IP Library Patent Application 17159909
Patent Application
App. No. 17/159,909

AUTOMATED MALWARE CLASSIFICATION WITH HUMAN-READABLE EXPLANATIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/159,909
Abstract

A malware classification is generated for an input data set with a human-readable explanation of the classification. An input data set having a hierarchical structure is received in a neural network that has an architecture based on a schema determined from a plurality of second input data sets and that is trained to classify received input data sets into one or more of a plurality of classes. An explanation is provided with the output of the neural network, the explanation comprising a subset of at least one input data set that caused the at least one input data set to be classified into a certain class using the schema of the generated neural network. The explanation may further be derived from the statistical contribution of one or more features of the input data set that caused the at least one input data set to be classified into a certain class.

Claims (31)

1 . A method of generating a malware classification for an input data set with a human-readable explanation, comprising:

receiving an input data set having a hierarchical structure;

analyzing the input data set using an artificial intelligence module to automatically output a malware classification for the received input data set; and

generating an explanation regarding the malware classification comprising a subset of the input data set that is responsible for the output malware classification.

2 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 1 , further comprising constructing the artificial intelligence module using a hierarchy of the input data set.

3 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 1 , wherein the artificial intelligence module is a neural network.

4 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 3 , wherein the neural network comprises a hierarchical multiple-instance-learning neural network.

5 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 1 , wherein the input data set having a hierarchical structure comprises JavaScript Object Notation (JSON) data or an Extensible Markup Language (XML) data.

6 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 1 , wherein the input data set is derived from at least one of sandbox execution of a file, static Portable Executable (PE) file analysis, or disassembly of executable code.

7 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 1 , wherein the malware classification comprises at least one of types of malware and families of malware.

8 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 1 , wherein the explanation comprises one or more logical rules that cause the subset of the input data set to produce the output malware classification via the artificial intelligence module.

9 . A method of generating a malware classification for an input data set with a human-readable explanation, comprising:

receiving a plurality of input data sets having a hierarchical structure;

determining a schema from one or more of the received input data sets;

generating a neural network architecture based on the determined schema;

training the generated neural network using the received plurality of input data sets to classify the received input data sets into one or more of a plurality of malware classes;

providing an explanation comprising a subset of at least one input data set that caused the at least one input data set to be classified into a certain malware class using the schema of the generated neural network.

10 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 9 , wherein the input data set having a hierarchical structure comprises JavaScript Object Notation (JSON) data or an Extensible Markup Language (XML) data.

11 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 9 , wherein the input data set is derived from at least one of sandbox execution of a file, static Portable Executable (PE) file analysis, or disassembly of executable code.

12 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 9 , wherein the neural network comprises a hierarchical multiple-instance-learning neural network.

13 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 9 , wherein the malware classification comprises at least one of types of malware and families of malware.

14 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 9 , wherein the explanation comprises one or more logical rules that cause the subset of the input data set to produce the output malware classification via the artificial intelligence module.

15 . A method of generating a malware classification for an input data set with a human-readable explanation, comprising:

receiving an input data sets having hierarchical structure;

processing the received input data set in a neural network, the neural network having an architecture based on a schema determined from a plurality of second input data sets and trained to classify received input data sets into one or more of a plurality of classes; and

providing an explanation comprising a subset of at least one input data set that caused the at least one input data set to be classified into a certain class using the schema of the generated neural network.

16 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 15 , further comprising constructing the neural network constructed using a hierarchy of the input data set.

17 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 15 , wherein the neural network comprises a hierarchical multiple-instance-learning neural network.

18 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 15 , wherein the input data set is derived from at least one of sandbox execution of a file, static Portable Executable (PE) file analysis, or disassembly of executable code.

19 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 15 , wherein the explanation comprises one or more logical rules that cause the subset of the input data set to produce the output malware classification via the neural network.

20 . The method of generating a malware classification for an input data set with a human-readable explanation of claim 19 , wherein the explanation is derived from the statistical contribution of one or more features of the input data set that caused the at least one input data set to be classified into a certain class.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →