IP Library Granted Patent US 12,229,259
Granted Patent B2
US 12,229,259 · App. 17/586,010 · Granted Feb 18, 2025

Method and system for detecting malicious files in a non-isolated environment

Inventor: Nikolay Sergeevich Prudkovskij (Moscow, RU)
Assignee: F.A.C.C.T. NETWORK SECURITY LLC
G06F21/562G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,259
App. No.
17/586,010
Granted
Feb 18, 2025
Kind
B2
Abstract

A method and a system for detecting malicious files in non-isolated environment are provided. The method comprises, during a training phase: acquiring a plurality of executable files, analyzing a given executable file to obtain: (i) data associated with the given executable file; (ii) a control-flow graph associated with the given executable file, and (iii) a data-flow graph associated with the given executable file; determining, based on the data, parameters of the given executable file; generating, by the processor, based on the parameters, at least a first feature vector and a second feature vector; generating, by the processor, based on the control-flow graph, a third feature vector; generating, by the processor, based on the data-flow graph, a fourth feature vector; and training the each one of ensemble of classifiers based on a respective feature vector to determine if a given in-use executable file is one of malicious and non-malicious.

Claims (86)

1. A computer-implementable method for detecting malicious files in non-isolated environment, the method comprising:

during a training phase:

acquiring plurality of executable files including at least one malicious executable file and at least one non-malicious executable file;

analyzing a binary form of the given executable file to obtain a first data associated with the given executable file,

the first data comprising a Byte/Entropy Histogram associated with the given executable file;

the analyzing comprising analyzing at least one selected from the group consisting of: byte n-grams, data of fields of the given executable file, a file section entropy, metadata of the binary form of the given executable file, and line length distribution histograms;

analyzing a disassembled form of the given executable file to obtain: (i) a second data associated with the given executable file; (ii) a control-flow graph associated with the given executable file, and (iii) a data-flow graph associated with the given executable file,

the second data being different from the first data;

determining based on data including the first and second data, parameters of the given executable file;

determining the parameters of the given executable file as being indicative of one of a malicious executable file and a non-malicious executable file;

generating, based on the parameters, at least a first feature vector and a second feature vector;

generating, based on the control-flow graph, a third feature vector;

generating, based on the data-flow graph, a fourth feature vector,

each one of the first feature vector, the second feature vector, the third feature vector, and the fourth feature vector being different from an other one thereof; and

training an ensemble of classifiers to determine if a given in-use executable file is one of malicious and non-malicious, the training comprising:

training a first classifier of the ensemble of classifiers based on the first feature vector;

training a second classifiers of the ensemble of classifiers based on the second feature vector;

training a third classifiers of the ensemble of classifiers based on the third feature vector; and

training a fourth classifiers of the ensemble of classifiers based on the fourth feature vector;

assigning to each one of the ensemble of classifiers, a respective decisive priority value,

the respective decisive priority value being indicative of a respective weight assigned to a prediction outcome of a given classifier of the ensemble of classifiers, the respective weight having been determined based on prediction accuracy of the given classifier.

2. The method of claim 1 , further comprising, during an in-use phase following the training phase:

obtaining the given in-use executable file;

generating a first in-use feature vector, a second in-use feature vector, a third in-use feature vector, and a fourth in-use feature vector associated with the given in-use executable file;

feeding the first in-use feature vector, the second in-use feature vector, the third in-use feature vector, and the fourth in-use feature vector to the ensemble of classifiers to determine a prediction outcome indicative of whether the given in-use executable file is one of malicious and non-malicious; and

generating a report including the prediction outcome for presentation thereof to a user.

3. The method of claim 1 , wherein the first feature vector comprises numerical ones of the parameters of the given executable file, and the second vector comprises string ones of the parameters of the given executable file.

4. The method of claim 1 , wherein obtaining the second data associated with the given executable file comprises obtaining at least one of: metadata, an Import Table, and an Export Table associated with the given executable file.

5. The method of claim 1 , wherein the data of the fields of the given executable file comprises at least one of: a number of sections in the given executable file, a size of headers, a code size, an availability of digital signature, an availability of imported DLL and functions where these libraries have been used, names of exported functions, data from a resource catalog, and an assembler version of the given executable file.

6. The method of claim 1 , wherein the file section entropy has been determined using a sliding window applied to the binary form of the given executable file.

7. The method of claim 4 , wherein the metadata of the binary form of the given executable file comprises a number of sections in the file, sizes thereof, a presence of a checksum, a file size, a creation time, an operating system version, and an assembler version associated with the given executable file.

8. The method of claim 1 , wherein analyzing the disassembled form of the given executable file comprises analyzing at least one of: characters, registers, operation codes, a system interface (Windows APIs) access rate, sections, and metadata, associated with the given executable file.

9. The method of claim 8 , wherein the analyzing further comprises determining, in a code of the disassembled form of the given executable file, a frequency of occurrence of characters, including at least one of: “−”, “+”, “*”, “]”, “[”, “?”, “@”.

10. The method of claim 7 , wherein the analyzing further comprises determining a ratio between a number of known registers and a number of unknown registers obtained from the disassembled form of the given executable file.

11. The method of claim 8 , wherein the sections obtained from the disassembled form of the given executable file include at least one of: .text, .data, .bss, .rdata, .edata, .idata, .rsrc, .tls, and .reloc.

12. The method of claim 7 , wherein the metadata extracted from the disassembled form of the given executable file comprises the file size and a number of code lines.

13. The method of claim 2 , wherein the prediction outcome includes one of a binary prediction outcome and a probabilistic prediction outcome.

14. The method of claim 1 , wherein the respective decisive priority of a given classifier in the ensemble of classifiers is determined based on one of: an accuracy associated with the given classifier, a completeness associated with the given classifier, and an F-measure associated with the given classifier.

15. A system for detecting malicious files in non-isolated environment, the system comprising at least one processor and at least one non-transitory computer-readable medium storing instructions, which, when executed by the at least one processor, cause the system to:

during a training phase:

acquire a plurality of executable files including at least one malicious executable file and at least one non-malicious executable file;

analyze a binary form of the given executable file to obtain a first data associated with the given executable file, the first data comprising a Byte/Entropy Histogram associated with the given executable file, by:

analyzing at least one selected from the group consisting of: byte n-grams, data of fields of the given executable file, a file section entropy, metadata of the binary form of the given executable file, and line length distribution histograms;

analyze a disassembled form of the given executable file, to obtain: (i) a second data associated with the given executable file; (ii) a control-flow graph associated with the given executable file, and (iii) a data-flow graph associated with the given executable file,

the second data being different from the first data;

determine, based on the data including the first and second data, parameters of the given executable file;

determine the parameters of the given executable file as being indicative of one of a malicious executable file and a non-malicious executable file;

generate, based on the parameters, at least a first feature vector and a second feature vector;

generate, based on the control-flow graph, a third feature vector;

generate, based on the data-flow graph, a fourth feature vector,

each one of the first feature vector, the second feature vector, the third feature vector, and the fourth feature vector being different from an other one thereof; and

train an ensemble of classifiers to determine if a given in-use executable file is one of malicious and non-malicious, by:

training a first classifier of the ensemble of classifiers based on the first feature vector;

training a second classifiers of the ensemble of classifiers based on the second feature vector;

training a third classifiers of the ensemble of classifiers based on the third feature vector; and

training a fourth classifiers of the ensemble of classifiers based on the fourth feature vector;

assign, to each one of the ensemble of classifiers, a respective decisive priority value,

the respective decisive priority value being indicative of a respective weight assigned to a prediction outcome of a given classifier of the ensemble of classifiers, the respective weight having been determined based on prediction accuracy of the given classifier.

16. The system of claim 15 , wherein, during an in-use phase following the training phase, the processor is further configured to:

obtain the given in-use executable file;

generate a first in-use feature vector, a second in-use feature vector, a third in-use feature vector, and a fourth in-use feature vector associated with the given in-use executable file;

feed the first in-use feature vector, the second in-use feature vector, the third in-use feature vector, and the fourth in-use feature vector to the ensemble of classifiers to determine a prediction outcome indicative of whether the given in-use executable file is one of malicious and non-malicious; and

generate a report including the prediction outcome for presentation thereof to a user.

17. A computer-implementable method for detecting malicious files in non-isolated environment, the method comprising:

during a training phase:

acquiring a training set of data including a plurality of executable files, the plurality of executable files including at least one malicious executable file and at least one non-malicious executable file; and

training, based on the training set of data, an ensemble of classifiers to determine if a given in-use executable file is one of malicious and non-malicious, the training comprising:

training a first classifier of the ensemble of classifiers based on a first plurality of feature vectors,

a given one of the first plurality of feature vectors having been determined based on parameters associated with a respective one of the plurality of executable files;

training a second classifiers of the ensemble of classifiers based on a second plurality of feature vectors,

a given one of the second plurality of feature vectors having been determined based on the parameters associated with the respective one of the plurality of executable files,

the parameters having been determined based on first and second data obtained, for a given executable file of the plurality of executable files, respectively, based on analyzing (i) a binary form and (ii) a disassembled form of the given executable file,

 the first data comprising a Byte/Entropy Histogram associated with the given executable file;

 analyzing the binary form comprising analyzing at least one selected from the group consisting of: byte n-grams, data of fields of the given executable file, a file section entropy, metadata of the binary form of the given executable file, and line length distribution histograms; and

 the second data being different from the first data;

training a third classifiers of the ensemble of classifiers based on a third plurality of feature vectors,

a given one of the third plurality of feature vectors having been determined based on a control-flow graph of the respective one of the plurality of executable files; and

training a fourth classifiers of the ensemble of classifiers based on a fourth plurality of feature vectors,

a given one of the fourth plurality of feature vectors having been determined based on a data-flow graph of the respective one of the plurality of executable files,

 each one of the given one of the first plurality of feature vectors, the given one of the second plurality of feature vectors, the given one of the third plurality of feature vectors, and the given one of the fourth plurality of feature vectors being different from an other one thereof; and

assigning, to each one of the ensemble of classifiers, a respective decisive priority value.

18. The method of claim 17 , further comprising, during an in-use phase following the training phase:

obtaining, by the processor, the given in-use executable file;

generating, by the processor, a first in-use feature vector, a second in-use feature vector, a third in-use feature vector, and a fourth in-use feature vector associated with the given in-use executable file;

feeding the first in-use feature vector, the second in-use feature vector, the third in-use feature vector, and the fourth in-use feature vector to the ensemble of classifiers to determine a prediction outcome indicative of whether the given in-use executable file is one of malicious and non-malicious; and

generating a report including the prediction outcome for presentation thereof to a user.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2025
From: F.A.C.C.T. NETWORK SECURITY LLC
To: GROUP-IB GLOBAL PRIVATE LIMITED
Reel/Frame 071439/0078 →
CHANGE OF NAME Recorded Feb 7, 2024
From: GROUP IB TDS, LTD
To: F.A.C.C.T. NETWORK SECURITY LLC
Reel/Frame 066522/0741 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2022
From: PRUDKOVSKIJ, NIKOLAY SERGEEVICH
To: GROUP IB TDS, LTD
Reel/Frame 058814/0298 →
Priority Claims (1)
RU 2020107922 · Feb 21, 2020 · national
Continuity (2)
Continuation PCTRU2020000089 · Feb 25, 2020
Related Publication 20220164444A1 · May 26, 2022
References Cited (345)
US 6928434B1 · Choi et al. · 2005 [cited by applicant]
US 7225343B1 · Honig et al. · 2007 [cited by applicant]
US 7383581B1 · Moore et al. · 2008 [cited by applicant]
US 7496628B2 · Arnold et al. · 2009 [cited by applicant]
US 7712136B2 · Sprosts et al. · 2010 [cited by applicant]
US 7730040B2 · Reasor et al. · 2010 [cited by applicant]
US 7865953B1 · Hsieh et al. · 2011 [cited by applicant]
US 7958555B1 · Chen et al. · 2011 [cited by applicant]
US 7984500B1 · Khanna et al. · 2011 [cited by applicant]
US 8132250B2 · Judge et al. · 2012 [cited by applicant]
US 8151341B1 · Gudov · 2012 [cited by applicant]
US 8255532B2 · Smith-Mickelson et al. · 2012 [cited by applicant]
US 8260914B1 · Ranjan · 2012 [cited by applicant]
US 8285830B1 · Stout et al. · 2012 [cited by applicant]
US 8402543B1 · Ranjan et al. · 2013 [cited by applicant]
US 8448245B2 · Banerjee et al. · 2013 [cited by applicant]
US 8532382B1 · Ioffe · 2013 [cited by applicant]
US 8539582B1 · Aziz et al. · 2013 [cited by applicant]
US 8555388B1 · Wang et al. · 2013 [cited by applicant]
US 8561177B1 · Aziz et al. · 2013 [cited by applicant]
US 8600993B1 · Gupta et al. · 2013 [cited by applicant]
US 8612463B2 · Brdiczka et al. · 2013 [cited by applicant]
US 8625033B1 · Marwood et al. · 2014 [cited by applicant]
US 8635696B1 · Aziz · 2014 [cited by applicant]
US 8650080B2 · O'Connell et al. · 2014 [cited by applicant]
US 8660296B1 · Ioffe · 2014 [cited by applicant]
US 8677472B1 · Dotan et al. · 2014 [cited by applicant]
US 8683595B1 · Barker · 2014 [cited by applicant]
US 8776229B1 · Aziz · 2014 [cited by applicant]
US 8850571B2 · Staniford et al. · 2014 [cited by applicant]
US 8856937B1 · Wüest et al. · 2014 [cited by applicant]
US 8972412B1 · Christian et al. · 2015 [cited by applicant]
US 8984640B1 · Emigh et al. · 2015 [cited by applicant]
US 9026840B1 · Kim · 2015 [cited by applicant]
US 9060018B1 · Yu et al. · 2015 [cited by applicant]
US 9165142B1 · Sanders et al. · 2015 [cited by applicant]
US 9210111B2 · Chasin et al. · 2015 [cited by applicant]
US 9215239B1 · Wang et al. · 2015 [cited by applicant]
US 9223972B1 · Vincent et al. · 2015 [cited by applicant]
US 9253208B1 · Koshelev · 2016 [cited by applicant]
US 9330258B1 · Satish et al. · 2016 [cited by applicant]
US 9338181B1 · Burns et al. · 2016 [cited by applicant]
US 9357469B2 · Smith et al. · 2016 [cited by applicant]
US 9456000B1 · Spiro et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9654593B2 · Garg et al. · 2017 [cited by applicant]
US 9705904B1 · Davis · 2017 [cited by examiner]
US 9723344B1 · Granström et al. · 2017 [cited by applicant]
US 9736178B1 · Ashley · 2017 [cited by applicant]
US 9747446B1 · Pidathala et al. · 2017 [cited by applicant]
US 9917852B1 · Xu et al. · 2018 [cited by applicant]
US 9934376B1 · Ismael · 2018 [cited by applicant]
US 10148685B2 · Hassanzadeh et al. · 2018 [cited by applicant]
US 10284574B1 · Aziz et al. · 2019 [cited by applicant]
US 10467411B1 · Pidathala et al. · 2019 [cited by applicant]
US 10514909B2 · Yahav · 2019 [cited by examiner]
US 10546143B1 · Wesson · 2020 [cited by applicant]
US 10783247B1 · Steinfadt et al. · 2020 [cited by applicant]
US 10990674B2 · Srinivasagopalan et al. · 2021 [cited by applicant]
US 11023580B1 · Han · 2021 [cited by examiner]
US 11270000B1 · Chiang et al. · 2022 [cited by applicant]
US 11663405B2 · Wilson et al. · 2023 [cited by applicant]
US 20020161862A1 · Horvitz · 2002 [cited by applicant]
US 20030009696A1 · Bunker et al. · 2003 [cited by applicant]
US 20060021029A1 · Brickell et al. · 2006 [cited by applicant]
US 20060037080A1 · Maloof · 2006 [cited by applicant]
US 20060074858A1 · Etzold et al. · 2006 [cited by applicant]
US 20060107321A1 · Tzadikario · 2006 [cited by applicant]
US 20060224898A1 · Ahmed · 2006 [cited by applicant]
US 20060253582A1 · Dixon et al. · 2006 [cited by applicant]
US 20070019543A1 · Wei et al. · 2007 [cited by applicant]
US 20070239999A1 · Honig et al. · 2007 [cited by applicant]
US 20070240220A1 · Tuvell · 2007 [cited by examiner]
US 20080172651A1 · Davia · 2008 [cited by applicant]
US 20090138342A1 · Otto et al. · 2009 [cited by applicant]
US 20090281852A1 · Abhari et al. · 2009 [cited by applicant]
US 20090292925A1 · Meisel · 2009 [cited by applicant]
US 20100011124A1 · Wei et al. · 2010 [cited by applicant]
US 20100037314A1 · Perdisci et al. · 2010 [cited by applicant]
US 20100076857A1 · Deo et al. · 2010 [cited by applicant]
US 20100115620A1 · Alme · 2010 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20100191737A1 · Friedman et al. · 2010 [cited by applicant]
US 20100205665A1 · Komili et al. · 2010 [cited by applicant]
US 20100235918A1 · Mizrahi et al. · 2010 [cited by applicant]
US 20110222787A1 · Thiemert et al. · 2011 [cited by applicant]
US 20120030293A1 · Bobotek · 2012 [cited by applicant]
US 20120079596A1 · Thomas et al. · 2012 [cited by applicant]
US 20120087583A1 · Yang et al. · 2012 [cited by applicant]
US 20120158626A1 · Zhu et al. · 2012 [cited by applicant]
US 20120233656A1 · Rieschick et al. · 2012 [cited by applicant]
US 20120291125A1 · Maria · 2012 [cited by applicant]
US 20130086677A1 · Ma et al. · 2013 [cited by applicant]
US 20130103666A1 · Sandberg et al. · 2013 [cited by applicant]
US 20130111591A1 · Topan et al. · 2013 [cited by applicant]
US 20130117848A1 · Golshan et al. · 2013 [cited by applicant]
US 20130191364A1 · Kamel et al. · 2013 [cited by applicant]
US 20130227691A1 · Aziz et al. · 2013 [cited by applicant]
US 20130263264A1 · Klein et al. · 2013 [cited by applicant]
US 20130297619A1 · Chandrasekaran et al. · 2013 [cited by applicant]
US 20130340080A1 · Gostev et al. · 2013 [cited by applicant]
US 20140033307A1 · Schmidtler · 2014 [cited by applicant]
US 20140058854A1 · Ranganath et al. · 2014 [cited by applicant]
US 20140082730A1 · Vashist et al. · 2014 [cited by applicant]
US 20140173287A1 · Mizunuma · 2014 [cited by applicant]
US 20140310811A1 · Hentunen · 2014 [cited by applicant]
US 20150007250A1 · Dicato, Jr. et al. · 2015 [cited by applicant]
US 20150049547A1 · Kim · 2015 [cited by applicant]
US 20150067839A1 · Wardman et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150170312A1 · Mehta et al. · 2015 [cited by applicant]
US 20150178306A1 · Yang et al. · 2015 [cited by applicant]
US 20150200963A1 · Geng et al. · 2015 [cited by applicant]
US 20150220735A1 · Paithane et al. · 2015 [cited by applicant]
US 20150227364A1 · Asadullah et al. · 2015 [cited by applicant]
US 20150295945A1 · Canzanese et al. · 2015 [cited by applicant]
US 20150310010A1 · Brenner et al. · 2015 [cited by applicant]
US 20150356291A1 · Zakorzhevsky et al. · 2015 [cited by applicant]
US 20150363791A1 · Raz et al. · 2015 [cited by applicant]
US 20150381654A1 · Wang et al. · 2015 [cited by applicant]
US 20160036837A1 · Jain et al. · 2016 [cited by applicant]
US 20160036838A1 · Jain et al. · 2016 [cited by applicant]
US 20160044054A1 · Stiansen et al. · 2016 [cited by applicant]
US 20160055490A1 · Keren et al. · 2016 [cited by applicant]
US 20160057159A1 · Yin et al. · 2016 [cited by applicant]
US 20160065595A1 · Kim et al. · 2016 [cited by applicant]
US 20160112445A1 · Abramowitz · 2016 [cited by applicant]
US 20160127388A1 · Cabot et al. · 2016 [cited by applicant]
US 20160127907A1 · Baxley et al. · 2016 [cited by applicant]
US 20160132521A1 · Reininger et al. · 2016 [cited by applicant]
US 20160149943A1 · Kaloroumakis et al. · 2016 [cited by applicant]
US 20160191243A1 · Manning · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by applicant]
US 20160205123A1 · Almurayh et al. · 2016 [cited by applicant]
US 20160226894A1 · Lee et al. · 2016 [cited by applicant]
US 20160253679A1 · Venkatraman et al. · 2016 [cited by applicant]
US 20160261628A1 · Doron et al. · 2016 [cited by applicant]
US 20160267179A1 · Mei et al. · 2016 [cited by applicant]
US 20160285907A1 · Nguyen et al. · 2016 [cited by applicant]
US 20160306974A1 · Turgeman et al. · 2016 [cited by applicant]
US 20160359679A1 · Parandehgheibi et al. · 2016 [cited by applicant]
US 20170006045A1 · Kivva et al. · 2017 [cited by applicant]
US 20170034211A1 · Buergi et al. · 2017 [cited by applicant]
US 20170068816A1 · Cavazos · 2017 [cited by examiner]
US 20170111374A1 · Harris · 2017 [cited by examiner]
US 20170111377A1 · Park et al. · 2017 [cited by applicant]
US 20170134401A1 · Medvedovsky et al. · 2017 [cited by applicant]
US 20170142144A1 · Weinberger et al. · 2017 [cited by applicant]
US 20170149813A1 · Wright et al. · 2017 [cited by applicant]
US 20170171230A1 · Leiderfarb et al. · 2017 [cited by applicant]
US 20170200457A1 · Chai et al. · 2017 [cited by applicant]
US 20170230401A1 · Ahmed et al. · 2017 [cited by applicant]
US 20170244735A1 · Visbal et al. · 2017 [cited by applicant]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20170251003A1 · Rostami-Hesarsorkh et al. · 2017 [cited by applicant]
US 20170262633A1 · Miserendino et al. · 2017 [cited by applicant]
US 20170272471A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170279818A1 · Milazzo et al. · 2017 [cited by applicant]
US 20170286544A1 · Hunt et al. · 2017 [cited by applicant]
US 20170289187A1 · Noel et al. · 2017 [cited by applicant]
US 20170295157A1 · Chavez et al. · 2017 [cited by applicant]
US 20170295187A1 · Havelka et al. · 2017 [cited by applicant]
US 20170324738A1 · Hari et al. · 2017 [cited by applicant]
US 20170346839A1 · Peppe et al. · 2017 [cited by applicant]
US 20180012021A1 · Volkov · 2018 [cited by applicant]
US 20180012144A1 · Ding et al. · 2018 [cited by applicant]
US 20180025157A1 · Titonis · 2018 [cited by examiner]
US 20180034779A1 · Ahuja et al. · 2018 [cited by applicant]
US 20180063190A1 · Wright et al. · 2018 [cited by applicant]
US 20180096153A1 · Dewitte et al. · 2018 [cited by applicant]
US 20180115573A1 · Kuo et al. · 2018 [cited by applicant]
US 20180165452A1 · Sun et al. · 2018 [cited by applicant]
US 20180268464A1 · Li · 2018 [cited by applicant]
US 20180307832A1 · Ijiro et al. · 2018 [cited by applicant]
US 20180309787A1 · Evron et al. · 2018 [cited by applicant]
US 20180365420A1 · Krylov et al. · 2018 [cited by applicant]
US 20190005239A1 · Park et al. · 2019 [cited by applicant]
US 20190089737A1 · Shayevitz et al. · 2019 [cited by applicant]
US 20190114423A1 · Chistyakov et al. · 2019 [cited by applicant]
US 20190158525A1 · Rostami-Hesarsorkh et al. · 2019 [cited by applicant]
US 20190207973A1 · Peng · 2019 [cited by applicant]
US 20190230098A1 · Navarro · 2019 [cited by applicant]
US 20190294720A1 · Beringer et al. · 2019 [cited by applicant]
US 20190373005A1 · Bassett · 2019 [cited by applicant]
US 20200092306A1 · Jusko et al. · 2020 [cited by applicant]
US 20200134702A1 · Li · 2020 [cited by applicant]
US 20200162483A1 · Farhady · 2020 [cited by examiner]
US 20200302058A1 · Kenyon et al. · 2020 [cited by applicant]
US 20200364334A1 · Pevny · 2020 [cited by examiner]
US 20210141897A1 · Seifert et al. · 2021 [cited by applicant]
US 20210390182A1 · Boutnaru · 2021 [cited by examiner]
US 20230252144A1 · Kim · 2023 [cited by examiner]
AU 2017203008B2 · 2019 [cited by applicant]
CA 2900312A1 · 2014 [cited by applicant]
CN 103491205A · 2014 [cited by applicant]
CN 104504307A · 2015 [cited by applicant]
CN 103020494B · 2015 [cited by applicant]
CN 105429956A · 2016 [cited by applicant]
CN 105897714A · 2016 [cited by applicant]
CN 106131016A · 2016 [cited by applicant]
CN 106506435A · 2017 [cited by applicant]
CN 106713312A · 2017 [cited by applicant]
CN 107392019A · 2017 [cited by applicant]
CN 107392456A · 2017 [cited by applicant]
EP 1160646A2 · 2001 [cited by applicant]
EP 2916256A1 · 2015 [cited by applicant]
EP 2410452B1 · 2016 [cited by applicant]
EP 2743854B1 · 2018 [cited by applicant]
EP 2946331B1 · 2019 [cited by applicant]
EP 3800570A1 · 2021 [cited by examiner]
GB 2425622A · 2006 [cited by applicant]
GB 2493514A · 2013 [cited by applicant]
KR 1020070049514A · 2007 [cited by applicant]
KR 20120090131A · 2012 [cited by applicant]
KR 101514984B1 · 2015 [cited by applicant]
RU 91213U1 · 2010 [cited by applicant]
RU 2382400C2 · 2010 [cited by applicant]
RU 107616U1 · 2011 [cited by applicant]
RU 2446459C1 · 2012 [cited by applicant]
RU 129279U1 · 2013 [cited by applicant]
RU 2487406C1 · 2013 [cited by applicant]
RU 2488880C1 · 2013 [cited by applicant]
RU 2495486C1 · 2013 [cited by applicant]
RU 2522019C1 · 2014 [cited by applicant]
RU 2523114C2 · 2014 [cited by applicant]
RU 2530210C2 · 2014 [cited by applicant]
RU 2536664C2 · 2014 [cited by applicant]
RU 2538292C1 · 2015 [cited by applicant]
RU 2543564C1 · 2015 [cited by applicant]
RU 2566329C2 · 2015 [cited by applicant]
RU 2571594C2 · 2015 [cited by applicant]
RU 2580036C2 · 2016 [cited by applicant]
RU 2589310C2 · 2016 [cited by applicant]
RU 164629U1 · 2016 [cited by applicant]
RU 2607231C2 · 2017 [cited by applicant]
RU 2610586C2 · 2017 [cited by applicant]
RU 2613535C1 · 2017 [cited by applicant]
RU 2622870C2 · 2017 [cited by applicant]
RU 2625050C1 · 2017 [cited by applicant]
RU 2628192C2 · 2017 [cited by applicant]
RU 2636702C1 · 2017 [cited by applicant]
RU 2654146C1 · 2018 [cited by applicant]
RU 2670906C9 · 2018 [cited by applicant]
RU 2681699C1 · 2019 [cited by applicant]
RU 2702269C1 · 2019 [cited by applicant]
RU 2706883C1 · 2019 [cited by applicant]
RU 2706896C1 · 2019 [cited by applicant]
RU 2708356C1 · 2019 [cited by applicant]
RU 2728497C1 · 2020 [cited by applicant]
RU 2728498C1 · 2020 [cited by applicant]
RU 2738344C1 · 2020 [cited by applicant]
WO 0245380A2 · 2002 [cited by applicant]
WO 2009026564A1 · 2009 [cited by applicant]
WO 2011045424A1 · 2011 [cited by applicant]
WO 2012015171A2 · 2012 [cited by applicant]
WO 2017111835A1 · 2017 [cited by applicant]
WO 2019010182A1 · 2019 [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 17/486,428 issued on May 25, 2023. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 17/178,320 issued on Oct. 20, 2023. [cited by applicant]
Lajevardi et al., “A semantic-based correlation approach for detecting hybrid and low-level APTs”, Future Generation Computer Systems 96(1), Feb. 2019, 25 pages. [cited by applicant]
Search Report with regard to RU Patent Application No. 2020110068 completed Sep. 8, 2020. [cited by applicant]
International Search Report with regard to PCT/RU2020/000140 mailed Nov. 19, 2020. [cited by applicant]
Search Report with regard to RU Patent Application No. 2020107922 completed Mar. 24, 2020. [cited by applicant]
International Search Report with regard to PCT/RU2020/000089 mailed Oct. 29, 2020. [cited by applicant]
English Abstract for CN107392019 retrieved on Espacenet on Dec. 2, 2021. [cited by applicant]
Notice of Allowance with regard to the U.S. Appl. No. 17/087,775 mailed Nov. 15, 2021. [cited by applicant]
Search Report with regard to the NL Patent Application No. 2027556 completed Sep. 29, 2021. [cited by applicant]
Phuong, “On Preempting Advanced Persistent Threats Using Probabilistic Graphical Models”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Mar. 2019, pp. 1-14. [cited by applicant]
Manuel et al., “A survey on automated dynamic malware-analysis techniques and tools”, ACM Computing Surveys, vol. 44, No. 2, Feb. 2012, pp. 1-49. [cited by applicant]
Tokhtabayev et al., “Malware Analysis and Detection via Activity Trees in User-Dependent Environment”, Aug. 2017, ICIAP: International Conference on Image Analysis and Processing, 17th International Conference, Naples, … [cited by applicant]
Search Report with regard to EP Patent Application No. EP20924272 completed Nov. 30, 2022. [cited by applicant]
Chandramohan et al., “A scalable approach for malware detection through bounded feature space behavior modeling”, 28th IEEE/ACM International Conference on Automated Software Engineering (ASE), IEEE, 2013, pp. 312-322. [cited by applicant]
Alahmadi et al., “MalClassifier: Malware family classification using network flow sequence behaviour”, APWG Symposium on Electronic Crime Research (ECrime), IEEE, 2018, pp. 1-13. [cited by applicant]
Galal et al., “Behavior-based features model for malware detection”, Journal of Computer Virology and Hacking Techniques, Springer Paris, vol. 12, No. 2, 2015, pp. 59-67. [cited by applicant]
Pirscoveanu et al., “Analysis of malware behavior: Type classification using machine learning”, International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), Centre for Multidisciplin… [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 17/178,320 issued on Apr. 19, 2023. [cited by applicant]
English Abstract for KR20120090131 retrieved on Espacenet on Apr. 21, 2023. [cited by applicant]
Github / Linguist, https://github.com/github/linguist accessed on Sep. 24, 2021, pdf 6 pages. [cited by applicant]
Blackducksoftware / Ohcount, https://github.com/blackducksoftware/ohcount accessed on Sep. 24, 2021, pdf 4 pages. [cited by applicant]
Search Report with regard to the RU Patent Application No. 2020126232 completed Jan. 28, 2021. [cited by applicant]
Rudman et al., “Dridex: Analysis of the traffic and automatic generation of IOCs”, IEEE, 2016, https://digifors.cs.up.ac.za/issa/2016/Proceedings/Full/paper%2041.pdf, pp. 77-84. [cited by applicant]
Grant Decision and Search Report with regard to the RU Patent Application No. 2019139630 completed Jun. 26, 2020. [cited by applicant]
Dauber et al., “Stylometric Authorship Attribution in Collaborative Documents”, Materials of International Conference on Cyber Security Cryptography and Machine Learning (CSCML) 2017, pp. 115-135. [cited by applicant]
Afroz, Deception in Authorship Attribution, Drexel University, 2013, http://hdl.handle.net/1860/4431, pp. 1-91. [cited by applicant]
Granin, “Text Analyzer”, https://habr.com/ru/post/114186/ and Machine Translation into English by Yandex Translate on Oct. 21, 2020, pdf 32 pages. [cited by applicant]
“Authorship Attribution Program by NeoNeuro”, https://neoneuro.com accessed Jul. 31, 2020, pdf 5 pages. [cited by applicant]
“Tools for Software Analysis and Forensic Engineering, S.A.F.E.”, https://www.safe-corp.com/index.htm accessed Jul. 31, 2020, pdf 2 pages. [cited by applicant]
English Abstract for CN 103020494 retrieved on Espacenet on Oct. 21, 2020. [cited by applicant]
Grant Decision and Search Report with regard to the RU Patent Application No. 2019139628 completed Jun. 26, 2020. [cited by applicant]
Search Report with regard to RU Patent Application No. 2021108261 completed Feb. 28, 2022. [cited by applicant]
English Abstract for RU91213 retrieved on Espacenet on Mar. 25, 2022. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 15/707,641 mailed Apr. 25, 2019. [cited by applicant]
English Translation of CN106713312, © Questel—FAMPAT, Jul. 17, 2019. [cited by applicant]
English Translation of CN105897714, © Questel—FAMPAT, Jul. 17, 2019. [cited by applicant]
English Translation of CN106506435, © Questel—FAMPAT, Jul. 26, 2019. [cited by applicant]
English Translation of CN107392456, © Questel—FAMPAT, Jul. 29, 2019. [cited by applicant]
English Translation of CN103491205, © Questel—FAMPAT, Jul. 29, 2019. [cited by applicant]
English Translation of CN106131016, © Questel—FAMPAT, Jul. 17, 2019. [cited by applicant]
Invitation to Respond to Written Opinion received Aug. 5, 2019 with regard to the counterpart SG Patent Application No. 10201900339Q. [cited by applicant]
Invitation to Respond to Written Opinion received Aug. 5, 2019 with regard to the counterpart SG Patent Application No. 10201901079U. [cited by applicant]
Invitation to Respond to Written Opinion received Jul. 31, 2019 with regard to the counterpart SG Patent Application No. 10201900335P. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018144708 completed Aug. 16, 2019. [cited by applicant]
English Translation of KR10-2007-0049514 (Description, Claims) retrieved on Espacenet on Oct. 16, 2019. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018147431 completed Aug. 15, 2019. [cited by applicant]
English Abstract of KR10-1514984 retrieved on Espacenet on Oct. 15, 2019. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/261,854 mailed Oct. 21, 2019. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/707,641 mailed Oct. 30, 2019. [cited by applicant]
Whyte, “DNS-based Detection of Scanning Worms in an Enterprise Network”, Aug. 2004, NOSS, pp. 1-17 {Year: 2005)—in the Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/707,641. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 15/858,013 mailed Nov. 22, 2019. [cited by applicant]
Search Report with regard to the counterpart SG Patent Application No. 10201900062S mailed Dec. 5, 2019. [cited by applicant]
Search Report with regard to the counterpart SG Patent Application No. 10201900060Y mailed Dec. 5, 2019. [cited by applicant]
English Abstract for CN105429956 retrieved on Espacenet on Jan. 7, 2020. [cited by applicant]
English Abstract for CN104504307 retrieved on Espacenet on Jan. 7, 2020. [cited by applicant]
Office Action received with regard to the counterpart U.S. Appl. No. 15/858,032 mailed Apr. 6, 2020. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/858,013 mailed May 8, 2020. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/270,341 mailed May 27, 2020. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/858,013 mailed Jun. 10, 2020. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/249,004 mailed Apr. 23, 2021. [cited by applicant]
English Abstract of RU107616 retrieved on Espacenet on Jul. 3, 2017. [cited by applicant]
European Search Report with regard to EP17180099 completed on Nov. 28, 2017. [cited by applicant]
European Search Report with regard to EP17191900 completed on Jan. 11, 2018. [cited by applicant]
Yoshioka et al., “Sandbox Analysis with Controlled Internet Connection for Observing Temporal Changes of Malware Behavior”, https://www.researchgate.net/publication/254198606, 15 pages. [cited by applicant]
Yoshioka et al., “Multi-Pass Malware Sandbox Analysis with Controlled Internet Connection”, IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences, Engineering Sciences Society, Tokyo, 2… [cited by applicant]
Wikipedia, “Blockchain”, https://en.wikipedia.org/wiki/Blockchain, pdf document, 18 pages. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101764 completed Jun. 29, 2018. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101761 completed Jun. 20, 2018. [cited by applicant]
International Search Report with regard to the counterpart Patent Application No. PCT/RU2016/000526 mailed Jun. 1, 2017. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101760 completed Jun. 22, 2018. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101759 completed Sep. 7, 2018. [cited by applicant]
English Abstract of RU129279 retrieved on Espacenet on Sep. 11, 2017. [cited by applicant]
English Abstract of RU164629 retrieved on Espacenet on Sep. 11, 2017. [cited by applicant]
English Abstract of RU2538292 retrieved on Espacenet on Sep. 11, 2017. [cited by applicant]
Prakash et al., “PhishNet: Predictive Blacklisting to Detect Phishing Attacks”, INFOCOM, 2010 Proceedings IEEE, USA, 2010, ISBN: 978-1-4244-5836-3, doc. 22 pages. [cited by applicant]
Search Report with regard to the counterpart Patent Application No. RU2018105377 completed Oct. 15, 2018. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101763 completed Jan. 11, 2019. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2016137336 completed Jun. 6, 2017. [cited by applicant]
English Abstract of RU2522019 retrieved on Espacenet on Jan. 25, 2019. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2017140501 completed Jul. 11, 2018. [cited by applicant]
European Search Report with regard to the counterpart EP Patent Application No. EP17211131 completed Apr. 12, 2018. [cited by applicant]
European Search Report with regard to the counterpart EP Patent Application No. EP17210904 completed May 16, 2018. [cited by applicant]
Notice of Allowance with regard to the U.S. Appl. No. 17/077,132 mailed Oct. 11, 2022. [cited by applicant]
Search Report with regard to the counterpart Patent Application No. NL 2029433 completed Oct. 18, 2022. [cited by applicant]
Singh Jagsir et al., “A survey on machine learning-based malware detection in executable files”, Journal of Systems Architecture, Elsevier BV, NL, Aug. 2020, pp. 1-24. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 17/486,428 mailed Dec. 13, 2023. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 17/685,588 mailed Feb. 27, 2024. [cited by applicant]