IP Library Granted Patent US 11,941,122
Granted Patent B2
US 11,941,122 · App. 17/564,786 · Granted Mar 26, 2024

Systems and methods for detecting malware using static and dynamic malware models

Inventors: Mantas Briliauskas (Vilnius, LT); Aleksandr {hacek over (S)}ev{hacek over (c)}enko (Vilnius, LT)
Assignee: UAB 360 IT
G06F21/566G06F18/2148G06F21/562G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,941,122
App. No.
17/564,786
Granted
Mar 26, 2024
Kind
B2
Abstract

In an embodiment, systems and methods for detecting malware are provided. A server trains a static malware model and a dynamic malware model to detect malware in files. The models are distributed to a plurality of user devices for use by antimalware software executing on the user devices. When a user device receives a file, the static malware model is used to determine whether the file contains malware. If the static malware model is unable to make the determination, when the file is later executed, the dynamic malware model is used to determine whether the file contains malware. The file along with the determination made by the dynamic malware model are then provided to the server. The server then retrains the static malware model using the received files and the received determinations. The server then distributes the updated static malware model to each of the devices.

Claims (53)

1. A method for detecting malware in files, the method comprising:

determining a first probability that a file stored on a computing device is malware using a first malware model by the computing device;

based on the determined first probability, determining a malware status of the file by the computing device, wherein the malware status is one of malware, not malware, or inconclusive by;

if the first probability is below a first threshold and below a second threshold, determining that the malware status is not malware;

if the first probability is above the first threshold and below the second threshold, determining that the malware status is inconclusive; and

if the probability is above the first threshold and above the second threshold, determining that the malware status is malware;

when the malware status of the file is inconclusive:

determining a second probability that the file is malware using a second malware model by the computing device;

providing at least a portion of the file and the second probability to the server through the network as training data for the first malware model; and

receiving an updated version of the first malware model from the server.

2. The method of claim 1 , wherein the first model is a static malware model and the second model is a dynamic malware model.

3. The method of claim 1 , wherein providing at least a portion of the file and the second probability to the server through the network as training data for the first malware model comprises:

extracting features from the file; and

providing the extracted features from the file and the second probability to the server through the network as training data for the first malware model.

4. The method of claim 1 , wherein the updated version of the first model was trained using the at least a portion of the file and the second probability.

5. The method of claim 1 , further comprising:

when the malware status of the file is malware, alerting a user.

6. The method of claim 1 , further comprising receiving the second malware model from the server by the computing device through the network.

7. A system for detecting malware in files, the system comprising:

at least one computing device; and

a computer-readable medium storing computer-executable instructions that when executed by the at least one computing device cause the at least one computing device to:

determine a first probability that a file stored on the at least one computing device is malware using a first malware model;

based on the determined first probability, determine a malware status of the file, wherein the malware status is one of malware, not malware, or inconclusive by:

if the first probability is below a first threshold and below a second threshold, determining that the malware status is not malware;

if the first probability is above the first threshold and below the second threshold, determining that the malware status is inconclusive; and

if the probability is above the first threshold and above the second threshold, determining that the malware status is malware;

when the malware status of the file is inconclusive:

determine a second probability that the file is malware using a second malware model;

provide at least a portion of the file and the second probability to the server through the network as training data for the first malware model; and

receive an updated version of the first malware model from the server.

8. The system of claim 7 , wherein the first model is a static malware model and the second model is a dynamic malware model.

9. The system of claim 7 , wherein providing at least a portion of the file and the second probability to the server through the network as training data for the first malware model comprises:

extracting features from the file; and

providing the extracted features from the file and the second probability to the server through the network as training data for the first malware model.

10. The system of claim 9 , wherein the updated version of the first model was trained using the at least a portion of the file and the second probability.

11. The system of claim 7 , further comprising computer-executable instructions that when executed by the at least one computing device cause the at least one computing device to: when the malware status of the file is malware, alert a user.

12. The system of claim 7 , further comprising computer-executable instructions that when executed by the at least one computing device cause the at least one computing device to receive the second malware model from the server by the computing device through the network.

13. A non-transitory computer-readable medium storing computer-executable instructions that when executed by at least one computing device cause the at least one computing device to:

determine a first probability that a file stored on the at least one computing device is malware using a first malware model;

based on the determined first probability, determine a malware status of the file, wherein the malware status is one of malware, not malware, or inconclusive by:

if the first probability is below a first threshold and below a second threshold, determining that the malware status is not malware;

if the first probability is above the first threshold and below the second threshold, determining that the malware status is inconclusive; and

if the probability is above the first threshold and above the second threshold, determining that the malware status is malware;

when the malware status of the file is inconclusive:

determine a second probability that the file is malware using a second malware model;

provide at least a portion of the file and the second probability to the server through the network as training data for the first malware model; and

receive an updated version of the first malware model from the server.

14. The non-transitory computer-readable medium of claim 13 , wherein the first model is a static malware model and the second model is a dynamic malware model.

15. The non-transitory computer-readable medium of claim 13 , wherein providing at least a portion of the file and the second probability to the server through the network as training data for the first malware model comprises:

extract features from the file; and

provide the extracted features from the file and the second probability to the server through the network as training data for the first malware model.

16. The non-transitory computer-readable medium of claim 15 , wherein the updated version of the first model was trained using the at least a portion of the file and the second probability.

17. The non-transitory computer-readable medium of claim 13 , further comprising computer-executable instructions that when executed by the at least one computing device cause the at least one computing device to: when the malware status of the file is malware, alert a user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2022
From: SEVCENKO, ALEKSANDR; BRILIAUSKAS, MANTAS
To: UAB 360 IT
Reel/Frame 061253/0357 →
Continuity (2)
Continuation 17563738 · Dec 28, 2021
Related Publication 20230205881A1 · Jun 29, 2023