IP Library Granted Patent US 12,045,349
Granted Patent B2
US 12,045,349 · App. 17/978,624 · Granted Jul 23, 2024

Multi-dimensional malware analysis

Inventors: Steven Grobman (Flower Mound, TX); Jonathan B. King (Hillsboro, OR); Yonghong Huang (Portland, OR); Amit Kumar (Bangalore, IN)
Assignee: McAfee, LLC
G06F21/566G06F21/54G06F21/568G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,045,349
App. No.
17/978,624
Granted
Jul 23, 2024
Kind
B2
Abstract

There is disclosed in one example a computing apparatus, including: a hardware platform, including a processor, a memory, and a network interface; a bucketized reputation modifier table; and instructions encoded within the memory to instruct the processor to: perform a feature-based malware analysis of an object; assign the object a malware reputation according to the feature-based malware analysis; query and receive via the network interface a complementary score for a complementary property of the object; query the bucketized reputation modifier table according to the complementary score to receive a reputation modifier for the object; adjust the object's reputation according to the reputation modifier; and take a security action according to the adjusted reputation.

Claims (26)

1. A computer-implemented method of detecting computer malware, comprising:

bucketizing analysis results for a class of objects based on one or more features shared by the class of objects;

computing respective probabilistic curves for buckets of the bucketized analysis results;

computing respective feature analysis thresholds for the probabilistic curves;

performing feature analysis on an object under analysis, including computing a malware score;

comparing the malware score to a feature analysis threshold for a bucket associated with the object under analysis; and

taking a malware action on the object under analysis based on the comparing.

2. The computer-implemented method of claim 1 , wherein bucketizing analysis results comprises computing a set of probabilistic curves associated with the bucketized analysis results.

3. The computer-implemented method of claim 1 , wherein bucketizing analysis results comprises computing bucketized predictions for one or more objects.

4. The computer-implemented method of claim 1 , wherein bucketizing analysis results comprises computing uniform resource locator (URL) reputations for one or more objects.

5. The computer-implemented method of claim 1 , wherein bucketizing analysis results comprises bucketizing internet protocol (IP) address reputations for one or more objects.

6. The computer-implemented method of claim 1 , wherein bucketizing analysis results comprises bucketizing certificate reputation for one or more objects.

7. The computer-implemented method of claim 1 , wherein the probabilistic curves represent a probability that an object is malicious or is associated with a malicious entity, without respect to a severity of maliciousness.

8. The computer-implemented method of claim 1 , wherein the object's position within the probabilistic curves is not a direct input to the feature analysis.

9. The computer-implemented method of claim 1 , wherein computing the probabilistic curves is performed on a cloud or backend service.

10. One or more tangible, nontransitory computer-readable storage media having stored thereon executable instructions to instruct a processor to: bucketize analysis results for a class of objects based on one or more features shared by the class of objects; compute respective probabilistic curves for buckets of the bucketized analysis results; compute respective feature analysis thresholds for the probabilistic curves; perform feature analysis on an object under analysis, including computing a malware score; compare the malware score to a feature analysis threshold for a bucket associated with the object under analysis; and take a malware action on the object under analysis based on the comparing.

11. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein bucketizing analysis results comprises computing a set of probabilistic curves associated with the bucketized analysis results.

12. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein bucketizing analysis results comprises computing bucketized predictions for one or more objects.

13. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein bucketizing analysis results comprises computing uniform resource locator (URL) reputations for one or more objects.

14. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein bucketizing analysis results comprises bucketizing internet protocol (IP) address reputations for one or more objects.

15. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein bucketizing analysis results comprises bucketizing certificate reputation for one or more objects.

16. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein the probabilistic curves represent a probability that an object is malicious or is associated with a malicious entity, without respect to a severity of maliciousness.

17. The one or more tangible, nontransitory computer-readable storage media of claim 10 , wherein the object's position within the probabilistic curves is not a direct input to the feature analysis.

18. A computing apparatus, comprising: a hardware platform comprising a processor circuit and a memory; and instructions encoded within the memory to instruct the processor circuit to: bucketize analysis results for a class of objects based on one or more features shared by the class of objects; compute respective probabilistic curves for buckets of the bucketized analysis results; compute respective feature analysis thresholds for the probabilistic curves; perform feature analysis on an object under analysis, including computing a malware score; compare the malware score to a feature analysis threshold for a bucket associated with the object under analysis; and take a malware action on the object under analysis based on the comparing.

19. The computing apparatus of claim 18 , wherein bucketizing analysis results comprises computing a set of probabilistic curves associated with the bucketized analysis results.

20. The computing apparatus of claim 18 , wherein bucketizing analysis results comprises computing bucketized predictions for one or more objects.

Priority Claims (1)
IN 202041039840 · Sep 15, 2020 · national
Continuity (2)
Continuation 17083457 · Oct 29, 2020
Related Publication 20230056936A1 · Feb 23, 2023