IP Library Granted Patent US 10,423,786
Granted Patent B2
US 10,423,786 · App. 15/352,158 · Granted Sep 24, 2019

System and method for statistical analysis of comparative entropy

Inventors: David Neill Beveridge (Hillsboro, OR); Abhishek Ajay Karnik (Portland, OR); Kevin A. Beets (Ladera Ranch, CA); Tad M. Heppner (Göteborg, SE); Karthik Raman (San Francisco, CA)
Assignee: McAfee, LLC
G06F21/563G06F21/56G06F21/565
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,423,786
App. No.
15/352,158
Granted
Sep 24, 2019
Kind
B2
Abstract

In accordance with one embodiment of the present disclosure, a method for determining the similarity between a first data set and a second data set is provided. The method includes performing an entropy analysis on the first and second data sets to produce a first entropy result, wherein the first data set comprises data representative of a first one or more computer files of known content and the second data set comprises data representative of a one or more computer files of unknown content; analyzing the first entropy result; and if the first entropy result is within a predetermined threshold, identifying the second data set as substantially related to the first data set.

Claims (49)

1. At least one non-transitory machine readable storage medium, comprising computer-executable instructions carried on the computer readable storage medium, the instructions, when read and executed by a processor, cause the processor to:

electronically receive one or more files of an unknown content;

determine that the one or more files of an unknown content contain malware by:

comparing token values between a first probability distribution function associated with a first data set comprising one of more computer files of a first known content and a second probability distribution function associated with a second data set comprising the one or more computer files of an unknown content, wherein the first known content is known to be malware;

generating a first entropy result based on a difference between an expected number of occurrences of the token values in the first probability distribution function and an actual number of occurrences of the token values in the second probability distribution function; and

determining that the second data set is substantially related to the first data set based on a determination that the first entropy result is within a threshold; and

based on the determination that the one or more files of an unknown content contain malware, notify a user that the unknown content is malware.

2. The at least one non-transitory machine readable storage medium of claim 1 , further comprising instructions to cause the processor to:

compare the token values between a third probability distribution function of a third data set comprising a second known content and the second probability distribution function;

generate a second entropy result from the third data set and the second data set; and

determine whether the second data set is substantially related to the third data set based on whether the second entropy result is within the threshold.

3. The at least one non-transitory machine readable storage medium of claim 1 , wherein the instructions that cause the processor to generate the first entropy result further cause the processor to determine whether a first entropy value associated with the first data set is mathematically similar to a second entropy value associated with the second data set.

4. The at least one non-transitory machine readable storage medium of claim 1 , wherein the determination whether the second data is substantially related to the first data set is further based on whether the second data set is likely derived from the first data set.

5. The at least one non-transitory machine readable storage medium of claim 1 , wherein the first data set comprises data representative of a probability distribution function associated with one or more resources, the one or more resources constituting a portion of the first known content.

6. The at least one non-transitory machine readable storage medium of claim 1 , wherein the second data set comprises data representative of a probability distribution function associated with one or more resources, the one or more resources constituting a portion of the unknown content.

7. The at least one non-transitory machine readable storage medium of claim 1 , wherein the first known content and the unknown content are members of one or more of a plurality of categories of computer files.

8. The at least one non-transitory machine readable storage medium of claim 7 , wherein the instructions further cause the processor to categorize the unknown content into the one or more of the plurality of categories of computer files based substantially on the determination that the second data set is substantially related to the first data set.

9. The at least one non-transitory machine readable storage medium of claim 7 , wherein the plurality of categories of computer files include at least one of: malware, source code, image files, or object code.

10. The at least one non-transitory machine readable storage medium of claim 2 , wherein the instructions that cause the processor to generate the second entropy result further cause the processor to determine whether a third entropy value associated with the third data set is mathematically similar to a second entropy value associated with the second data set.

11. The at least one he non-transitory machine readable storage medium of claim 2 , wherein the determination whether the second data is substantially related to the third data set is further based on whether the second data set is likely derived from the third data set.

12. The at least one non-transitory machine readable storage medium of claim 2 , wherein the third data set comprises data representative of a probability distribution function associated with one or more resources, the one or more resources constituting a portion of the second known content.

13. The at least one non-transitory machine readable storage medium of claim 2 , wherein the second known content is a member of one or more of a plurality of categories of computer files.

14. The at least one non-transitory machine readable storage medium of claim 13 , wherein the instructions further cause the processor to categorize the second known content into the one or more of the plurality of categories of computer files based substantially on the determination that the second data set is substantially related to the third data set.

15. The at least one non-transitory machine readable storage medium of claim 13 , wherein the plurality of categories of computer files include at least one of: malware, source code, image files, or object code.

16. An electronic system for determining the similarity between a first data set and a second data set, the system comprising:

a computing device configured to:

electronically receive one or more files of an unknown content;

determine that the one or more files of an unknown content contain malware by:

comparing token values between a first probability distribution function associated with the first data set comprising one or more computer files of a first known content and a second probability distribution function associated with the second data set comprising one or more computer files of an unknown content, wherein the first known content is known to be malware;

generating a first entropy result based on a difference between an expected number of occurrences of the token values in the first probability distribution function and an actual number of occurrences of the token values in the second probability distribution function; and

determining that the second data set is substantially related to the first data set based on a determination that the first entropy result is within a threshold; and

based on the determination that the one or more files of an unknown content contain malware, notify a user that the unknown content is malware.

17. The electronic system of claim 16 , wherein the computing device is also configured to:

compare the token values between a third probability distribution function of a third data set comprising a second known content and the second probability distribution function;

generate a second entropy result from the third data set and the second data set; and

determine whether the second data set is substantially related to the third data set based on whether the second entropy result is within the threshold.

18. The electronic system of claim 16 , wherein the computing device is also configured to generate the first entropy result further based on a determination whether a first entropy value associated with the first data set is mathematically similar to a second entropy value associated with the second data set.

19. The electronic system of claim 16 , wherein the computing device is also configured to determine whether the second data is substantially related to the first data set further based on whether the second data set is likely derived from the first data set.

20. The electronic system of claim 16 , wherein the first data set comprises data representative of a probability distribution function associated with one or more resources, the one or more resources constituting a portion of the first known content.

21. The electronic system of claim 16 , wherein the second data set comprises data representative of a probability distribution function associated with one or more resources, the one or more resources constituting a portion of the unknown content.

22. The electronic system of claim 16 , wherein the first known content and the unknown content are members of one or more of a plurality of categories of computer files.

23. The electronic system of claim 22 , wherein the computing device is further configured to categorize the unknown content into the one or more of the plurality of categories of computer files based substantially on the determination that the second data set is substantially related to the first data set.

24. The electronic system of claim 22 , wherein the plurality of categories of computer files include at least one of: malware, source code, image files, or object code.

25. The electronic system of claim 17 , wherein the computing device is also configured to generate the second entropy result further based on a determination whether a third entropy value associated with the third data set is mathematically similar to a second entropy value associated with the second data set.

26. The electronic system of claim 17 , wherein the computing device is also configured to determine whether the second data is substantially related to the third data set further based on whether the second data set is likely derived from the third data set.

27. The electronic system of claim 17 , wherein the third data set comprises data representative of a probability distribution function associated with one or more resources, the one or more resources constituting a portion of the second known content.

28. The electronic system of claim 17 , wherein the second known content is a member of one or more of a plurality of categories of computer files.

29. The electronic system of claim 28 , wherein the computing device is further configured to categorize the second known content into the one or more of the plurality of categories of computer files based substantially on the determination that the second data set is substantially related to the third data set.

30. The electronic system of claim 28 , wherein the plurality of categories of computer files include at least one of: malware, source code, image files, or object code.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2016
From: BEVERIDGE, DAVID NEILL; KARNIK, ABHISHEK AJAY; BEETS, KEVIN A.; HEPPNER, TAD M.; RAMAN, KARTHIK
To: MCAFEE, INC.
Reel/Frame 040329/0983 →
Continuity (2)
Continuation 13232718 · Sep 14, 2011
Related Publication 20170061125A1 · Mar 2, 2017