IP Library Granted Patent US 8,875,286
Granted Patent B2
US 8,875,286 · App. 13/308,533 · Granted Oct 28, 2014

Method and apparatus for detecting malicious software using machine learning techniques

Inventors: Oliver Friedrichs (Woodside, CA); Alfred Huger (Calgary, CA); Adam J. O'Donnell (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F21/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,875,286
App. No.
13/308,533
Granted
Oct 28, 2014
Kind
B2
Abstract

Novel methods, components, and systems for detecting malicious software in a proactive manner are presented. More specifically, we describe methods, components, and systems that leverage machine learning techniques to detect malicious software. The disclosed invention provides a significant improvement with regard to detection capabilities compared to previous approaches.

Claims (24)

1. A computer implemented method for determining whether a software application is malicious, comprising:

accessing in a training phase, using a server application, a body of training data comprising a set of software applications, said server application configured to derive during said training phase a classification algorithm for determining whether software applications are likely benign or malicious;

before execution of a software application of interest, extracting, using a client or server application, a feature vector from the software application of interest by applying a mathematical transformation operation to the software application of interest to generate a series of values that represents features of the software application of interest and that is indicative of whether or not the software application of interest is likely to be benign or malicious;

applying the feature vector to the classification algorithm;

using the results of the classification algorithm to determine how to treat the software application of interest.

2. A computer implemented method for determining whether a software application is malicious, comprising:

accessing in a training phase a body of training data comprising a set of software applications to derive during said training phase a classification algorithm for determining whether selected software applications are likely benign or malicious;

before execution of a software application of interest, receiving from a client application a feature vector relating to the software application of interest, wherein the feature vector is generated by applying a mathematical transformation operation to the software application of interest and comprises a series of values that represents features of the software application of interest and that is indicative of whether or not the software application of interest is likely to be benign or malicious;

applying the feature vector to the classification algorithm;

transmitting information indicative of a maliciousness of the software application of interest to the client application based on the results of the application of the feature vector to the classification algorithm.

3. A computer implemented method for determining whether a software application is malicious, comprising:

before execution of a software application, extracting a feature vector from the software application by applying a mathematical transformation operation to the software application to generate a series of values that represents features of the software application and that is indicative of whether or not the software application is likely to be benign or malicious;

transmitting said feature vector to a server application;

receiving information indicative of a maliciousness of the software application from said server application relating to results of applying said feature vector to a classification algorithm concerning whether said software application is benign or potentially malicious.

4. A method according to claim 1 , wherein the classification algorithm produces a score that represents confidence in its determination as to whether the software application is benign or malicious.

5. A method according to claim 1 , wherein the data used to derive the classification algorithm is can be taken directly from transaction logs of actual client systems that communicate with the server side component.

6. A method according to claim 1 , wherein the classification algorithm is developed using a machine learning method selected from the group consisting of Support Vector Machines, Neural Networks, Decision Trees, naive Bayes, Logistic Regression.

7. A method according to claim 1 , wherein the feature vector is encoded.

8. A method according to claim 1 , wherein the feature vector is compressed.

9. A method according claim 1 , wherein, following application of the feature vector to the classification algorithm, the application is transmitted to a server for further processing.

10. A method according to claim 1 , wherein the body of training data includes actual in-field usage data.

11. A method according to claim 1 , wherein the output of the classification algorithm is compared to results from another method for identifying malicious software.

12. A method according to claim 1 , wherein the body of training data comprises a set of software applications.

13. A method according to claim 12 , wherein software applications in the body of training data are associated with a disposition label.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2014
From: IMMUNET LLC
To: SOURCEFIRE LLC
Reel/Frame 033235/0701 →
CHANGE OF NAME Recorded Jul 2, 2014
From: IMMUNET CORPORATION
To: IMMUNET LLC
Reel/Frame 033267/0471 →
CHANGE OF NAME Recorded Mar 24, 2014
From: SOURCEFIRE, INC.
To: SOURCEFIRE LLC
Reel/Frame 032513/0481 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2014
From: SOURCEFIRE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 032513/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2012
From: FRIEDRICHS, OLIVER; HUGER, ALFRED A.; O'DONNELL, ADAM J.
To: IMMUNET CORPORATION
Reel/Frame 027798/0520 →
Continuity (5)
Provisional Application 61418532 · Dec 1, 2010
Provisional Application 61418514 · Dec 1, 2010
Provisional Application 61418547 · Dec 1, 2010
Provisional Application 61418580 · Dec 1, 2010
Related Publication 20120227105A1 · Sep 6, 2012