IP Library Granted Patent US 10,068,187
Granted Patent B1
US 10,068,187 · App. 15/610,173 · Granted Sep 4, 2018

Generation and use of trained file classifiers for malware detection

Inventor: Na Sai (Austin, TX)
Assignee: SPARKCOGNITION, INC.
G06N99/005G06F21/562G06N3/02G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,068,187
App. No.
15/610,173
Granted
Sep 4, 2018
Kind
B1
Abstract

A method includes accessing information identifying multiple files and identifying classification data for the multiple files, where the classification data indicates, for a particular file of the multiple files, whether the particular file includes malware. The method also includes generating n-gram vectors for the multiple files by, for each file, generating an n-gram vector indicating occurrences of character pairs in printable characters representing the file. The method further includes generating and storing a file classifier using the n-gram vectors and the classification data as supervised training data.

Claims (44)

1. A computing device comprising:

a memory configured to store instructions to generate a trained file classifier; and

a processor configured to execute the instructions from the memory to perform operations comprising:

accessing information identifying multiple files and identifying classification data for the multiple files, wherein the classification data indicates, for a particular file of the multiple files, whether the particular file includes malware;

generating a feature vector representing the particular file of the multiple files, the feature vector including:

zero-skip n-gram data indicating occurrences of adjacent characters in printable characters representing the particular file;

skip n-gram data indicating occurrences of non-adjacent characters in the printable characters representing the particular file; and

n-gram data indicating occurrences of groups of entropy indicators in a set of entropy indicators derived from file entropy data for the particular file, each entropy indicator of the set of entropy indicators having a value representing entropy of a corresponding chunk of the particular file;

generating the trained file classifier using the feature vector and the classification data as supervised training data; and

transmitting the trained file classifier to a remote computing device via a network, wherein the trained file classifier is executable by the remote computing device to restrict access to a file or to restrict execution of the file based on a classification result generated by execution of the trained file classifier.

2. The computing device of claim 1 , wherein the zero-skip n-gram data includes a Boolean vector indicating the occurrences of the adjacent characters in the printable characters.

3. The computing device of claim 1 , wherein the zero-skip n-gram data indicates a count of the occurrences of the adjacent characters pairs in the printable characters.

4. The computing device of claim 1 , wherein the skip n-gram data includes a Boolean vector indicating the occurrences of the non-adjacent characters in the printable characters.

5. The computing device of claim 1 , wherein the trained file classifier corresponds to a decision tree, a neural network, or a support vector machine.

6. The computing device of claim 1 , wherein the skip n-gram data indicates a count of the occurrences of the non-adjacent characters in the printable characters.

7. A method comprising:

accessing information identifying multiple files and identifying classification data for the multiple files, wherein the classification data indicates, for a particular file of the multiple files, whether the particular file includes malware;

generating a feature vector representing the particular file of the multiple files, the feature vector including:

zero-skip n-gram data indicating occurrences of adjacent characters in printable characters representing the particular file;

skip n-gram data indicating occurrences of non-adjacent characters in the printable characters representing the particular file; and

n-gram data indicating occurrences of groups of entropy indicators in a set of entropy indicators derived from file entropy data for the particular file, each entropy indicator of the set of entropy indicators having a value representing entropy of a corresponding chunk of the particular file;

generating a trained file classifier using the feature vector and the classification data as supervised training data; and

transmitting the trained file classifier to a remote computing device via a network, wherein the trained file classifier is executable by the remote computing device to restrict access to a file or to restrict execution of the file based on a classification result generated by execution of the trained file classifier.

8. The method of claim 7 , further comprising processing the particular file to generate the printable characters representing the particular file.

9. The method of claim 7 , wherein the zero-skip n-gram data includes a Boolean vector indicating the occurrences of the adjacent characters in the printable characters.

10. The method of claim 7 , wherein the zero-skip n-gram data indicates a count of the occurrences of the adjacent characters in the printable characters.

11. The method of claim 7 , wherein the feature vector includes data representing to a plurality of skip n-grams, each skip n-gram of the plurality of skip n-grams based on a different skip value.

12. The method of claim 7 , wherein the non-adjacent characters of the skip n-gram data correspond to two characters separated by at least one other character in the printable characters.

13. The method of claim 7 , wherein the non-adjacent characters of the skip n-gram data correspond to two characters separated by at least two other characters in the printable characters.

14. The method of claim 7 , wherein the non-adjacent characters of the skip n-gram data correspond to two characters separated by at least three other characters in the printable characters.

15. The method of claim 7 , wherein the feature vector includes data representing to a plurality of skip n-grams, each skip n-gram of the plurality of skip n-grams based on a different skip value, and wherein the n-gram data indicating occurrences of the groups of entropy indicators is based on a value of n that is different from a value of n of zero-skip n-grams corresponding to the zero-skip n-gram data.

16. A computer-readable storage device storing instructions that, when executed, cause a computer to perform operations comprising:

accessing information identifying multiple files and identifying classification data for the multiple files, wherein the classification data indicates, for a particular file of the multiple files, whether the particular file includes malware;

generating a feature vector representing the particular file of the multiple files, the feature vector including:

zero-skip n-gram data indicating occurrences of adjacent characters in printable characters representing the particular file;

skip n-gram data indicating occurrences of non-adjacent characters in the printable characters representing the particular file; and

n-gram data indicating occurrences of groups of entropy indicators in a set of entropy indicators derived from file entropy data for the particular file, each entropy indicator of the set of entropy indicators having a value representing entropy of a corresponding chunk of the particular file;

generating and storing a trained file classifier using the feature vector and the classification data as supervised training data; and

causing the trained file classifier to be transmitted to a remote computing device via a network, wherein the trained file classifier is executable by the remote computing device to restrict access to a file or to restrict execution of the file based on a classification result generated by execution of the trained file classifier.

17. The computer-readable storage device of claim 16 , wherein the multiple files include files with malware, files without malware, and corresponding classification data.

18. The computer-readable storage device of claim 16 , wherein the operations further comprise:

generating a hash value based on the feature vector and storing the hash value of the feature vector as an identifier of the particular file.

19. The computer-readable storage device of claim 16 , wherein the particular file is a binary file and the operations further comprise generating the printable characters representing the binary file by converting at least a portion of the binary file to American Standard Code for Information Interchange (ASCII) characters.

20. The computer-readable storage device of claim 16 , wherein the feature vector includes data representing a plurality of skip n-grams, each skip n-gram of the plurality of skip n-grams based on a different skip value.

Assignments (4)
CHANGE OF NAME Recorded Jul 17, 2025
From: SPARKCOGNITION, INC.
To: AVATHON, INC.
Reel/Frame 072016/0432 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 4, 2024
From: ORIX GROWTH CAPITAL, LLC
To: SPARKCOGNITION, INC.
Reel/Frame 069300/0567 →
SECURITY INTEREST Recorded Apr 22, 2022
From: SPARKCOGNITION, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 059760/0360 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2017
From: SAI, NA
To: SPARKCOGNITION, INC.
Reel/Frame 042549/0217 →
Continuity (1)
Continuation 15583565 · May 1, 2017