IP Library › Granted Patent US 11,210,396
Granted Patent B2
US 11,210,396 · App. 16/112,825 · Granted Dec 28, 2021

Light-weight behavioral malware detection for windows platforms

Inventors: Bander Mohamed Alsulami (Philadelphia, PA); Spiros Mancoridis (Philadelphia, PA); Avinash Srinivasan (Lansdale, PA)
Assignees: Drexel University; Temple University
G06F21/566G06F16/16G06F2221/034G06F2221/07G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,210,396
App. No.
16/112,825
Filed
Aug 27, 2018
Granted
Dec 28, 2021
Kind
B2
Art Unit
2498
USPC
726/24
Abstract

A behavioral malware detection involves extracting features from prefetch files, wherein prefetch files; classifying and detecting benign applications from malicious applications using the features of the prefetch files; and quarantining malicious applications based on the detection.

Claims (11)

1. A behavioral malware detection method comprising the steps of:

extracting features from prefetch files in a computer operating system, wherein prefetch files accelerate computer application launch times by monitoring and adapting to applications usage patterns over time;

representing a list of dependency file names in the prefetch files using a Bag of Words (BoW) model, wherein the list of dependency file names are the features;

classifying and detecting benign applications from malicious applications using the BoW model, wherein the classification and detection is done using Bag of Words (BoW) extraction techniques to identify feature vectors of the features that are the list of dependency file names, wherein Singular Value Decomposition (SVD) is applied to extract singular values of the feature vectors in the classification and detection of benign applications and malicious applications;

quarantining malicious applications based on the detection.

2. The behavioral malware detection method of claim 1 , wherein the prefetch files are Microsoft Windows® prefetch files.

3. The behavioral malware detection method of claim 1 , wherein the BoW extraction technique supports two different Term Frequency (TF) representations: binary and raw.

4. The behavioral malware detection method of claim 1 , wherein classification of benign applications and malicious applications is achieved using Logistic Regression.

5. The behavioral malware detection method of claim 1 , wherein the detecting of malware is classified into two classes: the benign class and malicious class.

6. The behavioral malware detection method of claim 1 , wherein the classification is performed using Logistic Regression.

7. The behavioral malware detection method of claim 1 , wherein the classification updates new families of malicious applications to improve classification.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2019
From: SRINIVASAN, AVINASH
To: TEMPLE UNIVERSITY - OF THE COMMONWEALTH SYSTEM OF HIGHER EDUCATION
Reel/Frame 049095/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2019
From: ALSULAMI, BANDER MOHAMED; MANCORIDIS, SPIROS
To: DREXEL UNIVERSITY
Reel/Frame 048944/0114 →
Continuity (2)
Provisional Application 62550418 · Aug 25, 2017
Related Publication 20190065746A1 · Feb 28, 2019
Cited By (2)
US 12,346,432 US 12,500,902