determination (526) that none of the one or more domain names satisfies a threshold position in a list of domain names, designating (528) the one or more URLs as possible malicious URL data items, wherein the list of domain names is a traffic rank list of domain names satisfying a traffic ranking condition based on Internet traffic data, and wherein the list of domain names is accessed (522) from a remote network not within the local network;accessing (722) data indicating an expected distribution of n-grams for filepaths associated with a domain name of the one or more domain names, the domain name having a rank indicating that the domain name is associated with an amount of Internet traffic;determining (724) an actual distribution of n-grams for filepaths associated with the domain name;comparing (726) the expected distribution of n-grams to the actual distribution of n-grams;and assigning a score based on a plurality of factors relating to the possible malicious URL data items, the factors comprising at least (i) the determination that none of the one or more domain names satisfies the threshold position in the list of domain names, and (ii) a variance between the distributions.
  10. 10
    The method of Claim 9, wherein the method is adapted to be executed by a system according to any of Claims 1-8.
  11. 11
    One or more transitory or non-transitory computer-readable media storing one or more computer programs, the one or more computer programs comprising instructions to cause a computer system to perform operations including the operations recited in any of Claims 1-10.