IP Library Granted Patent US 10,599,844
Granted Patent B2
US 10,599,844 · App. 14/709,875 · Granted Mar 24, 2020

Automatic threat detection of executable files based on static data analysis

Inventors: Mauritius Schmidtler (Escondido, CA); Gaurav Dalal (San Jose, CA); Reza Yoosoofmiya (San Diego, CA)
Assignee: Webroot, Inc.
G06F21/565G06F21/562G06N20/00G06F8/53G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,599,844
App. No.
14/709,875
Granted
Mar 24, 2020
Kind
B2
Abstract

Aspects of the present disclosure relate to threat detection of executable files. A plurality of static data points may be extracted from an executable file without decrypting or unpacking the executable file. The executable file may then be analyzed without decrypting or unpacking the executable file. Analysis of the executable file may comprise applying a classifier to the plurality of extracted static data points. The classifier may be trained from data comprising known malicious executable files, known benign executable files and known unwanted executable files. Based upon analysis of the executable file, a determination can be made as to whether the executable file is harmful.

Claims (31)

1. A computer-implemented method comprising:

extracting a plurality of static data points from an executable file without decrypting or unpacking the executable file, wherein the plurality of static data points represent predefined character strings in the executable file;

generating a feature vector from the plurality of static data points using a classifier trained to classify the plurality of static data points based on a collection of data comprising known malicious executable files, known benign executable files, and known unwanted executable files, wherein the collection of data comprises at least a portion of the plurality of static data points, and wherein one or more features of the feature vector are selectively turned on or off based on whether a value of one or more static data points from the plurality of extracted static data points is within a predetermined range; and

evaluating the feature vector using support vector processing to determine whether the executable file is harmful.

2. The computer-implemented method according to claim 1 , wherein the extracting the plurality of static data points further comprises classifying the extracted static data points according to a type of data extracted from the executable file, and encoding the extracted static data points for the classifier based on the classification.

3. The computer-implemented method according to claim 2 , wherein generating the at least one feature vector comprises selectively setting features of the classifier based on the plurality of extracted static data points.

4. The computer-implemented method according to claim 2 , wherein the classifying the at least one static data point comprises classifying the plurality of extracted static data points into categories comprising numeric values, nominal values, string or byte sequences, and Boolean values.

5. The computer-implemented method according to claim 4 , wherein analyzing the executable file further comprises generating at least one feature vector from the plurality of extracted static data points, wherein features of the generated feature vector are weighted based at least upon the classified categories and the plurality of extracted static data points.

6. The computer-implemented method according to claim 1 , wherein determining whether the executable file is harmful further comprises preventing execution of the executable file when a determined probability value that the executable file is harmful exceeds a threshold value.

7. The computer-implemented method according to claim 6 , wherein the threshold value is set based on predetermined false positive range data.

8. The computer-implemented method according to claim 1 , wherein the plurality of static data points is extracted using a machine learning technique.

9. The computer-implemented method according to claim 1 , wherein a determination of whether the executable file is harmful is used to retrain the classifier.

10. A computer-readable storage device containing instructions, that when executed on at least one processor, causing the processor to execute a process comprising:

extracting a plurality of static data points from an executable file without decrypting or unpacking the executable file, wherein the plurality of static data points represent predefined character strings in the executable file;

generating a feature vector from the plurality of static data points using a classifier trained to classify the plurality of static data points based on a collection of data comprising known malicious executable files, known benign executable files and known unwanted executable files, wherein the collection of data comprises at least a portion of the plurality of static data points, and wherein one or more features of the feature vector are selectively turned on or off based on whether one or more values of one or more static data points from the plurality of extracted static data points is within a predetermined range; and

evaluating the feature vector using support vector processing to determine whether the executable file is harmful.

11. The computer-readable storage device according to claim 10 , wherein the extracting of the plurality of static data points executed by the processor further comprises classifying the extracted static data points according to a type of data extracted from the executable file, and encoding the extracted static data points for the classifier based on the classifying.

12. The computer-readable storage device according to claim 11 , wherein generating the at least one feature vector comprises selectively setting features of the classifier based on the plurality of extracted static data points.

13. The computer-readable storage device according to claim 11 , wherein the classifying the at least one static data point comprises classifying the plurality of extracted static data points into categories comprising numeric values, nominal values, string or byte sequences, and Boolean values.

14. The computer-readable storage device according to claim 13 , wherein analyzing the executable file further comprises generating a feature vector from the plurality of extracted static data points, wherein features of the generated feature vector are weighted based at least upon the classified categories and the plurality of extracted static data points.

15. The computer-readable storage device according to claim 10 , wherein determining whether the executable file is harmful further comprises preventing execution of the executable file when a determined probability value that the executable file is harmful exceeds a threshold value.

16. The computer-readable storage device according to claim 15 , wherein the threshold value is set based on predetermined false positive range data.

17. A system comprising:

at least one memory; and

at least one processor operatively connected with the memory and configured to perform operation of:

extracting a plurality of predefined character strings from an executable file without decrypting or unpacking the executable file;

generating a feature vector from the plurality of predefined character strings using a classifier trained to classify the plurality of predefined character strings based on a collection of data comprising known malicious executable files, known benign executable files and known unwanted executable files, wherein the collection of data comprises at least a portion of one or more of the plurality of predefined character strings, and wherein one or more features of the feature vector are selectively turned on or off based on whether a value of one or more predefined character strings from the plurality of predefined character strings is within a predetermined range; and

evaluating the feature vector using support vector processing to determine whether the executable file is harmful.

18. The system according to claim 17 , wherein the determining further comprises preventing execution of the executable file when a determined probability value that the executable file is harmful exceeds a threshold value, and wherein the threshold value is set based on predetermined false positive range data.

19. The system according to claim 17 , wherein the extracting the plurality of predefined character strings further comprises classifying the extracted plurality of predefined character strings according to a type of data extracted from the executable file, and encoding the extracted plurality of predefined character strings for the classifier based on the classification.

20. The system according to claim 17 , wherein determining whether the executable file is harmful further comprises preventing execution of the executable file when a determined probability value that the executable file is harmful exceeds a threshold value.

Assignments (6)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2015
From: SCHMIDTLER, MAURITIUS; DALAL, GAURAV; YOOSOOFMIYA, REZA
To: WEBROOT INC.
Reel/Frame 035618/0509 →
Continuity (1)
Related Publication 20160335435A1 · Nov 17, 2016
Cited By (42)
US 12,189,773 US 12,189,780 US 12,197,383 US 12,204,870 US 12,206,698 US 12,210,479 US 12,210,617 US 12,235,962 US 12,244,626 US 12,248,572 US 12,259,967 US 12,261,822 US 12,261,884 US 12,265,526 US 12,282,549 US 12,292,971 US 12,301,539 US 12,339,962 US 12,341,814 US 12,354,043 US 12,361,358 US 12,363,151 US 12,367,283 US 12,373,730 US 12,412,413 US 12,418,565 US 12,423,078 US 12,432,253 US 12,437,239 US 12,450,351 US 12,452,273 US 12,468,810 US 12,481,777 US 12,488,127 US 12,489,763 US 12,500,905 US 12,526,289 US 12,536,280 US 12,579,268 US 12,598,206 US 12,664,258 US 12,670,455