IP Library Granted Patent US 11,836,252
Granted Patent B2
US 11,836,252 · App. 17/304,641 · Granted Dec 5, 2023

Machine learning through iterative memory analysis for malware detection

Inventors: Vladimir Strogov (Singapore, SG); Alexey Malanov (Singapore, SG); Sergey Ulasen (Singapore, RU); Vyacheslav Levchenko (Saint Petersburg, RU); Serguei Beloussov (Singapore, SG); Stanislav Protasov (Singapore, SG)
Assignee: Acronis International GmbH
G06F21/56G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,836,252
App. No.
17/304,641
Granted
Dec 5, 2023
Kind
B2
Abstract

A system and method of anti-malware analysis including iterative techniques. These techniques are used to create a file attribute tree used by a machine learning analyzer to identify malicious files.

Claims (24)

1. A computer-implemented method for training a machine-learning static analyzer based on iterative executable file analysis, the method executed on a processor, the method comprising the steps of:

a. retrieving file attributes from an untrusted file;

b. creating an attributes tree of the untrusted file's attributes;

c. performing iteration of dynamic analysis of the untrusted file including decryption of at least one encrypted data block of the untrusted file by intercepting an operation of decrypting the at least one encrypted data block during an execution of the untrusted file's code and updating the tree of the file attributes for the untrusted file based on the at least one decrypted data block;

d. repeating step (c) until the file's code has been executed;

e. training machine learning static analyzer based on the updated file attributes tree of the untrusted file and a classified files collection;

f. analyzing the untrusted the and a second untrusted file, wherein the second untrusted file was modified from the untrusted file after the execution; and

g. repeating the steps of intercepting and updating at least three times, wherein updating at least three times expands the file attributes tree with six additional attributes for analysis.

2. The method of claim 1 , further comprising the step of decrypting data blocks in new or existing memory.

3. The method of claim 2 , further comprising the step of freezing the execution of the file following analysis of additional file data.

4. The method of claim 3 , further comprising the step of decrypting data blocks of the untrusted file in new or existing memory.

5. The method of claim 1 , further comprising making a given area executable and switching execution to the given area.

6. A non-transitory computer-readable storage medium with program code for training a machine-learning static analyzer based on iterative executable file analysis by way of the following steps comprising:

a. retrieving file attributes from an untrusted file;

b. creating an attributes tree of the file attributes of the untrusted file;

c. performing iteration of dynamic analysis of the untrusted the by:

intercepting an operation of decrypting at least one encrypted data block during an execution of the untrusted file's code; and

updating the tree of the file attributes for the untrusted file based on the at least one decrypted data block;

d. repeating step (c) until the file's code has been executed;

e. training the machine learning static analyzer based on the updated file attributes tree of the untrusted file and a classified files collection;

f. analyzing the untrusted file and a second untrusted file, wherein the second untrusted file was modified from the untrusted file after the execution; and

g. repeating the steps of intercepting and updating at least three times, wherein updating at least three times expands the file attributes tree with six additional attributes for analysis.

7. The non-transitory computer readable storage medium of claim 6 , further comprising decrypting data blocks of the untrusted file in new or existing memory.

8. The non-transitory computer-readable storage medium of claim 7 , further comprising the step of freezing the execution of the untrusted the following analysis of additional file data.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED BY DELETING PATENT APPLICATION NO. 18388907 FROM SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 66797 FRAME 766. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Nov 13, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 069594/0136 →
SECURITY INTEREST Recorded Mar 14, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 066797/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2023
From: STROGOV, VLADIMIR; MALANOV, ALEXEY; ULASEN, SERGEY; LEVCHENKO, VYACHESLAV; BELOUSSOV, SERGUEI; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 064616/0252 →