Supply Chain Attack Detection
The method addresses the challenge of detecting malicious actions in signed software applications by classifying instances of software applications as benign or suspicious based on collected action information, effectively enhancing computer network security.
Patent Information
- Application Number
- JP2024504256
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-07-05
- Filing Date
- 2023-06-13
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2043-06-13
AI Technical Summary
Existing computer security systems struggle to detect malicious actions performed by signed software applications deployed across multiple host computers in different enterprises, particularly in cases of supply chain attacks.
A method that identifies instances of software applications running on multiple host computers, collects information about actions performed by these instances, calculates features based on this information, and classifies the instances as benign or suspicious using a processor, generating alerts only for suspicious instances.
This approach enables the detection of abnormal and potentially malicious actions by signed software applications, even if they are deployed across multiple enterprises, thereby enhancing the security of computer networks.
Smart Images

Figure 0007687642000003 
Figure 0007687642000004 
Figure 0007687642000005
Abstract
Description
Technical Field
[0001] The present invention generally relates to computer security and networks. And in particular, it relates to detecting anomalous actions performed by a given instance of a software application deployed on multiple host computers in multiple enterprises.
Background Art
[0002] In many computer and network systems, multiple layers of security devices and software are deployed to detect and repel the ever-increasing range of security threats. At the most basic level, computers use antivirus software to prevent unauthorized programs from being executed on the computer. At the network level, intrusion detection and prevention systems analyze and control network traffic to detect and prevent malware from spreading through the network.
[0003] The above description is presented as a general overview of related technologies in this field, and it should not be construed as an admission that any of the information it contains constitutes prior art to this patent application.
Summary of the Invention
[0004] According to one embodiment of the present invention, a method is provided. The method includes identifying a plurality of host computers each running an instance of a particular software application, where each given instance on each given host computer includes a set of program instructions loaded from a respective storage device by the host computer; collecting information from the host computer about actions performed by the instance being run; calculating features based on the information collected from the plurality of host computers; comparing, by a processor, the collected information about the given instance to the features to classify the given instance as benign or suspicious; and generating an alert for the given instance only when the given instance is classified as suspicious.
[0005] In some embodiments, the information includes an action type and an entity.
[0006] In a first information embodiment, the action type of a given action includes creating or injecting a process, and the entity of the given action includes a process having a process name.
[0007] In a second information embodiment, the action type of a given action includes accessing a domain, and the entity of the given action includes a domain name.
[0008] In a third information embodiment, the action type of a given action includes accessing an Internet Protocol (IP) address, and the entity of the given action includes an IP address.
[0009] In an embodiment of the fourth information, the action type of a given action includes accessing an autonomous system number (ASN) address, and the entity of the given action includes an ASN.
[0010] In an embodiment of the fifth information, the action type of a given action includes loading a shared library, and the entity of the given action includes a shared library having respective names.
[0011] In an embodiment of the sixth information, the action type of a given action includes accessing a file, and the entity of the given action includes a file having a file name.
[0012] In an embodiment of the seventh information, the action type of a given action includes accessing a key in a registry, and the entity of the given action includes a registry key having a key name.
[0013] In an embodiment of the eighth information, the action type of a given action includes transmitting a system call to an operating system, and the entity of the given action includes a system call having a system call name.
[0014] In some embodiments, the host computer includes a first host computer distributed among a plurality of sources, and the set of host computers distributed among the sources includes the first host computer and additional host computers. The method further includes normalizing the entity into a normalized entity, and for each of the actions, defining a corresponding normalized action that includes each action type and the normalized entity for one of the actions.
[0015] In an embodiment of the first feature, the step of calculating a given feature includes calculating the count of the source.
[0016] In an embodiment of the second feature, the step of calculating a given feature includes calculating the count of the source, including at least one host computer in the set that is executing a given instance of the software application.
[0017] In an embodiment of the third feature, for each given action type, the step of calculating a given feature includes calculating the count of the host computers in the set that are executing a given instance of the software application that has executed a given action including the given action type.
[0018] In an embodiment of the fourth feature, for each given action type, the step of calculating a given feature includes calculating the count of the source, including at least one host computer in the set that has executed a given action including the given action type.
[0019] In an embodiment of the fifth feature, for each given normalization action, the step of calculating a given feature includes calculating the count of the source, including at least one host computer in the set that has executed the given normalization action.
[0020] In an embodiment of the sixth feature, the step of calculating a given feature includes calculating the count of distinct normalization actions.
[0021] In an embodiment of the seventh feature, for a given source, the step of calculating a given feature includes calculating a first count of distinct normalization actions executed by an instance of the software application running on the host computer in the given source, calculating a respective second count for each of the distinct normalization actions executed by an instance of the software application running on the host computer in each of the sources other than the given source, calculating an average of the second counts, and comparing the first count with the calculated average.
[0022] In an embodiment of the eighth feature, for each given action type, the step of calculating a given feature includes calculating a count of the sources having at least one host computer within the set that is running a given instance of the software application that executed a given action including the given action type.
[0023] In an embodiment of the ninth feature, for each given normalization action, the step of calculating a given feature includes calculating a count of the sources having at least one host computer within the set that is running a given instance of the software application that executed the given normalization action.
[0024] In an embodiment of the tenth feature, for each given normalization action, the step of calculating a given feature includes calculating a count of the host computers within the set that are running a given instance of the software application that executed the given normalization action.
[0025] In an embodiment of the 11th feature, for each given source, the step of calculating a given feature includes calculating the count of the host computers within the set that are executing a given instance related to the software application.
[0026] In an embodiment of the 12th feature, for each combination including a given source and a given normalization action, the step of calculating a given feature includes calculating the count of the host computers within the given source on which the given normalization action has been executed.
[0027] In an embodiment of the 13th feature, for each combination including a given source and a given action type, the step of calculating a given feature includes calculating the count of the host computers within the given source on which a given normalization action including the given action type has been executed.
[0028] In an embodiment of the 14th feature, for each source, the step of calculating a given feature includes calculating the count of different normalization actions executed by the software application running on the host computer belonging to the given source.
[0029] In an embodiment of the 15th feature, for each source, the step of calculating a given feature includes calculating the count of the host computers belonging to the given source.
[0030] In one embodiment, the host computer executes a plurality of software applications each having a respective name. The method further includes normalizing the names, and the instance related to the specific software application includes the instance related to the software application having the same normalized name.
[0031] In another embodiment, the step of collecting the information about a given action executed by a given instance on a given host computer includes detecting, by an endpoint agent running on the host computer, the given action executed by the given instance; extracting, by the endpoint agent, the information about the given action; transmitting, by the endpoint agent, the extracted information; and receiving, by the processor, the transmitted information.
[0032] According to one embodiment of the present invention, an apparatus is also provided. The apparatus includes a network interface controller (NIC) and one or more processors. The processor identifies a plurality of host computers each running an instance of a particular software application, each given instance in each given host computer including a set of program instructions loaded from a respective storage device by the host computer, collects information about actions executed by the instance being run from the host computer via the NIC, calculates a feature based on the information collected from the plurality of host computers, compares the collected information about the given instance with the feature to classify the given instance as benign or suspect, and generates an alert for the given instance only when the given instance is classified as suspect.
[0033] According to one embodiment of the present invention, a computer software product is additionally provided. The product includes a non-transitory computer-readable medium in which program instructions are stored. When read by a computer, the instructions cause the computer to identify a plurality of host computers each running a respective instance of a particular software application, where each given instance on each given host computer includes a set of program instructions loaded from a respective storage device by the host computer, collect information regarding actions performed by the instance being run from the host computer via the NIC, calculate features based on the information collected from the plurality of host computers, compare the collected information for a given instance with the features to classify the given instance as benign or suspect, and generate an alert for the given instance only when the given instance is classified as suspect.
Brief Description of the Drawings
[0034] This disclosure is described herein by way of example only with reference to the accompanying drawings.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
[0035] One level of security that an enterprise can adopt to protect its data is to restrict software applications deployed on the enterprise's network to signed software applications. However, prior to an application being signed, there can be instances where malicious code is inserted into a given software application. In these instances, a vendor can distribute to enterprise customers a signed version of a software application that contains malicious code that can be used to initiate a cyber attack in a given customer. These cyber attacks are sometimes known as supply chain attacks.
[0036] Embodiments of the present invention provide a method and system for identifying signed software applications that include malicious code. As described below, a plurality of host computers running respective instances of a particular software application are identified, and each given instance on each given host computer includes a set of program instructions loaded from a respective storage device by the host computer. Information regarding actions performed by the running instances is collected from the host computers, and features are calculated based on the information collected from the plurality of host computers. The information collected for a given instance is compared to the features to classify the given instance as benign or suspicious, and an alert is generated for the given instance only when the given instance is classified as suspicious.
[0037] A system implementing embodiments of the present invention can monitor millions of actions performed by dozens of different software applications running on thousands of host computers deployed in hundreds of enterprises. This rich information enables these systems to identify abnormal (and thus suspicious) actions performed by a given instance of a given application, even if the given application is signed.
[0038] System description FIG. 1 is a block diagram schematically showing an exemplary security server configured to train and execute an abnormal action detection model 22 according to one embodiment of the present invention. In the embodiments described below, the security server 20 is configured to train the model 22 by analyzing an action log 24 that stores information collected from actions 26 performed by a software application 28 running on a host computer 30 deployed at a plurality of sources 32.
[0039] In some embodiments, the set of host computers 30 can include all host computers 30 at all sources 32. For each given software application 28, the first subset can include the host computers (i.e., those of all sources 32) that are running an instance of the given software application. And each given source 32 can have a respective second subset of host computers that includes the host computers at the given source that are running an instance of each given software application.
[0040] In some embodiments, each given host computer 30 can execute a respective instance of an endpoint agent 34 that detects an action 26 executed by a software application 28 running on the given host computer, extracts information from each given detected action 26, and transmits the extracted information about the detected action to a security server 20.
[0041] Each source 32 can be referred to by a respective source identifier (ID) 36, and can include an organization or enterprise that has a local data network such as a local area network (LAN) 38 that couples the host computers to a gateway 40 that couples (to each other and) the LAN 38 to a public network such as the Internet 42.
[0042] In the configuration shown in FIG. 1, the host computer 30 can communicate via the Internet 40 with one or more remote servers 44 (e.g., a web server, a CDN server, etc.) that each have respective attributes such as an Internet Protocol (IP) address 46, a domain (name) 48, and an autonomous system number (ASN) 50.
[0043] Figure 2 is a block diagram showing exemplary hardware, software, and data components in a given host computer 300 in accordance with one embodiment of the invention. A given host computer may include a host processor 60, a host memory 62, a storage device 64, and a host network interface controller (NIC) 66 that couples the given host computer to respective LANs 38.
[0044] In some embodiments, each host computer 30 may include (or be assigned) a respective host ID 68. Exemplary host IDs may include, but are not limited to, media access control (MAC) addresses, and local IP addresses.
[0045] The storage device 64 typically stores a set of files 70. In some embodiments, a given file 70 may include a respective file signature 72 (e.g., a computed hash), and a respective file signature ID 74 indicating the identity of the entity that generated the respective file signature. Each given file 70 includes a respective file name 76, a respective file size 78, and a respective file type 80. Exemplary file types 80 may include, but are not limited to, executable files, shared libraries (e.g., DLLs), documents, images, and ZIP TM (i.e., compressed).
[0046] In embodiments herein, a given file 70 having a given type 80 may be referred to by the respective type 80. For example, a given file 70 where each type 80 is "executable" may be referred to herein as a given executable file 70. And a given file 70 where each type 80 is "shared library" may be referred to herein as a given DLL file 70.
[0047] In some embodiments, a given endpoint agent 34 running on a given host computer 30 can classify the file type for a given file 70 by analyzing the data that each host processor reads from, or writes to, the given file. For example, if the data includes compressed image data, a given endpoint agent can classify the file type as an image file type (e.g., JPG).
[0048] In the configuration shown in FIG. 2, the memory 62 includes an operating system 82, management information 84, a registry 86, an endpoint agent 34, and a plurality of processes 88 each having a respective process name 90. In some embodiments, the operating system 82 may include a set of system calls 81 each having a respective syscall name 83. One example of an operating system 82 is WINDOWS® manufactured by Microsoft Corporation of Redmond, Washington, USA. One example of an endpoint agent 34 is CORTEX XDR manufactured by Palo Alto Networks, Inc., 3000 Tanner Way, Santa Clara, California 95054, USA TM is.
[0049] To manage the operation of a given host computer, the processor 60 can execute the operating system 82. The registry 86 may include a database of registry keys 92 each having a respective key name 93 that stores low-level settings for the operating system. During operation, the operating system 82 can access (i.e., read or update) the keys 92 to manage the given host computer.
[0050] A given process 88 includes a set of program instructions 94 that can be executed by a processor 100. To start the execution of a given software application 28, the processor 60 can load a given executable file 70 (i.e., a given file 70 where each file type 78 is "executable") and start the execution of the program instructions 94 as a given process.
[0051] In some embodiments, a given process 88 can include respective process signatures 96 and respective process signature IDs 98 that indicate the identity of the entity that generated each process signature.
[0052] FIG. 3 is a block diagram showing the hardware and data components in an exemplary security server 20 according to one embodiment of the present invention. In the configuration shown in FIG. 3, the security server 20 includes a server processor 100, a server memory 102 that stores an action log 24 and a model 22, and a server NIC 104 that couples the security server to the Internet 42.
[0053] In some embodiments, the action log 24 includes a set of log entries 106, and the model 22 includes a set of features 108. The log entries 106 are described in the description with reference to FIG. 4 below, and the features 108 are described in the description with reference to FIG. 5 below.
[0054] Processors 60 and 100 include general-purpose central processing units (CPUs) or dedicated embedded processors, which are programmed with software or firmware to perform the functions described herein. This software can be downloaded, for example, in electronic form from host computer 30 or security server 22 via a network. Additionally or alternatively, the software can be stored on a tangible, non-transitory computer-readable medium such as an optical, magnetic, or electronic memory medium. Further, additionally or alternatively, at least some of the functions of processors 60 and 100 can be performed by hard-wired or programmable digital logic circuits.
[0055] Exemplary memories 62, 102, and storage devices 64 include dynamic random access memories, non-volatile random access memories, hard disk drives, and solid state disk drives.
[0056] In some embodiments, the tasks described herein that are performed by processors 60 and 90 can be divided among multiple physical and / or virtual computing devices. In other embodiments, these tasks can be performed in a managed cloud.
[0057] FIG. 4 is a block diagram showing exemplary data that can be stored by processor 100 for a given log entry 106 in accordance with an embodiment of the present invention. In the embodiments herein, log entry 106 has a one-to-one correspondence with action 26, and once processor 100 receives information regarding a new given action 26 from a given endpoint agent 34 executing on a given host computer 39, processor 100 can add a new log entry 106 and populate the new log entry with information such as the following. ● Host ID 110. Processor 100 can store the host ID 68 of a given host computer in host ID 110. ● Source ID 112. As described above, a given host computer 30 is deployed to a given source 32. The processor 100 can store the source ID 36 of the given source in the source ID 112. ● Time 114. The processor 100 can store the date and time of a given action at the time 114. ● Full application name 116. In an embodiment where the program instructions 94 of a given software application 28 execute a given action, the processor 100 can store the file name 76 of the executable file storing the program instructions in the full application name 116. ● Normalized application ID 118. Using the embodiment described in the description with reference to FIG. 6 below, the processor 100 can derive a normalized application ID for the full application name 116. ● Action type 120. The following are exemplary action types 120 that the processor 100 can store in a new log entry in response to receiving information about a given action. ○ Process creation. A given software application 28 running on a given host computer created a new process 88. ○ Domain access. A given software application running on a given host computer accessed a given domain 48. ○ IP address access. A given software application 28 running on a given host computer accessed a given IP address 46. ○ ASN access. A given software application 28 running on a given host computer accessed a given IP address 46 belonging to a given ASN 50. ○ Module load. A given software application 28 running on a given host computer loads a shared library such as a given DLL file 70. ○ Process injection. A given software application 28 running on a given host computer may inject a new process 88. ○ File access. A given software application 28 running on a given host computer may create, read from, write to, or delete a given file 70. ○ Registry access. A given software application 28 running on a given host computer may access a given registry key 92 within a registry 86. ○ System call. A given software application 28 running on a given host computer may communicate a given system call 81 (e.g., GetClipboardData) to an operating system 82. ○ Remote Procedure Call (RPC). A given software application 28 running on a given host computer may communicate an RPC. Examples of RPCs are described in the description with reference to FIG. 6 below. ● Raw action entity 122. The processor 100 can store in the raw action entity 122 an “entity name” for which a given action has been performed by a given software application 28. For example, ○ When the action type 120 is process creation or process injection, the processor 100 can store in the raw action entity 122 the process name of the process created / injected by a given action. ○ When the action type 120 is domain access, the processor 100 can store in the raw action entity 122 the domain name accessed by a given action. ○ When the action type 120 is IP address access, the processor 100 can store in the raw action entity 122 the IP address accessed by a given action. ○ When the action type 120 is an ASN access, the processor 100 can store in the raw action entity 122 the ASN of the IP address accessed by a given action. ○ When the action type 120 is a module load, the processor 100 can store in the raw action entity 122 the file name of the DLL (i.e., shared library) file loaded by a given action. ○ When the action type 120 is a file access, the processor 100 can store in the raw action entity 122 the file name of the file accessed by a given action. ○ When the action type 120 is a registry access, the processor 100 can store in the raw action entity 122 the name / identifier of the registry key loaded by a given action. ○ When the action type 120 is a system call, the processor 100 can store in the raw action entity 122 the system call name of the system call invoked by a given action. ○ When the action type 120 is an administrative system access (e.g., accessing settings within the operating system 82), the processor 100 can store in the raw action entity 122 a query for the settings within the administrative information 84. ● Normalized action entity 124. Using the embodiments described in the description with reference to FIG. 6 below, the processor 100 can derive a normalized action entity for the raw action entity 122. ● The normalized action 126 includes a combination of the action type 120 and the normalized action entity 124.
[0058] FIG. 5 is a block diagram showing exemplary data components that can be stored by the security server in model 22 according to one embodiment of the present invention. In addition to the set of features 108, model 22 also includes a set of weights 130 that have a one-to-one correspondence with the features. In FIG. 5, features 108 and weights 130 can be distinguished by adding letters to the identification numbers, and as a result, the features include features 108A-108O and the weights include 130A-130O.
[0059] In an embodiment of the present specification, for each given software application 28, the processor 100 calculates features 108 that reflect respective metrics of actions executed by the given software application. In addition, the features can include the following. ● Features 108 where each feature type (not shown) is "global" (these features 108 are referred to as global features 108 in the present specification). In some embodiments, the processor 100 can calculate global features 108 by analyzing all log entries 106. ● Features 108 where each feature type includes a given source ID 36 (these features 108 are referred to as local features 108 in the present specification). In some embodiments, the processor 100 can calculate local features 108 by analyzing log entries 106 where each source ID 112 matches the given source ID 36.
[0060] Exemplary global features 108 that the processor 100 can calculate based on the log entries 106 include the following. ● Feature 108A: The processor 100 can calculate the count of distinct (i.e., different) source IDs 112 (i.e., with reference to each source 32). ● Feature 108B: For each given normalized application ID 118, the processor 100 can calculate each Feature 108B that includes a count of distinct sources 32 within a log entry where each normalized application ID 118 matches the given normalized application ID 118. ● Feature 108C: For each combination that includes a given normalized application ID 118 and a given normalized action 126, the processor 100 can calculate each Feature 108C (i.e., with reference to each host computer 30) that includes a count of distinct host IDs 110. ● Feature 108D: For each action type 120, the processor 100 can calculate each Feature 108D that includes a count of distinct source IDs 112. ● Feature 108E: For each normalized action 126, the processor 100 can calculate each Feature 108E that includes a count of distinct source IDs 112. ● Feature 108F: For each given normalized application ID 118, the processor 100 can calculate each Feature 108F that includes a count of distinct normalized actions 126 (i.e., those executed by the software application 28 referenced by the given normalized application ID). In some embodiments, the processor 100 can calculate Feature 108F only for normalized actions 126 that are executed by at least a specified number (e.g., five) of distinct source IDs 112 (i.e., as indicated by the log entry 106). ● Feature 108G: For each combination that includes a given normalized application ID 118 and a given action type 120, the processor 100 can calculate each Feature 108G that includes a count of distinct source IDs 112. ● Feature 108H: For each combination including a given normalized application ID 118 and a given normalized action 126, the processor 100 can calculate each respective feature 108H that includes a count of distinct source IDs 112. ● Feature 108I: For each combination including a given combination that includes a given normalized application ID 118 and a given normalized action 126, the processor 100 can calculate each respective feature 108I that includes a count of distinct host IDs 110.
[0061] Exemplary local features 108 that the processor 100 can calculate based on the log entries 106 include the following. ● Feature 108J: For each combination including a given distinct source ID 112 and a given normalized application ID 118, the processor 100 can calculate each respective feature 108I that includes a count of host IDs 110 (i.e., host computer 30) that include the software application corresponding to the given normalized application ID. In some embodiments, the processor 100 can include a given host computer 30 in the count only if the software application (i.e., the one corresponding to the given normalized application ID) was executed by the given computer within a specified period (e.g., the previous 30 days). ● Feature 108K: For each combination including a given distinct source ID 112 and a given normalized action 126, the processor 100 can calculate each respective feature 108J that includes a count of host IDs 110 (i.e., those referring to respective host computers 30) that executed the given normalized action. ● Feature 108L: For each combination of a given distinct source 32 and a given action type 120, the processor 100 can calculate each respective feature 108K that includes a count of host IDs 110 that executed the given action type. ● Feature 108M: For each combination including a given distinct source ID 112 and a given normalized application ID 118, the processor 100 can calculate each feature 108L including a count of distinct normalization actions 126. ● Feature 108N: For each given distinct source ID 112, the processor 100 can calculate each feature 108M including a count of host IDs 110 (i.e., host computer 30) belonging to (i.e., deployed therein) a given source.
[0062] In addition to the global features and local features 108 described above, the features 108 may include features 108O that are hybrid (i.e., global / local). For each combination including a given distinct source ID 112 and a distinct normalized application ID 118 (i.e., referring to a given software application 28 being executed on one or more of the host computers in a given source 32), the processor 100 can calculate each count of distinct normalization actions 126 (i.e., being executed by a given software application on a given host computer 30 in a given source). For each given calculated count, the processor 100 can calculate each feature 108O by averaging all the calculated counts other than the given calculated count and then comparing the given calculated count with the calculated average. This can be referred to as “computing the global profiles over the local profiles”. For example, it is as follows. ● Refer to the calculated count as local_distinct_actions. ● For each distinct normalized application ID 118, the processor 100 calculates the following. ○ AVG(local_distinct_actions) ○STDDEV(local_distinct_actions) (i.e., for all other source IDs) ●For each distinct source ID 112, the processor 100 calculates the following. z-score=(local_distinct_actions)- AVG(local_distinct_actions) / STDDEV(local_distinct_actions) The z-score represents how many standard deviations local_distinct_actions is greater than AVG(local_distinct_actions).
[0063] In the features 108A-108 described above, the processor 100 performs the count by counting the number of log entries 106 that match the specified conditions. For example, in feature 108N, the specified conditions include a combination of distinct sources and normalized application IDs.
[0064] As described below, the processor 100 can calculate a score for each action based on the features generated for the action. In the above features, ●For features 108C-M, lower values are more suspect than higher values. For feature 108, lower values are less suspect than higher values. In some embodiments, the processor 100 can calculate a value between 0 and 1 for each of the features 108C-M and 108O. Here, the closer the value is to 0, the more suspect it is, and the closer the value is to 1, the less suspect it is. ●The processor 100 can use feature 108B to provide context for features 108C-M and 108O. For example, if feature 108B is a low number (e.g., less than 5% of the sources), the processor 100 can use feature 108B to reduce the suspectness of features 108C-M and 108O. ● The processor 100 can use the features 108A and 108N to “normalize” other features 108 (e.g., to the 0-1 range described above). For example, if feature 108D is 700 and feature 108A is 1000, the processor 100 can calculate the normalized value for feature 108D as follows. Normalized 108D = 700 / 1000 = 0.7
[0065] Model training and deployment FIG. 6 is a flowchart generally showing a method of training the model 22 with respect to a set of training data according to one embodiment of the present invention. In the embodiments described herein, the training data includes the action log 24.
[0066] In step 140, the processor 100 collects, from each of the plurality of endpoint agents 34 respectively executed on the host computer 30 deployed on the plurality of sources 32, each set of actions 26 respectively executed in each raw action entity 122 by the software application executed on the host computer.
[0067] In step 142, using the embodiments described above, the processor stores the information from the collected actions in each log entry 106 in the action log 24.
[0068] In step 144, the processor 100 normalizes the raw entity 122 to the normalized entity 124, the action 26 to the normalized action 126, and the name 116 of the software application 28 to the normalized application ID 118 in the log entry 106. As described above, the normalized action 126 includes each combination of the action type 120 and the normalized action entity.
[0069] Different instances of a given software application 28 may have different names 116 that reflect different builds or versions. In embodiments of software application normalization, the processor 100 can normalize the application name 116 by removing unnecessary information to determine a common normalization application ID 118 across all instances. For example, the processor 100 can normalize any of the following full application names 116 Company-App-Agent-x86_64-7.12.0-15.exe Company-App-Agent-x86_64-7.13.0-15.exe Company-App-Agent-x86_64-7.12.0-16.exe to companyappagent and store companyappagent in the normalization application ID 118. In one embodiment, when the signature for a given software application includes respective file signatures 72, the processor 100 can normalize the application name of the given software application by concatenating the vendor name (i.e., the vendor that provided or generated the given software application) to the respective normalized application ID 118. In additional embodiments, the processor 100 can normalize a given software application by calculating a hash value for the executable file 70 of the given software application.
[0070]
[0071] In an embodiment of process normalization, when a given action type 120 includes process creation or process injection that includes a new process 88 having a given process name 90, the processor 100 can normalize the process name by removing any unnecessary information in the name. In some embodiments, when a given process includes respective process signatures 96, the processor 100 can normalize the process name by adding respective process signature IDs 98 to respective normalization entities 124.
[0072] In an embodiment of domain normalization, a given action type 120 includes domain access to a given domain 48. In this embodiment, the processor 100 can divide each domain 48 into three sections. For example, the domain "a.b.c.site.com" can be ● Public suffix ".com" ● Main domain "site" ● Subdomain "a.b.c" divided as such.
[0073] Since subdomains are typically attacker-controlled, the processor 100 can perform this normalization based on the main domain concatenated with the public suffix (i.e., "site.com").
[0074] In an embodiment of ASN normalization, a given action type 120 includes access to a given IP address 46. When the processor 100 can map a given IP address to a given ASN 50 including geolocation, the server processor can normalize the given IP address with respect to the geolocation.
[0075] In an embodiment of file normalization, a given action type 120 includes file access to a given file 70. In one embodiment of file normalization, the processor 100 can use an embodiment of a software application and an embodiment of the process normalization described above to standardize a given file by removing unnecessary information from each file name 76. In other embodiments of file normalization, the processor 100 can use each file size 80 and / or each file type 78 to normalize a given file.
[0076] In an embodiment of RPC normalization, a given action type 120 includes an RPC call. For example, WINDOWS TM The operating system uses WINDOWS MANAGEMENT INSTRUMENTATION to query the system data. TM queries. WMI TM Queries are used by both legitimate applications and attackers, and the queries can be split into three sections: SELECT, FROM, and WHERE. Since the WHERE section usually contains redundant information, the processor 100 can normalize the query by using only the SELECT section and the FROM section.
[0077] For example, the processor 100 can use this embodiment to normalize the following WMI TM query. SELECT ParentProcessId FROM win32_process WHERE ProcessID='16236 to SELECT ParentProcessId FROM win32_process
[0078] In an embodiment of registry normalization, a given action type 120 includes registry access to a given key 92 having a given path. In one embodiment of registry normalization, the processor 100 can normalize the registry access by removing redundant and randomized information within the path.
[0079] Some groups of registry keys 92 tend to be used more frequently than others for malicious activities. In another embodiment of registry normalization, the processor 100 can assign a respective identifier to each group (i.e., an identifier indicating whether each group tends to be used for malicious activities), and use the identifier for normalization.
[0080] In an embodiment of syscall normalization, when a given action type 120 includes a syscall, the processor 100 can normalize the syscall 81 to a syscall name 83 (i.e., without parameters within the syscall 81).
[0081] Returning to the flowchart, at step 146, using the embodiments described above, the processor 100 analyzes an action log 24 (here including a normalization application ID 118, a normalized entity 124, and a normalized action 126) to calculate local and global features 108. In the embodiments of this specification, the action log 24 includes information collected by the processor 100 from the host computer 30 (e.g., host ID 110, source ID 112, time 114, full application name 116, action type 120, and raw action entity 122), as well as information normalized by the server processor (e.g., normalized application name 118, normalized action entity 124, and normalized action 126).
[0082] In step 148, the processor 100 stores the calculated local and global features in the model 22, and the method ends.
[0083] FIG. 7 is a flowchart generally showing a method of using a model to classify the normalization action 126 in the action log 24 according to one embodiment of the present invention.
[0084] In step 150, the processor 100 selects the first log entry 106 in the action log 24. The selected log entry includes a given normalization application ID 118 and a given normalization action 126.
[0085] In step 152, the processor 100 identifies a set of local and global features 108 that can be used by the server processor to analyze a given normalization action. When analyzing the normalization action 126 in the log entry 106, the processor 100 may use the following. ● One or more first given features 108 (e.g., feature 108A) for all normalization actions. ● One or more second given features 108 (e.g., feature 108B) based only on a given normalized application ID. ● One or more third given features 108 (e.g., feature 108L) based only on a given normalization action. ● One or more fourth given features 108 (e.g., feature 108C) based on a combination of a given normalized application ID and a given normalization action.
[0086] In step 154, the processor 100 applies the identified features to a given normalization action so as to classify the given normalization action as either benign or suspicious. In the following example, the processor 100 can calculate a score based on the identified features and determine a classification based on the calculated score. In this example, a score lower than the 0-1 score range is more suspicious, and the processor 100 can set a threshold for determining the classification (for example, a score less than 0.3 can indicate that a given normalization action is suspicious, and a score of 0.3 or more can indicate that a given normalization action is benign).
[0087] To make the score not affected by unimportant factors (for example, the number of different sources 32, the number of different host computers 30, and the number of different software applications 28), the processor 100 can normalize each identified feature 108 so that the identified features are normalized to the range of [0,1]. For example, the processor 100 can perform the following steps. ● Divide each feature (Fi) (that is, feature 108) by its "maximum value" (Mi) to obtain a normalized feature (Fi). ○ Take the log of both the numerator and the denominator to scale down large numbers. ○ Truncate the result of the log to avoid overfitting and to bin the data to stabilize the result. ● Calculate the weighted average of the normalized features to obtain a single score. Each feature has a different weight (Wi) value (that is, weight 130).
Number
Number
[0088] In some embodiments, calculating the score enables the processor 100 to compare the identified features of the action normalization action to classify the normalization action as either benign or anomalous, and thus suspect.
[0089] In step 156, if the processor 100 classifies a given normalization action as suspect (i.e., using the embodiments described above), then in step 158, the server processor can generate an alert for the instance of the software application corresponding to the given normalized application ID.
[0090] In step 160, the processor 100 determines whether there is a non-selected log entry 106 in the action log 24. If there is a non-selected log entry 106 in the action log 24, then in step 162, the processor 100 selects the next log entry 106 in the action log, and the method ends.
[0091] Returning to step 160, if there is no non-selected log entry 106 in the action log 24, the method ends.
[0092] Returning to step 156, if the processor 100 classifies a given normalization action as benign, the method proceeds to step 162.
[0093] FIG. 8 is a flowchart generally showing a method of using a model to perform real-time classification of action 26 in accordance with one embodiment of the present invention.
[0094] In step 170, the processor 100 receives, from a given endpoint agent 34 executing on a given host computer 30, information about a new action 26 to be executed at a given raw action entity 122 by a given software application 28.
[0095] In step 172, using the above-described embodiments, the processor 100 creates a new log entry 106 and populates the new log entry with a host ID 110, a source ID 112, a time 114, a full application name 116, a normalized application ID 118, an action type 120, a raw action entity 122, a normalized entity 124, and a normalized action 126.
[0096] In step 174, using the above-described embodiments, the processor 100 identifies a set of local and global features 108 that can be used by the server processor to analyze the new normalized action.
[0097] In step 176, the processor 100 uses the embodiments described above to apply the features identified for the new normalized action so as to classify the new normalized action as either benign or suspect.
[0098] If, in step 178, the processor 100 classifies the new normalized action as suspect, then, in step 180, the server processor can generate an alert for an instance of the software application corresponding to the new normalized application ID.
[0099] In step 182, the processor 100 updates the feature 108 using the information in the new log entry, and the method ends. In some embodiments, the processor 100 can update the feature 108 periodically (e.g., once every 24 hours) (i.e., from the previous update) using the information in the new log entry 106.
[0100] Returning to step 178, if the processor 100 classifies the new normalization action as benign, the method proceeds to step 182.
[0101] It will be understood that the above-described embodiments are cited by way of example and that the invention is not limited to what has been particularly shown and described above. Rather, the scope of the invention includes both combinations and sub-combinations of the various features described above, as well as those variations and modifications that will occur to those skilled in the art upon reading the foregoing description and that are not disclosed in the prior art.
Claims
**Claim 1** A method comprising: identifying a plurality of host computers each executing a respective instance of a particular software application, each given instance on a given host computer including a set of program instructions loaded from a respective storage device by the host computer; collecting, from the host computers, information about actions performed by the executing instances; calculating features based on the information collected from the plurality of host computers; comparing, by a processor, the information collected about a given instance with the features to classify the given instance as benign or suspect; generating an alert for the given instance only when the given instance is classified as suspect; wherein the information includes action types and entities; the host computers include a first host computer distributed among a plurality of sources; the set of host computers distributed among the sources includes the first host computer and additional host computers; the method further comprising: normalizing the entity into a normalized entity; defining, for each of the actions, a corresponding normalized action including a respective action type and the normalized entity for one of the actions; a method. **Claim 2** the action type of a given action includes creating or injecting a process; the entity of the given action includes a process having a process name; The method according to claim 1. **Claim 3** the action type of a given action includes accessing a domain; the entity of the given action includes a domain name; The method according to claim 1. **Claim 4** the action type of a given action includes accessing an Internet Protocol (IP) address; the entity of the given action includes an IP address; The method according to claim 1. **Claim 5** The action type of the given action includes accessing an autonomous system number (ASN) address, The entity of the given action includes an ASN, The method according to claim 1.
6. The action type of the given action includes loading a shared library, The entity of the given action includes a shared library having its respective name, The method according to claim 1.
7. The action type of the given action includes accessing a file, The entity of the given action includes a file having a file name, The method according to claim 1.
8. The action type of the given action includes accessing a key in the registry, The entity of the given action includes a registry key having a key name, The method according to claim 1.
9. The action type of the given action includes transmitting a system call to the operating system, The entity of the given action includes a system call having a system call name, The method according to claim 1.
10. The step of calculating the feature includes calculating the count of the source, The method according to claim 1, including.
11. The step of calculating the feature includes calculating the count of the source, including at least one host computer in the set that is executing a given instance of the software application, The method according to claim 1, including.
12. For each given action type, the step of calculating the feature is, Calculating the count of the host computers in the set that are executing a given instance related to the software application that has executed a given action including the given action type, The method according to claim 1, including.
13. For each given action type, the step of calculating the feature is, Calculating the count of the source, including at least one host computer in the set that has executed a given action including the given action type, The method according to claim 1, including.
14. For each given normalization action, the step of calculating the feature is, Calculating the count of the source, including at least one host computer within the set that executed the given normalization action; The method according to claim 1, including;
15. The step of calculating the feature includes; Calculating the count of distinct normalization actions; The method according to claim 1, including;
16. For a given source, the step of calculating the feature includes; Calculating a first count of distinct normalization actions executed by an instance of the software application running on the host computer in the given source; Calculating respective second counts for distinct normalization actions executed by an instance of the software application running on the host computer in each of the sources other than the given source; Calculating the average of the second counts, and Comparing the first count with the calculated average; The method according to claim 1, including;
17. For each given action type, the step of calculating the feature includes; Calculating the count of the source having at least one host computer within the set that is running a given instance of the software application that executed a given action including the given action type; The method according to claim 1, including;
18. For each given normalization action, the step of calculating the feature includes; Calculating the count of the source having at least one host computer within the set that is running a given instance of the software application that executed the given normalization action; The method according to claim 1, including;
19. For each given normalization action, the step of calculating the feature includes; Calculating the count of the host computers within the set that are running a given instance of the software application that executed the given normalization action; The method according to claim 1, including;
20. For each given source, the step of calculating the feature includes; Calculating the count of the host computers within the set that are executing a given instance of the software application; The method according to claim 1, comprising:
21. For each combination comprising a given source and a given normalization action, the step of calculating the feature comprises: Calculating the count of the host computers within the given source on which the given normalization action has been executed; The method according to claim 1, comprising:
22. For each combination comprising a given source and a given action type, the step of calculating the feature comprises: Calculating the count of the host computers within the given source on which a given normalization action including the given action type has been executed; The method according to claim 1, comprising:
23. For each given source, the step of calculating the feature comprises: Calculating the count of different normalization actions executed by the software application running on the host computer belonging to the given source; The method according to claim 1, comprising:
24. For each given source, the step of calculating the feature comprises: Calculating the count of the host computers belonging to the given source; The method according to claim 1, comprising:
25. The host computer executes a plurality of software applications each having a respective name, and The method further comprises: Normalizing the name, wherein the instance related to the specific software application includes the instance related to the software application having the same normalized name; The method according to claim 1.
26. The step of collecting the information for a given action executed by a given instance on a given host computer comprises: Detecting, by an endpoint agent running on the host computer, the given action executed by the given instance; Extracting, by the endpoint agent, the information for the given action; Transmitting, by the endpoint agent, the extracted information, and Receiving, by the processor, the transmitted information; The method according to claim 1, comprising
27. An apparatus comprising a network interface controller (NIC), and one or more processors, wherein the processors identify a plurality of host computers executing respective instances related to a specific software application, and each given instance in each given host computer includes a set of program instructions loaded from respective storage devices by the host computer, collect information about actions performed by the executing instances from the host computers via the NIC, calculate features based on the information collected from the plurality of host computers, compare the collected information about the given instance with the features to classify the given instance as benign or suspect, and generate an alert for the given instance only when the given instance is classified as suspect, configured to wherein the information includes action types and entities, the host computers include a first host computer distributed among a plurality of sources, the set of host computers distributed among the sources includes the first host computer and additional host computers, the processor is further configured to normalize the entity into a normalized entity, define, for each of the actions, a corresponding normalized action including each action type and the normalized entity for one of the actions, configured as such, an apparatus.
28. A computer program comprising computer instructions stored on a non-transitory computer-readable medium, wherein the computer instructions, when executed by a processor, cause the computer to identify a plurality of host computers executing respective instances related to a specific software application, and each given instance in each given host computer includes a set of program instructions loaded from respective storage devices by the host computer, Collect information from the host computer regarding actions executed by the instance that is running, Calculate features based on the information collected from the plurality of host computers, Compare the collected information about the given instance with the features in order to classify the given instance as benign or suspicious, and Generate an alert for the given instance only when the given instance is classified as suspicious, Cause to be, wherein the information includes an action type and an entity the host computer includes a first host computer distributed among a plurality of sources, the set of host computers distributed among the sources includes the first host computer and additional host computers, further cause the computer to normalize the entity into a normalized entity, define, for each of the actions, a corresponding normalized action that includes the respective action type and the normalized entity for one of the actions, cause to be, a computer program.
Citation Information
Patent Citations
Software supply chain security detection method and device, electronic equipment, and storage medium
CN114077741A
Software behavior modeling device, software behavior modeling method, software behavior verification device and software behavior verification method
JP2008243034A
A system and method for detecting malicious processes without using signatures.
JP2014515538A
Method and system for detecting malicious application
US20140181973A1
Systems and Methods to Fingerprint and Classify Application Behaviors Using Telemetry
US20190319977A1