Detecting and blocking malicious files early in their transmission over a network
By generating partial file signatures to quickly identify and block malicious files, this technology solves the problems of high resource consumption and frequent false positives in existing technologies, and achieves early detection and efficient blocking of malicious file transmission.
Patent Information
- Application Number
- CN202110984220.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-06-29
- Filing Date
- 2021-08-25
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2041-08-25
AI Technical Summary
Existing technologies for blocking malicious files on the internet suffer from high resource consumption, frequent false positives and negatives, and an inability to detect them early.
The system receives malicious files, identifies their type and characteristics, generates a partial file signature, and uses this partial signature to quickly identify and block the malicious file, avoiding the need to process the entire file.
It saves computing and network resources, reduces false positives and negatives, and enables early detection and prevention of malicious file transfers.
Smart Images

Figure CN115549937B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present disclosure relate to the field of cybersecurity, and more specifically to countering cyberattacks and malicious files. BACKGROUND
[0002] Identifying malicious behavior (e.g., cyberattacks, malware, etc.) is often a time-consuming process for cybersecurity teams. There are many products that attempt to entice or trap bad actors (e.g., cyber intruders) to expose themselves, and these products trigger various actions from the network (e.g., block cyber intruders, stop malware and / or cyberattacks, etc.). SUMMARY
[0003] Some implementations described herein relate to a method. The method can include receiving a malicious file associated with a network of network devices and identifying a file type and file characteristics associated with the malicious file. The method can include determining one or more rules to apply to the malicious file based on the file type and file characteristics associated with the malicious file and applying the one or more rules to the malicious file to generate a partial file signature for the malicious file. The method can include providing the partial file signature for the malicious file to one or more of the network devices of the network, where the partial file signature can cause the one or more of the network devices to block the malicious file.
[0004] Some implementations described herein relate to a device. The device can include one or more memories and one or more processors. The one or more processors can be configured to receive a malicious file generated by a compromised terminal device associated with a network of network devices and identify a file type and file characteristics associated with the malicious file. The one or more processors can be configured to determine one or more rules to apply to the malicious file based on the file type and file characteristics associated with the malicious file and apply the one or more rules to the malicious file to generate a partial file signature for the malicious file. The one or more processors can be configured to provide the partial file signature for the malicious file to one or more of the network devices of the network, where the partial file signature can cause the one or more of the network devices to block the malicious file.
[0005] Some implementations described herein relate to a non-transitory computer- readable medium storing a set of instructions for a device. When (e.g., where "when" means "if" or "upon" and does not mean "while") the set of instructions is executed by one or more processors of the device, the set of instructions can cause the device to receive a malicious file associated with a network of network devices and identify a file type and file characteristics associated with the malicious file. When the set of instructions is executed by the one or more processors of the device, the set of instructions can cause the device to determine one or more rules applied to the malicious file based on the file type and file characteristics associated with the malicious file and apply the one or more rules to the malicious file to generate a partial file signature for the malicious file. When the set of instructions is executed by the one or more processors of the device, the set of instructions can cause the device to provide the partial file signature for the malicious file to one or more of the network devices of the network, where the partial file signature causes the one or more of the network devices to block the malicious file and transmit files other than the malicious file. BRIEF DESCRIPTION OF DRAWINGS
[0006] Figures 1A-1F is a diagram of an example associated with detecting and blocking malicious files early in transmission on a network.
[0007] Figure 2 is a diagram of an example environment in which the systems and / or methods described herein can be implemented.
[0008] Figure 3 and Figure 4 is a diagram of example components of one or more devices of Figure 2
[0009] Figure 5 is a flow diagram of an example process for detecting and blocking malicious files early in transmission on a network. DETAILED DESCRIPTION
[0010] The following detailed description implements the examples with reference to the accompanying drawings. The same reference numbers in different drawings can identify the same or similar elements.
[0011] Malicious behavior, such as that related to malicious files, cyberattacks, malware, etc., can be caused by a malicious actor (e.g., a cyber intruder) based on compromising a terminal device associated with a network. When a malicious file is identified (e.g., fingerprinted) and a fingerprint of the malicious file is identified, the malicious file can be blocked. However, current techniques for blocking malicious files can also create fingerprints that match other benign files that are not related to the malicious file (e.g., benign files tend to false positives and / or false negatives of the malicious file). Current techniques also utilize full file hashes to create fingerprints for malicious files. The entire malicious file needs to be utilized to create a full file hash, which reduces network traffic and consumes computing resources (e.g., processing resources, memory resources, communication resources, etc.), networking resources, and / or similar resources related to processing the entire malicious file, generating false positives and / or false negatives of the malicious file, failing to identify the malicious file, attempting to resolve false positives and / or false negatives of the malicious file, etc.
[0012] Some implementations described herein relate to a security system that is capable of detecting and blocking malicious files early in their transmission over a network. For example, the security system can receive a malicious file associated with a network of network devices and can identify a file type and file characteristics associated with the malicious file. The security system can determine one or more rules to apply to the malicious file based on the file type and file characteristics associated with the malicious file and can apply the one or more rules to the malicious file to generate a partial file signature for the malicious file. The security system can provide the partial file signature for the malicious file to one or more of the network devices of the network. The partial file signature can cause one or more of the network devices to block the malicious file.
[0013] In this way, the security system is capable of detecting and blocking malicious files early in their transmission over a network. The security system can detect the malicious file inline and fingerprint the malicious file early in the transmission of the malicious file. For some file types, the security system can utilize the first few bytes or kilobytes of the malicious file to generate a partial file signature for the malicious file. The security system can generate the partial file signature based on one or more rules that apply to different file types. For example, the security system can determine how many bytes or kilobytes of a certain type of file are sufficient to generate a partial file signature that does not match other benign files. Thus, the security system conserves computing resources, network resources, etc., that would otherwise be consumed by processing the entire malicious file, generating false positives and / or false negatives of the malicious file, failing to identify the malicious file, attempting to resolve false positives and / or false negatives of the malicious file, etc.
[0014] Figures 1A-1Fis a diagram of an example 100 associated with detecting and blocking malicious files that are early transmitted on a network. As shown Figures 1A-1F Example 100 includes a security system associated with a network of network devices, and a compromised end device, as shown. Further details of the security system, the network, the network devices, and the end device are provided elsewhere herein. In some implementations, the compromised end device can be considered an attacker end device when the end device is purposefully utilized by an attacker to generate a malicious file.
[0015] As shown Figure 1A and by reference number 105, the security system can receive, from one or more network devices, a malicious file associated with a compromised end device of the network. In some implementations, the malicious file can include a binary file (e.g., a Windows executable file, a Linux executable file, etc.), a regular executable file, an installation file, a self-extracting archive file, an archive file, a file with an unstructured header (e.g., a portable document format (PDF), a rich text format (RTF) file, etc.), and / or similar files associated with malicious behavior (e.g., a virus, a cyber attack, malware, a worm, a Trojan, spyware, etc.).
[0016] As shown Figure 1B by reference number 110, the security system can identify a file type and file characteristics associated with the malicious file. For example, the security system can determine that the file type of the malicious file is a binary file, an archive file, a file with an unstructured header, etc. If the security system identifies the file type of the malicious file as a binary file, the security system can determine file characteristics associated with the binary file, such as whether the binary file is a Windows executable file, a Linux executable file, a regular executable file, an installation file, a self-extracting archive file, etc. If the security system identifies the file type of the malicious file as a file with an unstructured header, the security system can determine file characteristics associated with the file with an unstructured header, such as whether the file with an unstructured header is a PDF file, an RTF file, etc.
[0017] The file characteristics can also include malicious data identifying malicious behavior (e.g., that the malicious file has been downloaded), malicious communication between network addresses (e.g., a media access control (MAC) address associated with the compromised end device, an internet protocol (IP) address associated with the compromised end device, a uniform resource locator (URL) address associated with the compromised end device, etc.), a serial number associated with the compromised end device, data identifying a manufacturer associated with the compromised end device, data identifying a make or model associated with the compromised end device, etc.
[0018] In some implementations, the security system (e.g., from a network device) receives network device data that identifies the network device associated with the network. This network device data may include the MAC address associated with the network device, the IP address associated with the network device, the serial number associated with the network device, data identifying the manufacturer associated with the network device, data identifying the manufacturing process or model associated with the network device, topology data (e.g., data identifying adjacent terminal devices and / or network devices, interconnections between terminal devices and / or network devices, etc.), etc. In some implementations, once the security system is notified of a malicious file, it configures the network device to forward the network device data.
[0019] Security systems can store malicious files, malicious data, and / or network device data in data structures (such as databases, tables, lists, etc.) associated with the security system. This data storage allows the security system to process it and generate security policies to prevent malicious files from further penetrating the network.
[0020] like Figure 1C As shown, and via reference numeral 115, a security system can determine one or more rules applied to a malicious file based on the file type and file characteristics associated with it. For example, when the malicious file is a binary file, the security system can determine one or more rules that cause it to identify whether the malicious file is a regular executable or an installer. When the malicious file is identified as a regular executable, the security system can determine one or more rules that cause it to hash (e.g., or utilize, transform to generate a unique result, etc.) a first number of bytes of the malicious file to generate a partial file signature. When the malicious file is identified as an installer, the security system can determine one or more rules that cause it to parse the malicious file to identify its compressed data and hash the first number of bytes of the malicious file and the compressed data to generate a partial file signature. This first number of bytes may include the first ten bytes, the first one hundred bytes, the first one thousand bytes, the first ten thousand bytes, etc., of the malicious file. Further details of partial file signatures are provided below.
[0021] In some implementations, when the malicious file is an archive file, the security system can determine one or more rules that cause the security system to hash a first number of bytes of the malicious file to generate a partial file signature.
[0022] In some implementations, when the malicious file is a file with an unstructured header, the security system can determine one or more rules that cause the system to parse the malicious file to identify the malicious bytes' code and hash a first number of bytes of the malicious file and the code of those malicious bytes to generate a partial file signature. The aforementioned one or more rules are merely examples of rules that a security system can determine to apply to malicious files, and these rules can differ in different contexts, such as for other file types associated with the malicious file.
[0023] like Figure 1D As shown, via reference numeral 120, a security system can apply one or more rules to a malicious file to generate a partial file signature targeting the malicious file. In some implementations, the security system can apply one or more rules to a malicious file to generate a partial file signature, fingerprint, or other identifier for the malicious file. A partial file signature allows a malicious file to be quickly identified without processing the entire malicious file. Since malicious files may include one of several file types (e.g., Windows executables, Microsoft Office files, Linux executables, macOS binaries, etc.), the security system can generate partial file signatures based on applying different rules applicable to different file types. A partial file signature can include a hash of a portion of the malicious file that is sufficient to identify the malicious file and does not match any benign file other than the malicious file. For example, the security system can apply one or more rules to a malicious file by hashing a first number of bytes of the malicious file to generate a partial file signature.
[0024] In some implementations, when a first number of bytes of a malicious file fail to identify it in a way that does not significantly reduce or eliminate false positives, the security system can also hash, transform, exploit, etc., one or more portions of the malicious file approximately in the middle (e.g., within five or ten percent of the middle portion of the malicious file) to generate a partial file signature. For example, if the malicious file contains one hundred bytes, the middle portion could be around byte 50 and from approximately byte 45 to approximately byte 55. The security system can also apply one or more rules to prevent any false positives from malicious files (e.g., identifying benign files based on partial file signatures). Each of the one or more portions can include a number of bytes large enough to identify the malicious file (e.g., far from the end of the malicious file). For example, each of the one or more portions could include ten, twenty, thirty, forty, etc. bytes from approximately the middle portion of the malicious file.
[0025] When the malicious file is a binary file, the security system can apply one or more rules to identify whether the malicious file is a regular executable file or an installer file. When the malicious file is a regular executable file, the security system can apply one or more rules to hash a first number of bytes of the malicious file to generate a partial file signature. When the malicious file is an installer file, the security system can apply one or more rules to parse the malicious file to identify its compressed data and hash a first number of bytes of the malicious file and the compressed data to generate a partial file signature.
[0026] When the malicious file is an archive file, the security system can apply one or more rules that cause the security system to hash a first number of bytes of the malicious file to generate a partial file signature.
[0027] When a malicious file is a file with an unstructured header, the security system can apply one or more rules to parse the malicious file to identify the malicious code bytes and hash a first number of bytes and the malicious code bytes to generate a partial file signature.
[0028] like Figure 1E As shown in Figure 125, a security system can hash the first N bytes (e.g., a first number of bytes) of a malicious file to generate a partial file signature. For example, when the malicious file is a regular executable or archive file, the security system can apply one or more rules that cause it to hash the first number of bytes of the malicious file to generate a partial file signature.
[0029] Alternative locations, such as Figure 1E As further illustrated by reference numeral 130 in the attached figure, the security system can hash the first N bytes and one or more portions of bytes (e.g., approximately in the middle) of a malicious file to generate a partial file signature. For example, when the malicious file is an installation file or a file with an unstructured header, the security system can apply one or more rules that cause the security system to hash a first number of bytes and one or more portions of bytes of the malicious file to generate a partial file signature.
[0030] like Figure 1FAs shown, the security system can provide the partial file signature for the malicious file to the network devices and / or the end devices of the network via the network devices via reference number 135. For example, the security system can provide the partial file signature to the network devices and other end devices using the addresses of the network devices and the compromised end devices. In some implementations, the security system can provide the partial file signature to one of the network devices and instruct the one of the network devices to forward the partial file signature to the other network devices. One of the network devices can forward the partial file signature to the other network devices and / or the compromised end devices based on the instruction.
[0031] As further shown in Figure 1F As further shown in
[0032] In some implementations, the one or more network devices and / or the compromised end devices can block traffic associated with the malicious file based on the partial file signature, can quarantine traffic associated with the malicious file based on the partial file signature, and / or the like. In this way, the compromised end devices can be prevented from spreading the malicious file to the network.
[0033] In some implementations, the security system can push a security update to the compromised end devices such that the compromised end devices can be better protected from the malicious file. In this way, the security update can eliminate the malicious file from the compromised end devices.
[0034] In some implementations, the security system can cause the compromised end devices to initiate a malware and / or virus scan to ensure that the compromised end devices are not infected with malware and / or viruses. In some implementations, the security system can cause the compromised end devices to go offline (e.g., disconnect from the network) such that the compromised end devices can not harm the network. In some implementations, the security system can send a notification for display on the compromised end devices (e.g., notifying a user that the end device has been compromised).
[0035] In this way, the security system is able to detect and block malicious files that are early in transmission on the network. The security system can inline detect a malicious file and fingerprint the malicious file as early as during transmission of the malicious file. For certain file types, the security system can utilize the first few bytes or kilobytes of a malicious file to generate a partial file signature for the malicious file. The security system can generate the partial file signature based on one or more rules that apply to different file types. For example, the security system can decide how many bytes or kilobytes of a certain type of file are sufficient to generate a partial file signature that does not match other benign files. Thus, the security system conserves computing resources, network resources, etc. that would otherwise be consumed by processing the entire malicious file, generating false positive and / or negative indications for the malicious file, failing to identify the malicious file, attempting to resolve false positive and / or negative indications for the malicious file, etc.
[0036] As indicated above, Figures 1A-1F are provided as examples. Other examples can differ from what is described Figures 1A-1F with respect to the examples described and / or contemplated herein. As Figures 1A-1F the number and arrangement of devices shown in FIG. 1 are provided as Figures 1A-1F examples. In practice, there can be additional devices, fewer devices, different devices, or differently arranged devices than those shown in FIG. 1. Furthermore, Figures 1A-1F two or more devices shown in FIG. 1 can be implemented within a single device, or Figures 1A-1F a single device shown in FIG. 1 can be implemented as multiple, distributed devices. Additionally, or alternatively, Figures 1A-1F a set of devices (e.g., one or more devices) shown in FIG. 1 can perform one or more functions described as being performed by another set of devices Figure 2 shown in FIG. 1.
[0037] Figure 2 is a schematic diagram of an example environment 200 in which systems and / or methods described herein can be implemented. As shown in Figure 2 environment 200 can include a security system 201, which can include and / or be executed within a cloud computing system 202. Cloud computing system 202 can include one or more elements 203-213, as described in greater detail below. As further shown in Figure 3 environment 200 can include a network 220, network devices 230, and / or end devices 240. Devices and / or elements of environment 200 can be interconnected via wired and / or wireless connections.
[0038] Cloud computing system 202 includes computing hardware 203, resource management component 204, host operating system (OS) 205, and / or one or more virtual computing systems 206. Cloud computing system 202 can execute on, for example, an Amazon Web Services platform, a Microsoft Azure platform, or a Snowflake platform. Resource management component 204 can perform virtualization (e.g., abstraction) of computing hardware 203 to create one or more virtual computing systems 206. Using virtualization, resource management component 204 enables a single computing device (e.g., a computer or a server) to operate like multiple computing devices, such as by creating multiple isolated virtual computing systems 206 from the computing hardware 203 of the single computing device. In this way, computing hardware 203 can operate more efficiently than using separate computing devices, with lower power consumption, higher reliability, higher availability, higher utilization, more flexibility, and lower cost.
[0039] Computing hardware 203 includes hardware and corresponding resources from one or more computing devices. For example, computing hardware 203 can include hardware from a single computing device (e.g., a single server) or multiple computing devices (e.g., multiple servers), such as multiple computing devices in one or more data centers. As shown, computing hardware 203 can include one or more processors 207, one or more memories 208, one or more storage components 209, and / or one or more networking components 210. Examples of processors, memories, storage components, and networking components (e.g., communication components) are described elsewhere herein.
[0040] Resource management component 204 includes a virtualization application (e.g., executing on hardware such as computing hardware 203) that is capable of virtualizing computing hardware 203 to launch, stop, and / or manage one or more virtual computing systems 206. For example, resource management component 204 can include a hypervisor (e.g., a bare-metal or type 1 hypervisor, a hosted or type 2 hypervisor, or other type of hypervisor) or a virtual machine monitor, such as when virtual computing systems 206 are virtual machines 211. Additionally or alternatively, resource management component 204 can include a container manager, such as when virtual computing systems 206 are containers 212. In some implementations, resource management component 204 executes within and / or in coordination with host operating system 205.
[0041] The virtual computing system 206 includes a virtual environment that can perform the operations and / or processes described herein using computing hardware 203 based in the cloud. As shown, the virtual computing system 206 can include virtual machines 211, containers 212, or a hybrid environment 213 that includes virtual machines and containers, among other examples. The virtual computing system 206 can execute one or more applications using a file system that includes binary files, software libraries, and / or other resources needed to execute the applications on a guest operating system (e.g., within the virtual computing system 206) or a host operating system 205.
[0042] Although the security system 201 can include one or more elements 203-213 of the cloud computing system 202, can be executed within the cloud computing system 202, and / or can be hosted within the cloud computing system 202, in some implementations, the security system 201 can not be cloud-based (e.g., can be implemented outside of a cloud computing system), or can be partially cloud-based. For example, the security system 201 can include one or more devices that are not part of the cloud computing system 202, such as Figure 2 the device 300 of FIG. 3, which can include a standalone server or other type of computing device. The security system 201 can perform one or more operations and / or processes described in greater detail elsewhere herein.
[0043] The network 220 includes one or more wired and / or wireless networks. For example, the network 220 can include a cellular network, a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a private network, the Internet, and / or a combination of these or other types of networks. The network 220 enables communication among the devices of the environment 200.
[0044] Network devices 230 can include one or more devices capable of receiving, processing, storing, routing and / or providing traffic (e.g., packets and / or other information or metadata) in the manner described herein. For example, network devices 230 can include routers, such as label-switched routers (LSRs), label edge routers (LERs), ingress routers, egress routers, provider routers (e.g., provider edge routers or provider core routers), virtual routers, or other types of routers. Additionally or alternatively, network devices 230 can include gateways, switches, firewalls, hubs, bridges, reverse proxies, servers (e.g., proxy servers, cloud servers, or data center servers), load balancers, and / or the like. In some implementations, network devices 230 can be physical devices implemented within an enclosure (e.g., a chassis). In some implementations, network devices 230 can be virtual devices implemented by one or more computing devices of a cloud computing environment or data center. In some implementations, set of network devices 230 can be a set of data center nodes for routing traffic through a network.
[0045] Terminal devices 240 include one or more devices capable of receiving, generating, storing, processing, and / or providing information, such as information described herein. For example, terminal devices 240 can include mobile phones (e.g., smartphones or wireless phones), notebook computers, tablet computers, desktop computers, handheld computers, gaming devices, wearable communication devices (e.g., smartwatches, smart glasses, heart rate monitors, fitness trackers, smart clothing, smart jewelry, or head-mounted displays), network devices, or similar types of devices. In some implementations, terminal devices 240 can receive network traffic from and / or provide network traffic to other terminal devices 240 via network 220 (e.g., by routing packets using network devices 230 as intermediaries).
[0046] Figure 2 The number and arrangement of devices and networks shown is provided as an example. In practice, there can be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or differently arranged devices and / or networks than those shown. Figure 2 There can be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or differently arranged devices and / or networks than those shown. Additionally, or alternatively, Figure 2 Two or more of the devices shown can be implemented within a single device, or Figure 3 A single device shown can be implemented as multiple, distributed devices. Additionally or alternatively, a set of devices (e.g., one or more devices) of environment 200 can perform one or more functions described as being performed by another set of devices of environment 200.
[0047] Figure 3 is Figure 3FIG. 1 illustrates an example system that can be used to implement a security system. The system can include a security system 201, a network device 230, and / or a terminal device 240. The security system 201, the network device 230, and / or the terminal device 240 can include one or more devices 300 and / or one or more components of the devices 300. As shown, the security system 201 can include a security system processor 210, a security system memory 220, a security system storage 230, a security system input 240, a security system output 250, and a security system communication component 260. The security system processor 210 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and / or other processing components. The security system processor 210 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the security system processor 210 includes one or more processors that are capable of being programmed to perform a function. The security system memory 220 includes a random access memory, a read only memory, and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory). The security system storage 230 stores information and / or software related to the operation of the security system 201. For example, the security system storage 230 can include a hard disk drive, a disk drive, an optical disk drive, a solid-state drive, an optical disk, a digital versatile disk, and / or another type of non-transitory computer-readable medium. The security system input 240 enables the security system 201 to receive input, such as user input and / or sensed input. For example, the security system input 240 can include a touchscreen, a keyboard, a keypad, a mouse, a button, a microphone, a switch, a sensor, a global positioning system component, an accelerometer, a gyroscope, and / or an actuator. The security system output 250 enables the security system 201 to provide output, such as via a display, a speaker, and / or one or more light-emitting diodes. The security system communication component 260 enables the security system 201 to communicate with other devices, such as via a wired connection and / or a wireless connection. For example, the security system communication component 260 can include a receiver, a transmitter, a transceiver, a modem, a network interface card, and / or an antenna. Figure 3 As shown, the device 300 can include a bus 310, a processor 320, a memory 330, a storage component 340, an input component 350, an output component 360, and a communication component 370.
[0048] The bus 310 includes a component that enables wired and / or wireless communication among the components of the device 300. The processor 320 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and / or other types of processing components. The processor 320 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the processor 320 includes one or more processors that are capable of being programmed to perform a function. The memory 330 includes a random access memory, a read only memory, and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory).
[0049] The storage component 340 stores information and / or software related to the operation of the device 300. For example, the storage component 340 can include a hard disk drive, a disk drive, an optical disk drive, a solid-state drive, an optical disk, a digital versatile disk, and / or another type of non-transitory computer-readable medium. The input component 350 enables the device 300 to receive input, such as user input and / or sensed input. For example, the input component 350 can include a touchscreen, a keyboard, a keypad, a mouse, a button, a microphone, a switch, a sensor, a global positioning system component, an accelerometer, a gyroscope, and / or an actuator. The output component 360 enables the device 300 to provide output, such as via a display, a speaker, and / or one or more light-emitting diodes. The communication component 370 enables the device 300 to communicate with other devices, such as via a wired connection and / or a wireless connection. For example, the communication component 370 can include a receiver, a transmitter, a transceiver, a modem, a network interface card, and / or an antenna.
[0050] Device 300 can perform one or more processes described herein. For example, a non-transitory computer-readable medium (e.g., memory 330 and / or storage component 340) can store a set of instructions (e.g., one or more instructions, code, software code, and / or program code) for execution by processor 320. The set of instructions can be executed by processor 320 to perform one or more processes described herein. In some implementations, the set of instructions executed by one or more processors 320 cause one or more processors 320 and / or device 300 to perform one or more processes described herein. In some implementations, hardwired circuitry can be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, implementations described herein are not limited to any specific combination of hardware circuitry and software.
[0051] Figure 4 The number and arrangement of components shown in FIG. 3 are provided as an example. Device 300 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 3. Additionally or alternatively, a set of components (e.g., one or more components) of device 300 can perform one or more functions described as being performed by another set of components of device 300. Figure 2
[0052] Figure 4 Figure 4 FIG. 4 is a diagram of example components of one or more devices of FIG. 1. Example components can be included in a device 400. Device 400 can correspond to network device 230. In some implementations, network device 230 can include one or more devices 400 and / or one or more components of device 400. As shown in FIG. 4, device 400 can include one or more of input components 410-1 through 410-B (B > 1) (hereinafter collectively referred to as input components 410, and individually as input component 410), switch component 420, output components 430-1 through 430-C (C > 1) (hereinafter collectively referred to as output components 430, and individually as output component 430), and controller 440. Figure 4
[0053] Input components 410 can be one or more points of attachment for physical links and can be one or more points of ingress for input traffic, such as packets. Input components 410 can process input traffic, such as by performing data link layer encapsulation or decapsulation. In some implementations, input components 410 can transmit and / or receive packets. In some implementations, input components 410 can include input line cards that include one or more packet processing components (e.g., in the form of integrated circuits), such as one or more interface cards (IFCs), packet forwarding components, line card controller components, input ports, processors, memories, and / or input queues. In some implementations, device 400 can include one or more input components 410.
[0054] Switch components 420 can interconnect input components 410 with output components 430. In some implementations, switch components 420 can be implemented via one or more crossbars, buses, and / or shared memories. Shared memories can act as temporary buffers to store packets from input components 410 before the packets are finally scheduled for delivery to output components 430. In some implementations, switch components 420 can enable input components 410, output components 430, and / or controller 440 to communicate with each other.
[0055] Output components 430 can store packets and can schedule packets for transmission on output physical links. Output components 430 can support data link layer encapsulation or decapsulation, and / or various higher-level protocols. In some implementations, output components 430 can transmit packets and / or receive packets. In some implementations, output components 430 can include output line cards that include one or more packet processing components (e.g., in the form of integrated circuits), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memories, and / or output queues. In some implementations, device 400 can include one or more output components 430. In some implementations, input components 410 and output components 430 can be implemented by the same set of components (e.g., an input / output component can be a combination of input components 410 and output components 430).
[0056] Controller 440 includes a processor, in the form of a CPU, GPU, APU, microprocessor, microcontroller, DSP, FPGA, ASIC, and / or other type of processor, for example. The processor is implemented in hardware, firmware, or a combination of software and hardware. In some implementations, controller 440 can include one or more processors that can be programmed to perform functions.
[0057] In some implementations, the controller 440 can include RAM, ROM, and / or other types of dynamic or static storage device (e.g., flash memory, magnetic storage, optical storage, etc.) that store information and / or instructions for use by or
[0058] In some implementations, the controller 440 can communicate with other devices, networks, and / or systems connected to the device 400 to exchange information about a network topology. The controller 440 can create a routing table based on the network topology information, can create a forwarding table based on the routing table, and can forward the forwarding table to the input component 410 and / or the output component 430. The input component 410 and / or the output component 430 can use the forwarding table to perform a routing lookup for an input and / or output packet.
[0059] The controller 440 can perform one or more processes described herein. The controller 440 can perform these processes in response to execution of software instructions stored by a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes a single physical storage location, or a plurality of physical storage locations, within a single physical storage device or distributed across multiple physical storage devices.
[0060] The software instructions can be read into the memory and / or storage components associated with the controller 440 from another computer-readable medium or from another device connected to the controller 440 via the communication interface. When executed, the software instructions stored in the memory and / or storage components associated with the controller 440 can cause the controller 440 to perform one or more processes described herein. Additionally, or alternatively, hardwired circuitry can be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, implementations described herein are not limited to any specific combination of hardware circuitry and software.
[0061] Figure 5 The number and arrangement of components shown in FIG. 4 are provided as an example. In practice, device 400 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally or alternatively, a set of components (e.g., one or more components) of device 400 can perform one or more functions described as being performed by another set of components of device 400. Figure 5 As shown, device 400 can include a plurality of components. The components shown in FIG. 4 can be implemented as hardware, software, firmware, or a combination thereof. For example, one or more of the components shown in FIG. 4 can be implemented as software instructions executed by a processor (e.g., controller 440) of device 400.
[0062] Figure 5 FIG. 5 is a flow diagram of an example process 500 for detecting and blocking early delivery of malicious files on a network. In some implementations, process 500 can be performed by a device (e.g., security system 201). In some implementations, one or more process blocks of process 500 can be performed by a device (e.g., security system 201). In some implementations, process 500 can be performed by a device (e.g., security system 201) in response to execution of software instructions stored by a non-transitory computer-readable medium. Figure 5 Figure 5 One or more process frames may be executed by another device or group of devices, either separate from or including the device, such as a network device (e.g., network device 230) and / or a terminal device (e.g., terminal device 240). Additionally or alternatively, Figure 5 One or more processing blocks can be executed by one or more components of device 300, such as processor 320, memory 330, storage component 340, input component 350, output component 360, and / or communication component 370. Additionally or alternatively, Figure 5 One or more processing blocks can be executed by one or more components of the device 400, such as input component 410, switch component 420, output component 430 and / or controller 440.
[0063] like Figure 5 As shown, process 500 may include receiving a malicious file associated with a network of a network device (box 510). For example, as described above, the device may receive a malicious file associated with a network of a network device.
[0064] like Figure 5 As further illustrated, process 500 may include identifying the file type and file characteristics associated with a malicious file (box 520). For example, as described above, the device may identify the file type and file characteristics associated with a malicious file.
[0065] like Figure 5 As further shown, process 500 may include determining one or more rules to be applied to a malicious file based on the file type and file characteristics associated with the malicious file (box 530). For example, as described above, the device may determine one or more rules to be applied to a malicious file based on the file type and file characteristics associated with the malicious file.
[0066] like Figure 5 As further illustrated, process 500 may include applying one or more rules to a malicious file to generate a partial file signature for the malicious file (box 540). For example, as described above, the device may apply one or more rules to a malicious file to generate a partial file signature for the malicious file. In some implementations, applying one or more rules to a malicious file to generate a partial file signature for the malicious file includes hashing a first number of bytes of the malicious file to generate a partial file signature. In some implementations, applying one or more rules to a malicious file to generate a partial file signature for the malicious file includes hashing a first number of bytes of the malicious file and bytes of one or more portions of the malicious file to generate a partial file signature. In some implementations, the bytes of one or more portions are located approximately in the middle of the malicious file. In some implementations, the bytes of one or more portions are located far from the end of the malicious file.
[0067] In some implementations, when the file type of the malicious file is a binary file, applying one or more rules to the malicious file to generate a partial file signature for the malicious file includes identifying whether the malicious file is a regular executable or an installer file; when the malicious file is a regular executable, hashing a first number of bytes of the malicious file to generate the partial file signature; and when the malicious file is an installer file, parsing the malicious file to identify compressed data of the malicious file, and hashing the first number of bytes of the malicious file and the compressed data to generate the partial file signature.
[0068] In some implementations, when the file type of the malicious file is an archive file, applying one or more rules to the malicious file to generate a partial file signature for the malicious file includes hashing a first number of bytes of the malicious file to generate the partial file signature.
[0069] In some implementations, when the file type of the malicious file is a file with an unstructured header, applying one or more rules to the malicious file to generate a partial file signature for the malicious file includes parsing the malicious file to identify a code of malicious bytes of the malicious file, and hashing the first number of bytes of the malicious file and the code of malicious bytes to generate the partial file signature.
[0070] In some implementations, when the file type of the malicious file is a regular executable or an archive file, applying one or more rules to the malicious file to generate a partial file signature for the malicious file includes hashing a first number of bytes of the malicious file to generate the partial file signature.
[0071] In some implementations, when the file type of the malicious file is an installer file or a file with an unstructured header, applying one or more rules to the malicious file to generate a partial file signature for the malicious file includes hashing a first number of bytes of the malicious file and one or more portions of bytes to generate the partial file signature. In some implementations, the one or more portions of bytes include a particular number of bytes and are located approximately in the middle of the malicious file.
[0072] As Figure 5Further shown, process 50 can include providing, to one or more network devices of the network, a partial file signature for the malicious file, where the partial file signature causes one or more of the network devices to block the malicious file (block 550). For example, as described above, the device can provide, to one or more of the network devices of the network, the partial file signature for the malicious file. In some implementations, the partial file signature causes one or more of the network devices to block the malicious file. In some implementations, the partial file signature causes one or more of the network devices to transmit a file other than the malicious file.
[0073] Process 500 can include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other processes described elsewhere herein.
[0074] Although Example blocks of process 500 are shown, but in some implementations, process 500 can include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in the figure. Additionally or alternatively, two or more of the blocks of process 500 can be performed in parallel. Example blocks of process 500 are shown, but in some implementations, process 500 can include additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in the figure. Additionally or alternatively, two or more of the blocks of process 500 can be performed in parallel.
[0075] According to some implementations, the following examples are disclosed.
[0076] Example 1. A method comprising: receiving, by a device, a malicious file associated with a network of a network device; identifying, by the device, a file type and file characteristics associated with the malicious file; determining, by the device, one or more rules to apply to the malicious file based on the file type and file characteristics associated with the malicious file; applying, by the device, the one or more rules to the malicious file to generate a partial file signature for the malicious file; and providing, by the device, the partial file signature for the malicious file to one or more of the network devices of the network, where the partial file signature causes one or more of the network devices to block the malicious file.
[0077] Example 2. The method of example 1, wherein applying the one or more rules to the malicious file to generate the partial file signature for the malicious file comprises hashing a first number of bytes of the malicious file to generate the partial file signature.
[0078] Example 3. The method of example 1, wherein applying the one or more rules to the malicious file to generate the partial file signature for the malicious file comprises hashing a first number of bytes of the malicious file and one or more portions of bytes to generate the partial file signature.
[0079] Example 4. The method of example 3, wherein the one or more portions of bytes are located at approximately a middle of the malicious file.
[0080] Example 5. The method of example 3, wherein the bytes of the one or more portions are located away from an end of the malicious file.
[0081] Example 6. The method of example 1, wherein when the file type of the malicious file is a binary file, applying the one or more rules to the malicious file to generate the partial file signature for the malicious file comprises: identifying whether the malicious file is a regular executable file or an installer file; when the malicious file is a regular executable file, hashing a first number of bytes of the malicious file to generate the partial file signature; and when the malicious file is an installer file: parsing the malicious file to identify compressed data of the malicious file, and hashing the first number of bytes of the malicious file and the compressed data to generate the partial file signature.
[0082] Example 7. The method of example 1, wherein when the file type of the malicious file is an archive file, applying the one or more rules to the malicious file to generate the partial file signature for the malicious file comprises: hashing a first number of bytes of the malicious file to generate the partial file signature.
[0083] Example 8. A device comprising: one or more memories; and one or more processors to: receive a malicious file generated by a compromised end device associated with a network of a network device; identify a file type and file characteristics associated with the malicious file; determine one or more rules to apply to the malicious file based on the file type and file characteristics associated with the malicious file; apply the one or more rules to the malicious file to generate a partial file signature for the malicious file; and provide the partial file signature for the malicious file to one or more of the network devices of the network, wherein the partial file signature causes the one or more of the network devices to block the malicious file.
[0084] Example 9. The device of example 8, wherein when the file type of the malicious file is a file with an unstructured header, the one or more processors apply the one or more rules to the malicious file to generate the partial file signature for the malicious file to: parse the malicious file to identify a code of malicious bytes of the malicious file; and hash a first number of bytes of the malicious file and the code of the malicious bytes to generate the partial file signature.
[0085] Example 10. The device of example 8, wherein the partial file signature causes the one or more of the network devices to transmit a file other than the malicious file.
[0086] Example 11. The device of example 8, wherein when the file type of the malicious file is a regular executable file or an archive file, the one or more processors apply one or more rules to the malicious file to generate a partial file signature for the malicious file to: hash a first number of bytes of the malicious file to generate the partial file signature.
[0087] Example 12. The device of example 8, wherein when the file type of the malicious file is an installation file or a file with an unstructured header, the one or more processors apply one or more rules to the malicious file to generate a partial file signature for the malicious file to: hash a first number of bytes of the malicious file and one or more portions of bytes to generate the partial file signature.
[0088] Example 13. The device of example 12, wherein the one or more portions of bytes comprise a particular number of bytes.
[0089] Example 14. The device of example 12, wherein the one or more portions of bytes are located at approximately a middle of the malicious file.
[0090] Example 15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the device to: receive a malicious file associated with a network of a network device; identify a file type and file characteristics associated with the malicious file; determine one or more rules to apply to the malicious file based on the file type and file characteristics associated with the malicious file; apply the one or more rules to the malicious file to generate a partial file signature for the malicious file; and provide the partial file signature for the malicious file to one or more of the network devices of the network, wherein the partial file signature causes the one or more of the network devices to block the malicious file and transmit files other than the malicious file.
[0091] Example 16. The non-transitory computer-readable medium of example 15, wherein the one or more instructions that cause the device to apply the one or more rules to the malicious file to generate the partial file signature for the malicious file cause the device to perform one of: hash a first number of bytes of the malicious file to generate the partial file signature; or hash the first number of bytes of the malicious file and one or more portions of bytes to generate the partial file signature.
[0092] Example 17. The non-transitory computer-readable medium of example 16, wherein the one or more portions of bytes are located at approximately a middle of the malicious file.
[0093] Example 18. The non-transitory computer-readable medium of example 15, wherein the one or more instructions that, as a result of being executed, cause the device to apply one or more rules to the malicious file to generate a partial file signature for the malicious file, cause the device to: identify whether the malicious file is a regular executable file or an installer file; when the malicious file is a regular executable file, hash a first number of bytes of the malicious file to generate the partial file signature; and when the malicious file is an installer file: parse the malicious file to identify compressed data of the malicious file, and hash the first number of bytes of the malicious file and the compressed data to generate the partial file signature.
[0094] Example 19. The non-transitory computer-readable medium of example 15, wherein the one or more instructions that, as a result of being executed, cause the device to apply one or more rules to the malicious file to generate a partial file signature for the malicious file, cause the device to hash a first number of bytes of the malicious file to generate the partial file signature when the file type of the malicious file is an archive file.
[0095] Example 20. The non-transitory computer-readable medium of example 15, wherein the one or more instructions that, as a result of being executed, cause the device to apply one or more rules to the malicious file to generate a partial file signature for the malicious file, cause the device to: parse the malicious file to identify a code of malicious bytes of the malicious file; and hash the first number of bytes of the malicious file and the code of malicious bytes to generate the partial file signature when the file type of the malicious file is a file with an unstructured header.
[0096] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementations to the precise form disclosed. Modifications can occur based on practice of the disclosure, either currently known or in the future developed.
[0097] As used in this document, the term "component" is intended to be broadly interpreted, to include hardware, firmware, or a combination of hardware and software. It will be apparent that systems and / or methods described herein can be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the implementations. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code — it being understood that software and hardware can be used to implement the systems and / or methods, as would be understood by those skilled in the art.
[0098] Although specific combinations of features are listed in the claims and / or described in the specification, the disclosure is not limited to these combinations. Indeed, many combinations of the features are possible, even if not specifically listed in the claims and / or described in the specification. Although each dependent claim listed below can only directly depend on one claim, the disclosure of various implementations includes each dependent claim in combination with every other claim in the set.
[0099] No element, act or instruction used in the present disclosure should be construed as critical or essential unless explicitly stated as such. Also, as used herein, the article “a” and “an” is intended to include one or more items, and can be used interchangeably with “one or more.” Furthermore, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, etc.), and can be used interchangeably with “one or more.” Where only one item is intended, the phrase “only one” or similar language is used. Also, as used herein, the terms “has,” “have,” “having,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Also, as used herein, the term “or” is intended to be inclusive when used in a series of items (e.g., “a, b, or c” or “a, b, and c”) unless explicitly stated otherwise (e.g., if used in the context “either a, b, or only one of a and b”).
[0100] In the foregoing specification, various example embodiments have been described. However, it is evident that various modifications and changes can be made thereto without departing from the broader spirit and scope of the application as set forth in the appended claims. The Specification and drawings are, accordingly, to be regarded in an illustrative rather than a restrictive sense.
Claims
1. A method comprising: The device receives malicious files generated by a compromised terminal device associated with the network device's network. The device identifies the file type and file characteristics associated with the malicious file. The file characteristics are based on the file type; The device determines one or more rules to be applied to the malicious file based on the file type and file characteristics associated with the malicious file; The device applies one or more rules to the malicious file to generate a partial file signature for the malicious file; as well as The device provides the partial file signature for the malicious file to one or more network devices in the network. The file signature wherein the partial file signature enables one or more network devices in the network device to block the malicious file. Applying one or more rules to the malicious file to generate the partial file signature for the malicious file includes: Hash a first number of bytes and one or more portions of bytes from the malicious file to generate a partial file signature. The first number of bytes are located at the beginning of the malicious file, and the bytes of the one or more portions are located away from the end of the malicious file.
2. The method according to claim 1, wherein the bytes of one or more portions are located in the middle of the malicious file.
3. The method according to claim 1, wherein when the file type of the malicious file is a binary file, applying the one or more rules to the malicious file to generate a partial file signature for the malicious file includes: Indicate whether the malicious file is a regular executable file or an installation file; When the malicious file is a regular executable file, a first number of bytes of the malicious file are hashed to generate the partial file signature; as well as When the malicious file is an installation file: Parse the malicious file to identify the compressed data of the malicious file, and The first number of bytes of the malicious file and the compressed data are hashed to generate the partial file signature.
4. The method according to claim 1, wherein when the file type of the malicious file is an archive file, applying the one or more rules to the malicious file to generate a partial file signature for the malicious file includes: A first number of bytes of the malicious file are hashed to generate the partial file signature.
5. An apparatus comprising: One or more memory units; as well as One or more processors, used to: Receive malicious files generated by compromised terminal devices associated with the network of the network device; Identify the file type and file characteristics associated with the malicious file. The file characteristics are based on the file type; One or more rules are determined based on the file type and file characteristics associated with the malicious file; Apply one or more of the rules to the malicious file to generate a partial file signature for the malicious file; as well as Provide the partial file signature for the malicious file to one or more network devices in the network. The file signature wherein the partial file signature enables one or more network devices in the network device to block the malicious file. When the malicious file is an installation file or a file with an unstructured header, the one or more processors apply the one or more rules to the malicious file to generate the partial file signature for the malicious file, in order to: Hash a first number of bytes and one or more portions of bytes from the malicious file to generate a partial file signature. The first number of bytes are located at the beginning of the malicious file, and the bytes of the one or more portions are located away from the end of the malicious file.
6. The apparatus of claim 5, wherein when the file type of the malicious file is a file with an unstructured header, the one or more processors apply the one or more rules to the malicious file to generate the partial file signature for the malicious file, so as to: The code that parses the malicious file to identify the malicious bytes of the malicious file; and A first number of bytes of the malicious file and the code of the malicious bytes are hashed to generate the partial file signature.
7. The device of claim 5, wherein the partial file signature enables the one or more network devices in the network device to transmit files other than the malicious file.
8. The device of claim 5, wherein the bytes of said one or more portions include a specific number of bytes.
9. The device of claim 5, wherein the bytes of one or more portions are located in the middle of the malicious file.
10. A non-transient computer-readable medium storing an instruction set, the instruction set comprising: One or more instructions, which, when executed by one or more processors of the device, cause the device to: Receive malicious files associated with network devices; Identify the file type and file characteristics associated with the malicious file. The file characteristics are based on the file type; One or more rules are determined based on the file type and file characteristics associated with the malicious file; Apply one or more of the rules to the malicious file to generate a partial file signature for the malicious file; as well as Provide the partial file signature for the malicious file to one or more network devices in the network. The partial file signature enables one or more network devices in the network apparatus to block the malicious file and transmit files other than the malicious file. The one or more instructions that cause the device to apply the one or more rules to the malicious file to generate a partial file signature for the malicious file cause the device to: Hash a first number of bytes and one or more portions of bytes from the malicious file to generate a partial file signature. The first number of bytes are located at the beginning of the malicious file, and the bytes of the one or more portions are located away from the end of the malicious file.
11. The non-transient computer-readable medium of claim 10, wherein the bytes of one or more portions are located in the middle of the malicious file.
12. The non-transient computer-readable medium of claim 10, wherein when the file type of the malicious file is a binary file, the device applies the one or more rules to the malicious file to generate the one or more instructions for the partial file signature of the malicious file, causing the device to: Indicate whether the malicious file is a regular executable file or an installation file; When the malicious file is a regular executable file, a first number of bytes of the malicious file are hashed to generate the partial file signature; and When the malicious file is an installation file: Parse the malicious file to identify the compressed data of the malicious file, and The first number of bytes of the malicious file and the compressed data are hashed to generate a partial file signature.
13. The non-transient computer-readable medium of claim 10, wherein when the file type of the malicious file is an archive file, the device applies the one or more rules to the malicious file to generate the one or more instructions for the partial file signature of the malicious file, causing the device to: A first number of bytes of the malicious file are hashed to generate the partial file signature.
14. The non-transient computer-readable medium of claim 10, wherein when the file type of the malicious file is a file with an unstructured header, the device applies the one or more rules to the malicious file to generate the one or more instructions for the partial file signature of the malicious file, causing the device to: The code that parses the malicious file to identify the malicious bytes of the malicious file; and A first number of bytes of the malicious file and the code of the malicious bytes are hashed to generate the partial file signature.
Citation Information
Patent Citations
Method, system and apparatus for obtaining document related information
CN101282341A
Method and system for generating a request for information on a file to perform an antivirus scan
CN110659484A
Analysis of Malware
US20210117544A1