IP Library Granted Patent US 12,462,026
Granted Patent B2
US 12,462,026 · App. 18/272,802 · Granted Nov 4, 2025

Generation device, generation method, and generation program

Inventors: Daiki Chiba (Musashino, JP); Mitsuaki Akiyama (Musashino, JP)
Assignee: NTT, Inc.
G06F21/56G06F21/562
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,026
App. No.
18/272,802
Granted
Nov 4, 2025
Kind
B2
Abstract

A generation device includes generation circuitry configured to acquire information on software, extract a feature quantity of the software from the information of the software acquired, generate a cluster for each software on the basis of the feature quantity extracted, calculate a clustering result including a center of gravity of the cluster, match the clustering result calculated with the past clustering result when a distance between a center of gravity of a cluster included in the past clustering result calculated from information on malware is equal to or less than a predetermined value, and generate a graph representing a relationship between the software and the malware on the basis of a result of matching.

Claims (41)

1 . A generation device comprising:

generation circuitry configured to:

acquire information on software;

extract a feature quantity of the software from the information of the software acquired;

generate a cluster for the software based on the feature quantity extracted, and calculate a clustering result including a center of gravity of the cluster;

match the clustering result calculated with a past clustering result when a distance between a center of gravity of a cluster included in the past clustering result calculated from information on malware is equal to or less than a predetermined value; and

generate a graph representing a relationship between the software and the malware based on a result of matching, and

output the generated graph to a display,

wherein the generation circuitry is further configured to:

acquire information on a plurality of pieces of software in a time series order;

extract an operation or structural characteristic of the software as the feature quantity;

further update the past clustering result;

and connect a node corresponding to the clustering result matched and the node corresponding to the past clustering result by edges in a time series order.

2 . The generation device according to claim 1 , wherein the generation circuitry is further configured to:

extract, as the feature quantity, a permission requested by the software, or a package name and a class name of a source code of the software.

3 . The generation device according to claim 2 , wherein the generation circuitry is further configured to:

generate the cluster using an X-means method;

and match the clustering result using a k-nearest neighbors algorithm.

4 . The generation device according to claim 1 , further comprising:

detection circuitry configured to detect a change in a property of the software; and

distribution circuitry configured to distribute learning data to a machine learning model for identifying software based on the change of the property detected.

5 . A generation method, comprising:

acquiring information on software;

extracting a feature quantity of the software from the information of the software acquired in the acquisition step;

generating a cluster for the software based on the feature quantity extracted, and calculating a clustering result including a center of gravity of the cluster;

matching the clustering result calculated with a past clustering result when a distance between the center of gravity of the cluster included in the past clustering result calculated from information on malware is equal to or less than a predetermined value;

and generating a graph representing the relationship between the software and the malware based on the result of matching, wherein

the acquiring includes acquiring information on a plurality of pieces of software in a time series order,

the extracting includes extracting an operation or structural characteristic of the software as the feature quantity,

the generating of the cluster includes further updating the past clustering result, and

the generating of the graph includes connecting a node corresponding to the clustering result matched and the node corresponding to the past clustering result by edges in a time series order.

6 . A non-transitory computer-readable recording medium storing therein a generation program causing a computer to execute a process comprising:

acquiring information on software;

extracting a feature quantity of the software from the information of the software acquired;

generating a cluster for each of the software based on the feature quantity extracted, and calculating a clustering result including a center of gravity of the cluster;

matching the clustering result calculated with a past clustering result when a distance between a center of gravity of a cluster included in the past clustering result calculated from information on malware is equal to or less than a predetermined value;

and generating a graph representing a relationship between the software and the malware based on a result of matching, wherein

the acquiring includes acquiring information on a plurality of pieces of software in a time series order,

the extracting includes extracting an operation or structural characteristic of the software as the feature quantity,

the generating of the cluster includes further updating the past clustering result, and

the generating of the graph includes connecting a node corresponding to the clustering result matched and the node corresponding to the past clustering result by edges in a time series order.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2023
From: CHIBA, DAIKI; AKIYAMA, MITSUAKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 064292/0518 →
Continuity (1)
Related Publication 20240303330A1 · Sep 12, 2024
References Cited (21)
US 20060015630A1 · Stolfo · 2006 [cited by examiner]
US 20150026808A1 · Perdisci · 2015 [cited by examiner]
US 20160357965A1 · Prowell · 2016 [cited by examiner]
US 20170063910A1 · Muddu · 2017 [cited by examiner]
US 20180288087A1 · Hittel · 2018 [cited by examiner]
US 20190073474A1 · Zhang · 2019 [cited by examiner]
US 20240004993A1 · Rozenberg · 2024 [cited by examiner]
CN 107368856A · 2017 [cited by examiner]
CN 108170467A · 2018 [cited by applicant]
CN 109074454A · 2018 [cited by examiner]
CN 110110177A · 2019 [cited by applicant]
CN 111090859A · 2020 [cited by applicant]
CN 107368856B · 2021 [cited by examiner]
KR 1020160119295A · 2016 [cited by applicant]
KR 20250069361A · 2025 [cited by examiner]
Extended European Search Report issued Sep. 30, 2024 in European Patent Application No. 21920981.4, 10 pages. [cited by applicant]
Aafer et al., “DroidAPIMiner: Mining API-Level Features for Robust Malware Detection in Android”, Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, SecureComm 2013, LNICST, vol. 127… [cited by applicant]
Arp et al., “DREBIN: Effective and Explainable Detection of Android Malware in Your Pocket”, NDSS'14, Feb. 23-26, 2014, pp. 1-15. [cited by applicant]
Mariconti et al., “MAMADROID: Detecting Android Malware by Building Markov Chains of Behavioral Models”, arXiv:1612.04433v3 [cs.CR], NDSS 2017, Nov. 20, 2017, pp. 1-16. [cited by applicant]
Mirzaei et al., “AndrEnsemble: Leveraging API Ensembles to Characterize Android Malware Families”, Session 4A: Mobile Security, AsiaCCS '19, Jul. 9-12, 2019, pp. 307-314. [cited by applicant]
Nomura et al., “Creating Family Tree of Android Malware”, Computer Security Symposium 2020, Information Processing Society of Japan, Oct. 26-29, 2020, pp. 527-534 (8 pages including English Abstract). [cited by applicant]