IP Library › Granted Patent US 11,803,641
Granted Patent B2
US 11,803,641 · App. 17/079,809 · Granted Oct 31, 2023

Utilizing Machine Learning to detect malicious executable files efficiently and effectively

Inventors: Changsha Ma (Campbell, CA); Nirmal Singh (Mohali, IN); Naveen Selvan (Mohali, IN); Tarun Dewan (Mohali, IN); Uday Pratap Singh (Mohali, IN); Deepen Desai (San Ramon, CA); Bharath Meesala (Bengaluru, IN); Rakshitha Hedge (Bengaluru, IN); Parnit Sainion (Morgan Hill, CA); Shashank Gupta (Sunnyvale, CA); Narinder Paul (Sunnyvale, CA); Rex Shang (Los Altos, CA); Howie Xu (Palo Alto, CA)
Assignee: Zscaler, Inc.
G06F21/565G06F21/53G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,803,641
App. No.
17/079,809
Granted
Oct 31, 2023
Kind
B2
Abstract

Systems and methods include determining a plurality of features associated with executable files, wherein the plurality of features are each based on static properties in predefined structure of the executable files; obtaining training data that includes samples of benign executable files and malicious executable files; extracting the plurality of features from the training data; and utilizing the extracted plurality of features to train a machine learning model to detect malicious executable files.

Claims (51)

1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors to perform steps of:

monitoring executable files in production traffic;

determining a plurality of features associated with the executable files that are effective to use for training a machine learning model based on the monitoring, wherein the plurality of features are each based on static properties in predefined structure of the executable files, and wherein the plurality of features include section details, each section being a segment of divided memory;

obtaining training data that includes samples of benign executable files and malicious executable files;

extracting the plurality of features from the training data; and

utilizing the extracted plurality of features to train the machine learning model to detect malicious executable files.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

providing the machine learning model for use in production to detect executable files.

3. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

obtaining data related to use of the machine learning model in production, wherein the data is obtained by monitoring traffic associated with users; and

updating the training of the machine learning model based on the data.

4. The non-transitory computer-readable storage medium of claim 3 , wherein the machine learning model is used in production in a cloud-based system, and wherein the updated trained machine learning model is distributed to a plurality of enforcement nodes via a central authority.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include

obtaining data related to a sandbox of executable files;

determining effectiveness of the machine learning model based on comparing results from the machine learning model and the data; and

updating the plurality of features based on the comparing.

6. The non-transitory computer-readable storage medium of claim 5 , wherein the sandbox is associated with a cloud-based system.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the executable file is a Portable Executable (PE) file.

8. The non-transitory computer-readable storage medium of claim 1 , wherein the static properties include any of file header information, file section details, file name anomalies, a digital certificate, and import/export detail.

9. A method comprising:

monitoring executable files in production traffic;

determining a plurality of features associated with the executable files that are effective to use for training a machine learning model based on the monitoring, wherein the plurality of features are each based on static properties in predefined structure of the executable files, and wherein the plurality of features include section details, each section being a segment of divided memory;

obtaining training data that includes samples of benign executable files and malicious executable files;

extracting the plurality of features from the training data; and

utilizing the extracted plurality of features to train the machine learning model to detect malicious executable files.

10. The method of claim 9 , further comprising

providing the machine learning model for use in production to detect executable files.

11. The method of claim 9 , further comprising

obtaining data related to use of the machine learning model in production, wherein the data is obtained by monitoring traffic associated with users; and

updating the training of the machine learning model based on the data.

12. The method of claim 11 , wherein the machine learning model is used in production in a cloud-based system, and wherein the updated trained machine learning model is distributed to a plurality of enforcement nodes via a central authority.

13. The method of claim 9 , further comprising

obtaining data related to a sandbox of executable files;

determining effectiveness of the machine learning model based comparing results from the machine learning model and the data; and

updating the plurality of features based on the comparing.

14. The method of claim 13 , wherein the sandbox is associated with a cloud-based system.

15. The method of claim 9 , wherein the executable file is a Portable Executable (PE) file.

16. The method of claim 9 , wherein the static properties include any of file header information, file section details, file name anomalies, a digital certificate, and import/export detail.

17. A server comprising:

one or more processors; and

memory storing instructions that, when executed, cause the one or more processors to

monitor executable files in production traffic;

determine a plurality of features associated with h executable files that are effective to use for training a machine learning model based on the monitoring, structure of the executable files, and wherein the plurality of features include section details, each section being a segment of divided memory;

obtain training data that includes samples of benign executable files and malicious executable files;

extract the plurality of features from the training data; and

utilize the extracted plurality of features to train the machine learning model to detect malicious executable files.

18. The server of claim 17 , wherein the instructions that, when executed, cause the one or more processors to provide the machine learning model for use in production to detect executable files.

19. The server of claim 17 , wherein the instructions that, when executed, cause the one or more processors to

obtain data related to use of the machine learning model in production, wherein the data is obtained by monitoring traffic associated with users; and

update the training of the machine learning model based on the data.

20. The server of claim 17 , wherein the static properties include any of file header information, file section details, file name anomalies, a digital certificate, and import/export detail.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: MA, CHANGSHA; SINGH, NIRMAL; SELVAN, NAVEEN; DEWAN, TARUN; SINGH, UDAY PRATAP; DESAI, DEEPEN; MEESALA, BHARATH; HEDGE, RAKSHITHA; SAINION, PARNIT; GUPTA, SHASHANK; PAUL, NARINDER; SHANG, REX; XU, HOWIE
To: ZSCALER, INC.
Reel/Frame 054164/0072 →
Priority Claims (1)
IN 202011039471 · Sep 11, 2020 · national
Continuity (1)
Related Publication 20220083659A1 · Mar 17, 2022
Cited By (2)
US 12,346,432 US 12,568,104