IP Library Granted Patent US 12670255
Granted Patent B2
US 12670255 · App. 18/706,812 · Granted Jun 30, 2026

Generation device and associated methodology for generating indicators of compromise corresponding to script-type malware

Inventors: Toshinori Usui (Musashino, JP); Tomonori Ikuse (Musashino, JP); Yuhei Kawakoya (Musashino, JP); Makoto Iwamura (Musashino, JP)
Assignee: NTT, Inc.
G06F21/566G06F21/564G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12670255
App. No.
18/706,812
Granted
Jun 30, 2026
Kind
B2
Abstract

A generation device includes processing circuitry configured to acquire behavior information related to behavior of malware and collection information related to date and time when the malware is collected, classify the malware into a first group based on the behavior information, classify the malware classified into the first group into a second group based on the collection information, detect an activity trace of the malware from the behavior information, and generate trace information of the malware from the activity trace indicated by the malware classified into the second group.

Claims (26)

1 . A generation device comprising:

processing circuitry configured to:

acquire behavior information related to behavior of malware and collection information related to date and time when the malware is collected;

classify the malware into a plurality of first groups based on the behavior information;

classify the malware classified into each of the plurality of first groups into a plurality of second groups based on the collection information;

detect an activity trace of the malware from the behavior information; and

generate trace information of the malware from the activity trace indicated by the malware classified into the plurality of second groups,

wherein the processing circuitry is further configured to execute the malware in an isolated environment, and acquire an API (Application Programming Interface) trace related to an API called during the malware execution as the behavior information.

2 . The generation device according to claim 1 , wherein the processing circuitry is further configured to classify the malware belonging to a time window among the malware classified into the plurality of first groups into the plurality of second groups by using the time window indicating a time section based on the collection information.

3 . The generation device according to claim 2 , wherein the processing circuitry is further configured to cluster the malware based on similarity between character strings of activity traces and determine the time window based on a change in tendency of the clustered malware.

4 . The generation device according to claim 1 , wherein the processing circuitry is further configured to extract features having high similarity between subspecies from the behavior information, cluster based on the features, and classify the malware into the plurality of first groups.

5 . The generation device according to claim 1 , wherein the processing circuitry is further configured to detect the activity trace from an API trace related to network communication, file operation, registry operation, or process generation.

6 . A generation method executed by a generation device, the generation method comprising:

acquiring behavior information related to behavior of malware and collection information related to date and time when the malware is collected;

classifying the malware into a plurality of first groups based on the behavior information;

classifying the malware classified into the plurality of first groups into a plurality of second groups based on the collection information;

detecting an activity trace of the malware from the behavior information; and

generating trace information of the malware from the activity trace indicated by the malware classified into the plurality of second groups,

wherein the generation method further includes executing the malware in an isolated environment, and acquiring an API (Application Programming Interface) trace related to an API called during the malware execution as the behavior information.

7 . A non-transitory computer-readable recording medium storing therein a generation program that causes a computer to execute a process comprising:

acquiring behavior information related to behavior of malware and collection information related to date and time when the malware is collected;

classifying the malware into a plurality of first groups based on the behavior information;

classifying the malware classified into the plurality of first groups into a plurality of second groups based on the collection information;

detecting an activity trace of the malware from the behavior information; and

generating trace information of the malware from the activity trace indicated by the malware classified into the plurality of second groups,

wherein the process further includes executing the malware in an isolated environment, and acquiring an API (Application Programming Interface) trace related to an API called during the malware execution as the behavior information.