IP Library Granted Patent US 11,818,166
Granted Patent B2
US 11,818,166 · App. 17/369,624 · Granted Nov 14, 2023

Malware infection prediction and prevention

Inventors: Sunil Mathew Thomas (Palm Harbor, FL); Tina LaVonne Barfield (Pinellas Park, FL); Adam Hyder (Cupertino, CA)
Assignee: Malwarebytes Inc.
H04L63/145G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,166
App. No.
17/369,624
Granted
Nov 14, 2023
Kind
B2
Abstract

A malware infection prediction method predicts a likelihood that a client device is to be infected with in a period of time based on state and behavior telemetry data. A malware infection prediction system receives telemetry data associated with use (i.e. behavior data) and configuration (i.e. state data) of a client device. By using a trained model, the system predicts a likelihood of the client device becoming infected within a given time frame. Based on the predicted likelihood, the system generates recommendations including recommended actions for reducing the likelihood of the client device becoming infected. The system then generates notifications including the recommendations and sends the notifications to the client device or to an administrative account associated with the client device.

Claims (42)

1. A method for preventing malware infection comprising:

receiving, at a server, telemetry data associated with use and configuration of a client device, wherein the telemetry data comprise:

user behavior data regarding interactions of one or more users of the client device; and

configuration data indicating a current configuration of the client device, the configuration data including at least one of: installed software, software configuration, hardware configuration, security configuration, and network configuration;

predicting a likelihood of the client device becoming infected within a given time frame by applying a trained model to the telemetry data;

generating, based on the likelihood of the client device becoming infected, one or more recommended actions for reducing the likelihood of the client device becoming infected;

generating one or more notifications including the recommendations; and

sending the notifications to the client device.

2. The method of claim 1 , wherein the model was trained using an aggregated telemetry dataset including telemetry data of a plurality of client devices.

3. The method of claim 1 , wherein the trained model predicts the likelihood of the client device becoming infected based on at least one of: a time of a day, a time of a month, or a time of a year.

4. The method of claim 1 , wherein the trained model further predicts one or more types of malware that are associated with the likelihood of the client device becoming infected.

5. The method of claim 1 , wherein the trained model is a machine learning model trained using supervised learning or unsupervised learning.

6. The method of claim 1 , wherein the user behavior data includes timestamps indicating times at which the user interactions with the client device occurred.

7. The method of claim 1 , wherein the recommended actions include at least one of: enabling a firewall, enabling a virtual private network (VPN), updating software, scanning a device that connects to the client device, changing security settings, or changing network settings.

8. A non-transitory computer readable storage medium storing instructions for preventing malware infection, the instructions when executed by one or more processors causing the one or more processors to perform steps comprising:

receiving, at a server, telemetry data associated with use and configuration of a client device, wherein the telemetry data comprise:

user behavior data regarding interactions of one or more users of the client device; and

configuration data indicating a current configuration of the client device, the configuration data including at least one of: installed software, software configuration, hardware configuration, security configuration, and network configuration;

predicting a likelihood of the client device becoming infected within a given time frame by applying a trained model to the telemetry data;

generating, based on the likelihood of the client device becoming infected, one or more recommended actions for reducing the likelihood of the client device becoming infected;

detecting an infection result indicating whether or not the client device became infected within the given time frame;

retraining the trained model based on the telemetry data and the infection result; and

storing the retrained model for future predictions.

9. The non-transitory computer readable storage medium of claim 8 , wherein the model is trained using an aggregated telemetry dataset including telemetry data of a plurality of client devices.

10. The non-transitory computer readable storage medium of claim 8 , wherein the trained model predicts the likelihood of the client device becoming infected based on at least one of: a time of a day, a time of a month, or a time of a year.

11. The non-transitory computer readable storage medium of claim 8 , wherein the trained model further predicts one or more types of malware that are associated with the likelihood of the client device becoming infected.

12. A non-transitory computer readable storage medium storing instructions for preventing malware infection, the instructions when executed by one or more processors causing the one or more processors to perform steps comprising:

receiving, at a server, telemetry data associated with use and configuration of a client device, wherein the telemetry data comprise:

user behavior data regarding interactions of one or more users of the client device; and

configuration data indicating a current configuration of the client device, the configuration data including at least one of: installed software, software configuration, hardware configuration, security configuration, and network configuration;

predicting a likelihood of the client device becoming infected within a given time frame by applying a trained model to the telemetry data;

generating, based on the likelihood of the client device becoming infected, one or more recommended actions for reducing the likelihood of the client device becoming infected;

generating one or more notifications including the recommendations; and

sending the notifications to the client device.

13. The non-transitory computer readable storage medium of claim 12 , wherein the model is trained using an aggregated telemetry dataset including telemetry data of a plurality of client devices.

14. The non-transitory computer readable storage medium of claim 12 , wherein the trained model predicts the likelihood of the client device becoming infected based on at least one of: a time of a day, a time of a month, or a time of a year.

15. The non-transitory computer readable storage medium of claim 12 , wherein the trained model further predicts one or more types of malware that are associated with the likelihood of the client device becoming infected.

16. The non-transitory computer readable storage medium of claim 12 , wherein the user behavior data includes timestamps indicating times at which the user interactions with the client device occurred.

17. The non-transitory computer readable storage medium of claim 12 , wherein the recommended actions include at least one of: enabling a firewall, enabling a virtual private network (VPN), updating software, scanning a device that connects to the client device, changing security settings, or changing network settings.

18. The non-transitory computer readable storage medium of claim 8 , wherein the trained model is a machine learning model trained using supervised learning or unsupervised learning.

19. The non-transitory computer readable storage medium of claim 8 , wherein the user behavior data includes timestamps indicating times at which the user interactions with the client device occurred.

20. The non-transitory computer readable storage medium of claim 8 , wherein the recommended actions include at least one of: enabling a firewall, enabling a virtual private network (VPN), updating software, scanning a device that connects to the client device, changing security settings, or changing network settings.

Assignments (7)
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES INC.
Reel/Frame 069193/0505 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 069193/0563 →
SECURITY INTEREST Recorded Oct 18, 2024
From: MALWAREBYTES INC.; MALWAREBYTES CORPORATE HOLDCO INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 068943/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: MALWAREBYTES INC.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 066900/0386 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 26, 2024
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066373/0912 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 1, 2023
From: MALWAREBYTES INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062599/0069 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: THOMAS, SUNIL MATHEW; BARFIELD, TINA LAVONNE; HYDER, ADAM
To: MALWAREBYTES INC.
Reel/Frame 057362/0319 →
Continuity (2)
Continuation 17160314 · Jan 27, 2021
Related Publication 20220239670A1 · Jul 28, 2022