IP Library Granted Patent US 11,941,123
Granted Patent B2
US 11,941,123 · App. 17/564,795 · Granted Mar 26, 2024

Systems and methods for detecting malware using static and dynamic malware models

Inventors: Mantas Briliauskas (Vilnius, LT); Aleksandr {hacek over (S)}ev{hacek over (c)}enko (Vilnius, LT)
Assignee: UAB 360 IT
G06F21/566G06F18/2148G06F21/562G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,941,123
App. No.
17/564,795
Granted
Mar 26, 2024
Kind
B2
Abstract

In an embodiment, systems and methods for detecting malware are provided. A server trains a static malware model and a dynamic malware model to detect malware in files. The models are distributed to a plurality of user devices for use by antimalware software executing on the user devices. When a user device receives a file, the static malware model is used to determine whether the file contains malware. If the static malware model is unable to make the determination, when the file is later executed, the dynamic malware model is used to determine whether the file contains malware. The file along with the determination made by the dynamic malware model are then provided to the server. The server then retrains the static malware model using the received files and the received determinations. The server then distributes the updated static malware model to each of the devices.

Claims (47)

1. A method for detecting malware in files, the method comprising:

receiving a first set of labeled training data by a server, wherein the first set of training data comprises a plurality of files and each file of the plurality of files is labeled as either malware or not malware;

training a first malware model using at least some of the first set of training data by the server, wherein the first malware model is a static malware model;

training a second malware model using at least some of the first set oft raining data by the server, wherein the second malware model is a dynamic malware model;

providing the first malware model and the second malware model to each computing device of a plurality of computing devices through a network;

receiving at least a portion of a first file and a probability that the first file is malware from a first computing device of the plurality of computing devices by the server through the network, wherein the first file is not part of the plurality of files and the probability was generated using the second malware model;

retraining the first malware model using the at least a portion of a first file and a probability that the first file is malware by the server; and

providing the retrained first malware model to the first computing device.

2. The method of claim 1 , wherein one or more of the plurality of files are executable files.

3. The method of claim 1 , further comprising:

receiving second training data from each computing device of the plurality of computing devices.

4. The method of claim 3 , further comprising retraining the first malware model using the second training data.

5. The method of claim 4 , further comprising providing the retrained first malware model to each computing device of the plurality of computing devices through the network.

6. The method of claim 1 , further comprising:

extracting static features from the files of the plurality of files of the first set of training data; and

training the first malware model using the extracted static features.

7. A system for detecting malware in files, the system comprising:

a server; and

a computer-readable medium storing computer-executable instructions that when executed by the server cause the server to:

receive a first set of labeled training data, wherein the first set of training data comprises a plurality of files and each file of the plurality of files is labeled as either malware or not malware;

train a first malware model using at least some of the first set of training data, wherein the first malware model is a static malware model;

train a second malware model using at least some of the first set of training data, wherein the second malware model is a dynamic malware model;

provide the first malware model and the second malware model to each computing device of a plurality of computing devices through a network;

receive at least a portion of a first file and a probability that the first file is malware from a first computing device of the plurality of computing devices through the network, wherein the first file is not part of the plurality of files and the probability was generated using the second malware model;

retrain the first malware model using the at least a portion of a first file and a probability that the first file is malware; and

provide the retrained first malware model to the first computing device.

8. The system of claim 7 , wherein one or more of the plurality of files are executable files.

9. The system of claim 7 , further comprising computer-executable instructions that when executed by the server cause the server to:

receive second training data from each computing device of the plurality of computing devices.

10. The system of claim 9 , further comprising computer-executable instructions that when executed by the server cause the server to retrain the first malware model using the second training data.

11. The system of claim 10 , further comprising computer-executable instructions that when executed by the server cause the server to provide the retrained first malware model to each computing device of the plurality of computing devices through the network.

12. The system of claim 7 , further comprising computer-executable instructions that when executed by the server cause the server to:

extract static features from the files of the plurality of files of the first set of training data; and

train the first malware model using the extracted static features.

13. A non-transitory computer-readable medium storing computer-executable instructions that when executed by a server cause the server to:

receive a first set of labeled training data, wherein the first set of training data comprises a plurality of files and each file of the plurality of files is labeled as either malware or not malware;

train a first malware model using at least some of the first set of training data, wherein the first malware model is a static malware model;

train a second malware model using at least some of the first set of training data, wherein the second malware model is a dynamic malware model;

provide the first malware model and the second malware model to each computing device of a plurality of computing devices through a network;

receive at least a portion of a first file and a probability that the first file is malware from a first computing device of the plurality of computing devices through the network, wherein the first file is not part of the plurality of files and the probability was generated using the second malware model;

retrain the first malware model using the at least a portion of a first file and a probability that the first file is malware; and

provide the retrained first malware model to the first computing device.

14. The non-transitory computer-readable medium of claim 13 , wherein one or more of the plurality of files are executable files.

15. The non-transitory computer-readable medium of claim 13 , further comprising computer-executable instructions that when executed by the server cause the server to:

receive second training data from each computing device of the plurality of computing devices, wherein the second training data received from a computing device comprises a set of static features extracted from a file by the computing device and a label that was generated for the file by the computing device using the second malware model.

16. The non-transitory computer-readable medium of claim 15 , further comprising computer-executable instructions that when executed by the server cause the server to retrain the first malware model using the second training data.

17. The non-transitory computer-readable medium of claim 16 , further comprising computer-executable instructions that when executed by the server cause the server to provide the retrained first malware model to each computing device of the plurality of computing devices through the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2022
From: SEVCENKO, ALEKSANDR; BRILIAUSKAS, MANTAS
To: UAB 360 IT
Reel/Frame 061253/0357 →
Continuity (2)
Continuation 17563738 · Dec 28, 2021
Related Publication 20230205844A1 · Jun 29, 2023