IP Library Granted Patent US 8,763,127
Granted Patent B2
US 8,763,127 · App. 13/255,567 · Granted Jun 24, 2014

Systems and method for malware detection

Inventors: Danfeng Yao (Blacksburg, VA); Deian Stefan (Glendale, NY); Chehai Wu (Goleta, CA)
Assignee: Rutgers, The State University of New Jersey
G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,763,127
App. No.
13/255,567
Granted
Jun 24, 2014
Kind
B2
Abstract

A system and method for distinguishing human input events from malware-generated events includes one or more central processing units (CPUs), one or more input devices and memory. The memory includes program code that when executed by the CPU causes the CPU to obtain a first set of input events from a user utilizing the input device. The first input events are used to obtain or derive a feature indicative of the user, such as a multi-dimensional feature vector as provided by a support vector machine. Second input events are then obtained, and the second input events are classified against the feature to determine if either the user or malware initiated the second input events.

Claims (9)

1. A computer system for distinguishing user-initiated outbound network traffic from malware-initiated outbound network traffic, the system comprising:

at least a central processing unit (CPU);

at least an input device;

networking hardware capable of carrying the network traffic; and

memory communicatively coupled to the CPU, the memory comprising program code executable by the at least a CPU to perform the following steps:

monitoring input events generated by the input device;

monitoring outbound network traffic events;

performing a time-based correlation analysis between the input events and the outbound network traffic events by performing a linear regression analysis between timestamps on outbound packets and timestamps on input events; and

distinguishing malware-initiated outbound traffic according to the time-based correlation analysis.

Assignments (2)
CONFIRMATORY LICENSE Recorded Apr 28, 2020
From: RUTGERS, THE STATE UNIVERSITY OF NEW JERSEY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 052511/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2011
From: YAO, DANFENG; STEFAN, DEIAN; WU, CHEHAI
To: RUTGERS, THE STATE UNIVERSITY OF NEW JERSEY
Reel/Frame 026878/0751 →
Continuity (2)
Provisional Application 61210097 · Mar 13, 2009
Related Publication 20110320816A1 · Dec 29, 2011