IP Library Granted Patent US 11,941,121
Granted Patent B2
US 11,941,121 · App. 17/563,738 · Granted Mar 26, 2024

Systems and methods for detecting malware using static and dynamic malware models

Inventors: Mantas Briliauskas (Vilnius, LT); Aleksandr {hacek over (S)}ev{hacek over (c)}enko (Vilnius, LT)
Assignee: UAB 360 IT
G06F21/566G06F18/2148G06F21/562G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,941,121
App. No.
17/563,738
Granted
Mar 26, 2024
Kind
B2
Abstract

In an embodiment, systems and methods for detecting malware are provided. A server trains a static malware model and a dynamic malware model to detect malware in files. The models are distributed to a plurality of user devices for use by antimalware software executing on the user devices. When a user device receives a file, the static malware model is used to determine whether the file contains malware. If the static malware model is unable to make the determination, when the file is later executed, the dynamic malware model is used to determine whether the file contains malware. The file along with the determination made by the dynamic malware model are then provided to the server. The server then retrains the static malware model using the received files and the received determinations. The server then distributes the updated static malware model to each of the devices.

Claims (54)

1. A method for detecting malware in files, the method comprising:

receiving a file by a computing device through a network;

determining a first probability that the file is malware using a first malware model, wherein the first malware model is a static malware model;

based on the determined first probability, determining a malware status of the file by the computing device, wherein the malware status is one of malware, not malware, or inconclusive;

when malware status of the file is inconclusive:

executing the file by the computing device;

determining a second probability that the file is malware based on the execution of the file using a second malware model by the computing device, wherein the second malware model is a dynamic malware model;

providing at least a portion of the file and the second probability to a server through the network by the computing device; and

receiving an updated version of the first model from the server by the computing device, wherein the updated version of the first model was trained using the file and the second probability.

2. The method of claim 1 , wherein providing the file and the second probability to the server through the network comprises:

extracting features from the file; and

providing the extracted features from the file and the second probability to the server through the network.

3. The method of claim 1 , wherein the first probability is determined in response to one or more of receiving the file and detecting that the user has selected the file.

4. The method of claim 1 , further comprising:

if the malware status of the file is malware, alerting a user.

5. The method of claim 1 , wherein executing the file by the computing device comprises receiving an indication to execute the file from the user and executing the file in response to the indication.

6. The method of claim 1 , wherein determining the malware status of the file comprises:

if the first probability is below a first threshold and below a second threshold, determining that the malware status is not malware;

if the first probability is above the first threshold and below the second threshold, determining that the malware status is inconclusive; and

if the probability is above the first threshold and above the second threshold, determining that the malware status is malware.

7. A system for detecting malware in files, the system comprising:

at least one computing device; and

a computer-readable medium storing computer-executable instructions that when executed by the at least one computing device cause the at least one computing device to:

receive a file;

determine a first probability that the file is malware using a first malware model, wherein the first malware model is a static malware model;

based on the determined first probability, determine a malware status of the file, wherein the malware status is one of malware, not malware, or inconclusive; and

when malware status of the file is inconclusive:

execute the file by the computing device;

determine a second probability that the file is malware based on the execution of the file using a second malware model, wherein the second malware model is a dynamic malware model;

provide at least a portion of the file and the second probability to a server through the network; and

receive an updated version of the first model from the server, wherein the updated version of the first model was trained using the file and the second probability.

8. The system of claim 7 , wherein providing the file and the second probability to the server through the network comprises:

extracting features from the file; and

providing the extracted features from the file and the second probability to the server through the network.

9. The system of claim 7 , wherein the first probability is determined in response to one or more of receiving the file and detecting that the user has selected the file.

10. The system of claim 7 , further comprising computer-executable instructions that when executed by the at least one computing device cause the at least one computing device to:

if the malware status of the file is malware, alert a user.

11. The system of claim 7 , wherein executing the file by the computing device comprises receiving an indication to execute the file from the user and executing the file in response to the indication.

12. The system of claim 7 , wherein determining the malware status of the file comprises:

if the first probability is below a first threshold and below a second threshold, determining that the malware status is not malware;

if the first probability is above the first threshold and below the second threshold, determining that the malware status is inconclusive; and

if the probability is above the first threshold and above the second threshold, determining that the malware status is malware.

13. A non-transitory computer-readable medium storing computer-executable instructions that when executed by at least one computing device cause the at least one computing device to:

receive a file;

determine a first probability that the file is malware using a first malware model, wherein the first malware model is a static malware model;

based on the determined first probability, determine a malware status of the file, wherein the malware status is one of malware, not malware, or inconclusive; and

when malware status of the file is inconclusive:

execute the file by the computing device;

determine a second probability that the file is malware based on the execution of the file using a second malware model, wherein the second malware model is a dynamic malware model;

provide at least a portion of the file and the second probability to a server through the network; and

receive an updated version of the first model from the server, wherein the updated version of the first model was trained using the file and the second probability.

14. The non-transitory computer-readable medium of claim 13 , wherein providing the file and the second probability to the server through the network comprises:

extracting features from the file; and

providing the extracted features from the file and the second probability to the server through the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2022
From: BRILIAUSKAS, MANTAS; SEVCENKO, ALEKSANDR
To: UAB 360 IT
Reel/Frame 059739/0110 →
Continuity (1)
Related Publication 20230205878A1 · Jun 29, 2023