IP Library Granted Patent US 8,635,700
Granted Patent B2
US 8,635,700 · App. 13/312,716 · Granted Jan 21, 2014

Detecting malware using stored patterns

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,635,700
App. No.
13/312,716
Granted
Jan 21, 2014
Kind
B2
Abstract

In one embodiment, a method includes identifying a plurality of portions of a file and comparing the plurality of portions of the file to a plurality of stored patterns. The plurality of stored patterns include portions of known malware. The method also includes determining, from the plurality of portions of the file and based on the comparing of the plurality of portions of the file to the plurality of stored patterns, a set of matching portions. The set of matching portions include one or more of the plurality of portions of the file. In addition, the method includes determining a score for each portion in the set of matching portions and providing information regarding the set of matching portions. The information includes the scores determined for each portion of the set of matching portions.

Claims (50)

1. A method comprising:

identifying, by at least one processor, a plurality of portions of a file;

comparing, by the at least one processor, the plurality of portions of the file to a plurality of stored patterns, the plurality of stored patterns comprising portions of known malware;

determining, by at least one processor, from the plurality of portions of the file and based on the comparing of the plurality of portions of the file to the plurality of stored patterns comprising portions of known malware, a set of matching portions, the set of matching portions comprising one or more of the plurality of portions of the file;

determining, by at least one processor, a first score for each portion in the set of matching portions;

determining an overall score for the file as a function of the first scores;

comparing the overall score to a threshold to determine whether the file comprises malware, wherein the threshold is based on the context of how the file was received; and

providing, by at least one processor, information regarding the set of matching portions, the information comprising the first score determined for each portion of the set of matching portions and the overall score;

wherein each first score is determined based on the frequency with which each respective portion in the set of matching portions occurs in the plurality of stored patterns.

2. The method of claim 1 , wherein each first score comprises a ranking of a likelihood that each respective portion in the set of matching portions is associated with malware.

3. The method of claim 1 , wherein comparing the plurality of portions of the file to the plurality of stored patterns comprises comparing byte sequences or text strings.

4. The method of claim 1 , wherein the information is provided to a human analyst to assist in determining whether the file is malware.

5. The method of claim 1 , wherein the information further comprises a description of each portion in the set of matching portions.

6. The method of claim 1 , further comprising:

in response to determining the first score for each portion in the set of matching portions, determining, by the at least one processor, that the file is potential malware; and

in response to determining that the file is potential malware, performing , by the at least one processor, remedial action regarding the file.

7. A system comprising:

at least one computer-readable medium; and

one or more processors configured to:

identify a plurality of portions of a file;

compare the plurality of portions of the file to a plurality of stored patterns, the plurality of stored patterns comprising portions of known malware;

determine, from the plurality of portions of the file and based on the comparing of the plurality of portions of the file to the plurality of stored patterns comprising portions of known malware, a set of matching portions, the set of matching portions comprising one or more of the plurality of portions of the file;

determine a first score for each portion in the set of matching portions;

determine an overall score for the file as a function of the first scores;

compare the overall score to a threshold to determine whether the file comprises malware, wherein the threshold is based on the context of how the file was received; and

provide information regarding the set of matching portions, the information comprising the first score determined for each portion of the set of matching portions and the overall score;

wherein the one or more processors are configured to determine each first score based on the frequency with which each respective portion in the set of matching portions occurs in the plurality of stored patterns.

8. The system of claim 7 , wherein each first score comprises a ranking of a likelihood that each respective portion in the set of matching portions is associated with malware.

9. The system of claim 7 , wherein the one or more processors are configured to compare the plurality of portions of the file to the plurality of stored patterns by comparing byte sequences or text strings.

10. The system of claim 7 , wherein the one or more processors are configured to provide the information to a human analyst to assist in determining whether the file is malware.

11. The system of claim 7 , wherein the information further comprises a description of each portion in the set of matching portions.

12. The system of claim 7 , wherein the one or more processors are further configured to:

determine that the file is potential malware in response to determining the first score for each portion in the set of matching portions; and

perform remedial action regarding the file in response to determining that the file is potential malware, performing remedial action regarding the file.

13. At least one non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, are configured to:

identify a plurality of portions of a file;

compare the plurality of portions of the file to a plurality of stored patterns, the plurality of stored patterns comprising portions of known malware;

determine, from the plurality of portions of the file and based on the comparing of the plurality of portions of the file to the plurality of stored patterns comprising portion of known malware, a set of matching portions, the set of matching portions comprising one or more of the plurality of portions of the file;

determine a first score for each portion in the set of matching portions;

determine an overall score for the file as a function of the first scores;

compare the overall score to a threshold to determine whether the file comprises malware, wherein the threshold is based on the context of how the file was received; and

provide information regarding the set of matching portions, the information comprising the first score determined for each portion of the set of matching portions and the overall score;

wherein the instructions are configured to determine each first score based on the frequency with which each respective portion in the set of matching portions occurs in the plurality of stored patterns.

14. The at least one non-transitory computer-readable medium of claim 13 , wherein each first score comprises a ranking of a likelihood that each respective portion in the set of matching portions is associated with malware.

15. The at least one non-transitory computer-readable medium of claim 13 , wherein the instructions are configured to compare the plurality of portions of the file to the plurality of stored patterns by comparing byte sequences or text strings.

16. The at least one non-transitory computer-readable medium of claim 13 , wherein the instructions are configured to provide the information to a human analyst to assist in determining whether the file is malware.

17. The at least one non-transitory computer-readable medium of claim 13 , wherein the information further comprises a description of each portion in the set of matching portions.

18. The at least one non-transitory computer-readable medium of claim 13 , wherein the instructions are further configured to:

determine that the file is potential malware in response to determining the first score for each portion in the set of matching portions; and

perform remedial action regarding the file in response to determining that the file is potential malware, performing remedial action regarding the file.

Assignments (13)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2012
From: RICHARD, MATTHEW; LEE, JESSE J.
To: RAYTHEON COMPANY
Reel/Frame 028602/0643 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2011
From: MCDOUGAL, MONTY D.; JENNINGS, RANDY S.; STERNS, WILLIAM E.
To: RAYTHEON COMPANY
Reel/Frame 027344/0595 →