IP Library Granted Patent US 11,212,307
Granted Patent B2
US 11,212,307 · App. 16/731,776 · Granted Dec 28, 2021

Server-supported malware detection and protection

Inventors: Lucas McLane (Hutto, TX); Jarred Capellman (Round Rock, TX)
Assignee: SPARKCOGNITION, INC.
H04L63/1425G06F21/56G06F21/561G06F21/566G06N3/08G06N5/04G06N20/00G06N20/10G06N20/20H04L9/0643G06F16/27G06N5/003
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,212,307
App. No.
16/731,776
Granted
Dec 28, 2021
Kind
B2
Abstract

A processor-readable storage device storing instructions that cause a processor to perform operations including, subsequent to determining, at a first device based on a first file attribute associated with a file, that a classification for the file is unavailable at the first device, sending the first file attribute from the first device to a second device to determine whether the classification for the file is available at the second device. The operations include receiving a notification at the first device from the second device that the classification for the file is unavailable at the second device. The operations include, determining the classification for the file by performing, at the first device, an analysis of a second file attribute based on a trained file classification model. The operations include sending the classification from the first device to the second device and to a third device.

Claims (39)

1. A processor-readable storage device storing instructions that, when executed, cause a processor to perform operations comprising:

subsequent to determining, at a first device based on a first file attribute associated with a file, that a classification for the file is unavailable at the first device, sending the first file attribute from the first device to a second device to determine whether the classification for the file is available at the second device, the second device storing data corresponding to a plurality of file attributes analyzed by a plurality of devices;

subsequent to sending the first file attribute to the second device, receiving a notification at the first device from the second device that the classification for the file is unavailable at the second device;

in response to receiving the notification, determining the classification for the file by performing, at the first device, an analysis of a second file attribute based on a trained file classification model, wherein the second file attribute is associated with the file, and wherein the second file attribute is distinct from the first file attribute and distinct from an entirety of the file;

sending the classification from the first device to the second device;

storing the classification in a cache at the first device; and

sending the classification to a third device responsive to determining that a third file attribute from the third device corresponds to the classification, wherein the classification is sent to the third device without sending the third file attribute to the second device subsequent to storing the classification.

2. The processor-readable storage device of claim 1 , wherein the classification includes a confidence level generated by the trained file classification model.

3. The processor-readable storage device of claim 1 , wherein the second device is coupled to a plurality of enterprise servers associated with a plurality of enterprises, each of the plurality of enterprise servers configured, in response to determining that a particular classification for a particular file is unavailable at a respective local prediction cache, to query the second device for the particular classification prior to executing a respective local trained classification model to determine the particular classification.

4. The processor-readable storage device of claim 1 , wherein the operations further comprise receiving the first file attribute from a fourth device.

5. The processor-readable storage device of claim 1 , wherein the first file attribute includes a secure hash algorithm (SHA) hash value determined from the file.

6. The processor-readable storage device of claim 1 , wherein the operations further comprise updating the trained file classification model based on a second classification model received from the second device, wherein the classification model includes data corresponding to the classification.

7. The processor-readable storage device of claim 6 , wherein the first device is associated with a first enterprise, and wherein the second classification model is distinct from a third classification model received at a fourth device associated with a second enterprise from the second device, and wherein the third classification model is trained on the classification.

8. The processor-readable storage device of claim 1 , wherein the second file attribute comprises at least one of:

one or more n-gram vectors indicating occurrences of character pairs in printable characters representing content of the file, and

a sequence of entropy indicators, each entropy indicator of the sequence of entropy indicators corresponding to a portion of the file.

9. The processor-readable storage device of claim 1 , wherein the second file attribute comprises an entropy indicator n-gram vector, the entropy indicator n-gram vector indicating occurrences of a plurality of n-grams in a sequence of entropy indicators representing the file, a first entropy indicator of the sequence corresponding to a first bin name associated with a first range of entropy values, a second entropy indicator of the sequence corresponding to a second bin name associated with a second range of entropy values, each of the plurality of n-grams comprising a combination of multiple bin names, wherein n is an integer greater than or equal to two.

10. The processor-readable storage device of claim 1 , wherein the operations further comprise receiving the third file attribute from the third device.

11. A method comprising:

subsequent to determining, at a first device based on a first file attribute associated with a file, that a classification for the file is unavailable at the first device, sending the first file attribute from the first device to a second device to determine whether the classification for the file is available at the second device;

subsequent to sending the first file attribute to the second device, receiving the classification at the first device from the second device responsive to the classification for the file being available at the second device, wherein the second device stores data corresponding to a plurality of file attributes analyzed by a plurality of devices associated with the second device;

storing the classification in a cache at the first device; and

sending the classification to a third device responsive to determining that a second file attribute from the third device corresponds to the classification, wherein the classification is sent to the third device without sending the second file attribute to the second device subsequent to storing the classification.

12. The method of claim 11 , further comprising updating the trained file classification model based on the classification to generate an updated trained file classification model.

13. The method of claim 11 , wherein the first file attribute includes a secure hash algorithm (SHA) value determined from the file.

14. The method of claim 11 , wherein the second device is coupled to a plurality of enterprise servers associated with a plurality of enterprises, each of the plurality of enterprise servers configured, in response to determining that a particular classification for a particular file is unavailable at a respective local prediction cache, to query the second device for the particular classification prior to executing a respective local trained classification model to determine the particular classification.

15. The method of claim 11 , wherein the classification indicates a confidence level generated concurrently with the classification by a classification model.

16. The method of claim 11 , further comprising updating a classification model stored in the second device based on a second classification model received from the first device.

17. A device comprising:

a memory storing instructions;

a first cache; and

a processor configured to execute the instructions from the memory to perform operations including:

subsequent to determining, based on a first file attribute associated with a file, that a classification for the file is unavailable at the device, sending the first file attribute from the device to a second device to determine whether the classification for the file is available at the second device;

subsequent to sending the first file attribute to the second device, receiving the classification at the device from the second device responsive to the classification for the file being available at the second device, wherein the second device stores data corresponding to a plurality of file attributes analyzed by a plurality of devices associated with the second device;

storing the classification in the first cache; and

sending the classification to a third device responsive to determining that a third file attribute from the third device corresponds to the classification, wherein the classification is sent to the third device without sending the third file attribute to the second device subsequent to storing the classification.

18. The device of claim 17 , wherein the second device is coupled to a plurality of enterprise servers associated with a plurality of enterprises, each of the plurality of enterprise servers configured, in response to determining that a particular classification for a particular file is unavailable at a respective local prediction cache, to query the second device for the particular classification prior to executing a respective local trained classification model to determine the particular classification.

19. The device of claim 17 , wherein the first file attribute includes a secure hash algorithm (SHA) value.

20. The device of claim 19 , wherein the classification includes a confidence level generated concurrently with the classification by the trained file classification model.

Assignments (4)
CHANGE OF NAME Recorded Jul 17, 2025
From: SPARKCOGNITION, INC.
To: AVATHON, INC.
Reel/Frame 072016/0432 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 4, 2024
From: ORIX GROWTH CAPITAL, LLC
To: SPARKCOGNITION, INC.
Reel/Frame 069300/0567 →
SECURITY INTEREST Recorded Apr 22, 2022
From: SPARKCOGNITION, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 059760/0360 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2019
From: MCLANE, LUCAS; CAPELLMAN, JARRED
To: SPARKCOGNITION, INC.
Reel/Frame 051394/0305 →
Continuity (3)
Continuation 16406284 · May 8, 2019
Continuation 15639520 · Jun 30, 2017
Related Publication 20200137100A1 · Apr 30, 2020