IP Library Granted Patent US 11,082,446
Granted Patent B1
US 11,082,446 · App. 17/160,314 · Granted Aug 3, 2021

Malware infection prediction and prevention

Inventors: Sunil Mathew Thomas (Palm Harbor, FL); Tina LaVonne Barfield (Pinellas Park, FL); Adam Hyder (Cupertino, CA)
Assignee: Malwarebytes Inc.
H04L63/145G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,082,446
App. No.
17/160,314
Granted
Aug 3, 2021
Kind
B1
Abstract

A malware infection prediction method predicts a likelihood that a client device is to be infected with in a period of time based on state and behavior telemetry data. A malware infection prediction system receives telemetry data associated with use (i.e. behavior data) and configuration (i.e. state data) of a client device. By using a trained model, the system predicts a likelihood of the client device becoming infected within a given time frame. Based on the predicted likelihood, the system generates recommendations including recommended actions for reducing the likelihood of the client device becoming infected. The system then generates notifications including the recommendations and sends the notifications to the client device or to an administrative account associated with the client device.

Claims (47)

1. A method for preventing malware infection comprising:

receiving, at a server, telemetry data associated with use and configuration of a client device;

predicting a likelihood of the client device becoming infected within a given time frame by applying a trained model to the telemetry data;

generating, based on the likelihood of the client device becoming infected, one or more recommendations including recommended actions for reducing the likelihood of the client device becoming infected;

generating one or more notifications including the recommendations;

sending the notifications to the client device;

detecting an infection result indicating whether or not the client device became infected within the given time frame;

retraining the trained model based on the telemetry data and the infection result; and

storing the retrained model for future predictions.

2. The method of claim 1 , wherein the model is trained based on an aggregated telemetry dataset based on a plurality of client devices.

3. The method of claim 1 , wherein the trained model further predicts likelihood of the client device becoming infected based on at least one of the following: a time of a day, a time of a month or a time of a year.

4. The method of claim 1 , wherein the trained model further predicts one or more types of malware that are associated with the likelihood of the client device becoming infected.

5. The method of claim 1 , wherein the trained model is a machine learning model trained based on supervised learning or unsupervised learning.

6. The method of claim 1 , wherein the use and configuration data comprise:

user behavior data including information of user interactions associated with one or more users who interact with the client device;

configuration data corresponding to a current configuration of the client device, the configuration data including at least one of the following: installed software, software configuration, hardware configuration, security configuration and network configuration.

7. The method of claim 1 , wherein the recommendations include at least one of the following: enable firewall, enable virtual private network (VPN), updating a software, scanning a device that connects to the client device, changing security settings, and changing network settings.

8. A non-transitory computer readable storage medium storing instructions for preventing malware infection, the instructions when executed by one or more processors causing the one or more processors to perform steps comprising:

receiving, at a server, telemetry data associated with use and configuration of a client device;

predicting a likelihood of the client device becoming infected within a given time frame by applying a trained model to the telemetry data;

generating, based on the likelihood of the client device becoming infected, one or more recommendations including recommended actions for reducing the likelihood of the client device becoming infected;

generating one or more notifications including the recommendations;

sending the notifications to the client device;

detecting an infection result indicating whether or not the client device became infected within the given time frame;

retraining the trained model based on the telemetry data and the infection result; and

storing the retrained model for future predictions.

9. The non-transitory computer readable storage medium of claim 8 , wherein the model is trained based on an aggregated telemetry dataset based on a plurality of client devices.

10. The non-transitory computer readable storage medium of claim 8 , wherein the trained model further predicts likelihood of the client device becoming infected based on at least one of the following: a time of a day, a time of a month or a time of a year.

11. The non-transitory computer readable storage medium of claim 8 , wherein the trained model further predicts one or more types of malware that are associated with the likelihood of the client device becoming infected.

12. The non-transitory computer readable storage medium of claim 8 , wherein the use and configuration data comprise:

user behavior data including information of user interactions associated with one or more users who interact with the client device;

configuration data corresponding to a current configuration of the client device, the configuration data including at least one of the following: installed software, software configuration, hardware configuration, security configuration and network configuration.

13. The non-transitory computer readable storage medium of claim 8 , wherein the recommendations include at least one of the following: enable firewall, enable virtual private network (VPN), updating a software, scanning a device that connects to the client device, changing security settings, and changing network settings.

14. A computer system comprising:

one or more processors; and

a non-transitory computer readable storage medium storing instructions for preventing malware infection, the instructions when executed by one or more processors causing the one or more processors to perform steps comprising:

receiving, at a server, telemetry data associated with use and configuration of a client device;

predicting a likelihood of the client device becoming infected within a given time frame by applying a trained model to the telemetry data;

generating, based on the likelihood of the client device becoming infected, one or more recommendations including recommended actions for reducing the likelihood of the client device becoming infected;

generating one or more notifications including the recommendations;

sending the notifications to the client device;

detecting an infection result indicating whether or not the client device became infected within the given time frame;

retraining the trained model based on the telemetry data and the infection result; and

storing the retrained model for future predictions.

15. The computer system of claim 14 , wherein the model is trained based on an aggregated telemetry dataset based on a plurality of client devices.

16. The computer system of claim 14 , wherein the trained model further predicts likelihood of the client device becoming infected based on at least one of the following: a time of a day, a time of a month or a time of a year.

17. The computer system of claim 14 , wherein the trained model further predicts one or more types of malware that are associated with the likelihood of the client device becoming infected.

Assignments (7)
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES INC.
Reel/Frame 069193/0505 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 069193/0563 →
SECURITY INTEREST Recorded Oct 18, 2024
From: MALWAREBYTES INC.; MALWAREBYTES CORPORATE HOLDCO INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 068943/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: MALWAREBYTES INC.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 066900/0386 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 26, 2024
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066373/0912 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 1, 2023
From: MALWAREBYTES INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062599/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2021
From: THOMAS, SUNIL MATHEW; BARFIELD, TINA LAVONNE; HYDER, ADAM
To: MALWAREBYTES INC.
Reel/Frame 055788/0767 →
Cited By (1)
US 12,462,031