IP Library › Granted Patent US 12,437,059
Granted Patent B2
US 12,437,059 · App. 18/341,832 · Granted Oct 7, 2025

Workload pattern detection

Inventors: Loic Fura (Poughkeepsie, NY); Chon N. Lei (Poughkeepsie, NY); Joseph Gentile (Wappingers Falls, NY); Jayapreetha Natesan (Hopewell Junction, NY); Abuchi Obiegbu (Poughkeepsie, NY); Olayinka Adesanya (Fishkill, NY)
Assignee: International Business Machines Corporation
G06F21/552G06N7/01G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,059
App. No.
18/341,832
Granted
Oct 7, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computer system are provided. A processor retrieves instructions for a plurality of processes. A processor generates a sample of the instructions for the plurality of processes. A processor determines a probability that the sample includes instructions from malicious processes. A processor, in response to the probability exceeding a threshold value, restricts one or more aspects of operation for at least one process of the plurality of processes.

Claims (55)

1. A computer-implemented method comprising:

retrieving instructions for a plurality of processes;

generating a sample of the instructions for the plurality of processes, wherein the sample of the instructions are non-sequential in regards to the instructions execution order, and wherein the sample of the instructions are randomly selected and include filtering aspects that attribute the sample to a device or process the sample of the instructions are retrieved from;

determining, using a machine learning model, a probability that the sample includes instructions from malicious processes;

in response to the probability exceeding a threshold value, restricting one or more aspects of operation for at least one process of the plurality of processes;

filtering, in response to the probability exceeding the threshold value, at least one process from the sample based on one or more identifiers corresponding to the filtering aspects that attribute the sample to the device or the process;

and generating a sample for at least each process and device that includes the instructions from the malicious process.

2. The computer-implemented method of claim 1 , wherein the machine learning model is a logistic regression model.

3. The computer-implemented method of claim 1 , wherein the machine learning model includes on or more of the following models: a deep neural network (DNN) or a support vector machine (SVM).

4. The computer-implemented method of claim 1 , the method further comprising:

in response to the probability exceeding the threshold value, filtering at least one process from the sample; and

determining a filtered probability that the filtered sample includes instructions from malicious processes.

5. The computer-implemented method of claim 1 , wherein the determining the probability that the sample includes instructions from malicious processes is performed by a hardware module connected to a processor executing the more than one process.

6. A computer program product comprising:

one or more computer-readable storage media and program instructions stored on the one or more computer-readable storage media, the program instructions comprising:

program instructions to retrieve instructions for a plurality of processes;

program instructions to generate a sample of the instructions for the plurality of processes, wherein the sample of the instructions are non-sequential in regards to the instructions execution order, and wherein the sample of the instructions are randomly selected and include filtering aspects that attribute the sample to a device or process the sample of the instructions are retrieved from;

program instructions to determine, using a machine learning model, a probability that the sample includes instructions from malicious processes;

program instructions, in response to the probability exceeding a threshold value, to restrict one or more aspects of operation for at least one process of the plurality of processes;

program instructions to filter, in response to the probability exceeding the threshold value, at least one process from the sample based on one or more identifiers corresponding to the filtering aspects that attribute the sample to the device or the process;

and program instructions to generate a sample for at least each process and device that includes the instructions from the malicious process.

7. The computer program product of claim 6 , wherein the machine learning model is a logistic regression model.

8. The computer program product of claim 6 , wherein the machine learning model includes on or more of the following models: a deep neural network (DNN) or a support vector machine (SVM).

9. The computer program product of claim 7 , the program instructions further comprising:

program instructions, in response to the probability exceeding the threshold value, to filter at least one process from the sample; and

program instructions to determine a filtered probability that the filtered sample includes instructions from malicious processes.

10. The computer program product of claim 6 , wherein the determining the probability that the sample includes instructions from malicious processes is performed by a hardware module connected to a processor executing the more than one process.

11. A computer system comprising:

one or more computer processors;

one or more computer readable storage media;

and program instructions stored on the computer readable storage media for execution by at least one of the one or more processors, the program instructions comprising:

program instructions to retrieve instructions for a plurality of processes;

program instructions to generate a sample of the instructions for the plurality of processes, wherein the sample of the instructions are non-sequential in regards to the instructions execution order, and wherein the sample of the instructions are randomly selected and include filtering aspects that attribute the sample to a device or process the sample of the instructions are retrieved from;

program instructions to determine, using a machine learning model, a probability that the sample includes instructions from malicious processes;

program instructions, in response to the probability exceeding a threshold value, to restrict one or more aspects of operation for at least one process of the plurality of processes;

program instructions to filter, in response to the probability exceeding the threshold value, at least one process from the sample based on one or more identifiers corresponding to the filtering aspects that attribute the sample to the device or the process;

and program instructions to generate a sample for at least each process and device that includes the instructions from the malicious process.

12. The computer system of claim 11 , the program instructions further comprising:

program instructions, in response to the probability exceeding the threshold value, to filter at least one process from the sample; and

program instructions to determine a filtered probability that the filtered sample includes instructions from malicious processes.

13. The computer-implemented method of claim 1 , wherein determining the probability that the sample includes instructions from the malicious process further comprises:

training the machine learning model based on a training data set, wherein the training data set is built from samples of the instructions for the plurality of processes retrieved, wherein the samples of the instructions retrieved include pre-classifications as either a malicious or a non-malicious program;

determining, using the machine learning model, a probability for each of the samples from the training data set include instructions from the malicious process, wherein the machine learning model uses logistic regression in determining the probability for each of the samples from the training data set;

verifying, the probability generated by the machine learning model for each of the samples corresponds to the pre-classifications; and

deploying the machine learning model for malicious code detection.

14. The computer-implemented method of claim 1 , wherein the instructions retrieved for the plurality of processes are binary operational codes executed by the plurality of processes, and wherein instruction data includes any addresses or registers accessed by the instructions corresponding to the plurality of processes.

15. The computer-implemented method of claim 1 , wherein determining the probability that the sample includes instructions from the malicious process further comprises:

creating statistical distribution data of the instructions;

observing, by the machine learning model, a distribution of potentially malicious instructions; and

increasing the probability that the sample includes instructions from malicious processes based on the observing of the distribution of the potentially malicious instructions.

16. The computer-implemented method of claim 1 , further comprising:

generating a subsample of the instructions, wherein the subsample filters out one or more processes from the sample with the probability exceeding the threshold value;

determining, using the machine learning model, that the probability the subsample includes instructions from the malicious process is less than the probability that the sample includes instructions from the malicious process;

determining that the one or more processes filtered from the subsample contributed to a maliciousness of the sample; and

adding the one or more processes back to the sample and filtering out one or more different processes for a next subsample.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2023
From: FURA, LOIC; LEI, CHON N.; GENTILE, JOSEPH; NATESAN, JAYAPREETHA; OBIEGBU, ABUCHI; ADESANYA, OLAYINKA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064069/0627 →
Continuity (1)
Related Publication 20250005140A1 · Jan 2, 2025
References Cited (46)
US 6574727B1 · Davidson · 2003 [cited by examiner]
US 10089459B2 · Sridhara · 2018 [cited by applicant]
US 10459849B1 · Shorb et al. · 2019 [cited by applicant]
US 10503904B1 · Singh et al. · 2019 [cited by applicant]
US 10607009B2 · Dahan · 2020 [cited by applicant]
US 10880328B2 · Farhady · 2020 [cited by applicant]
US 10997288B2 · Cudak · 2021 [cited by applicant]
US 11144638B1 · Golden · 2021 [cited by applicant]
US 11347500B2 · Krishnamoorthy et al. · 2022 [cited by applicant]
US 11347849B2 · Hicks · 2022 [cited by applicant]
US 11374946B2 · Hewlett, II · 2022 [cited by applicant]
US 11620379B1 · Hegde et al. · 2023 [cited by applicant]
US 20130326625A1 · Anderson · 2013 [cited by examiner]
US 20150058984A1 · Shen · 2015 [cited by examiner]
US 20160173516A1 · Raugas · 2016 [cited by examiner]
US 20190042745A1 · Chen · 2019 [cited by examiner]
US 20190197239A1 · Govardhan · 2019 [cited by applicant]
US 20190199736A1 · Howard · 2019 [cited by examiner]
US 20190303116A1 · Ding et al. · 2019 [cited by applicant]
US 20190340392A1 · Khorrami et al. · 2019 [cited by applicant]
US 20210328969A1 · Gaddam et al. · 2021 [cited by applicant]
US 20220138319A1 · Kim · 2022 [cited by applicant]
US 20220309160A1 · Xiao et al. · 2022 [cited by applicant]
US 20220311798A1 · Dani et al. · 2022 [cited by applicant]
US 20230252136A1 · Kim · 2023 [cited by examiner]
US 20230281308A1 · Maimon · 2023 [cited by examiner]
US 20230281315A1 · Capellman · 2023 [cited by examiner]
US 20240362335A1 · Biondi · 2024 [cited by examiner]
IN 202131001289A · 2021 [cited by applicant]
“Ransomware Protection Market Size and Forecast”, Verified Market Research, accessed on Feb. 3, 2023, 6 pages, <https://www.verifiedmarketresearch.com/product/ransomware-protection-market/>. [cited by applicant]
Braue, David, “Global Ransomware Damage Costs Predicted to Exceed $265 Billion by 2031”, 2022 Cybersecurity Ventures, 10 pages, <https://cybersecurityventures.com/global-ransomware-damage-costs-predicted-to-reach-250-bi… [cited by applicant]
Disclosed Anonymously, “Method of Early Detection and Halting of Ransomware Attacks”, IP.com No. IPCOM000268682D, IP.com Electronic Publication Date: Feb. 15, 2022, 5 pages. [cited by applicant]
Disclosed Anonymously, “System and Method for Reducing False Positives in the Failure Prediction of an Operating System”, IP.com No. IPCOM000266634D, IP.com Electronic Publication Date: Aug. 4, 2021, 11 pages. [cited by applicant]
Faruk et al., “Malware Detection and Prevention using Artificial Intelligence Techniques”, 2021 IEEE International Conference on Big Data (Big Data), ResearchGate, Conference Paper—Dec. 2021, 10 pages. [cited by applicant]
Gulmez et al., “Graph-Based Malware Detection Using Opcode Sequences”, 2021 9th International Symposium on Digital Forensics and Security (ISDFS), © 2021 IEEE, 5 pages. [cited by applicant]
Jeon et al., “Malware-Detection Method with a Convolutional Recurrent Neural Network Using Opcode Sequences”, Information Sciences, 2020, © 2020 Published by Elsevier Inc., 19 pages. [cited by applicant]
Jha et al., “Recurrent Neural Network for Detecting Malware”, Computers & Security 99, 2020, © 2020 Elsevier Ltd., 13 pages. [cited by applicant]
Masum et al., “Ransomware Classification and Detection With Machine Learning Algorithms”, ResearchGate, Conference Paper—Jan. 2022, 7 pages. [cited by applicant]
Niu et al., “Opcode-Level Function Call Graph Based Android Malware Classification Using Deep Learning”, Sensors 2020, Published: Jun. 29, 2020, 21 pages. [cited by applicant]
Patel et al., “Analyzing Hardware Based Malware Detectors”, DAC '17, Jun. 18-22, 2017, Austin, TX, USA, © 2017 ACM, 6 pages. [cited by applicant]
Singh et al., “Ransomware Detection using Process Memory”, Proceedings of the 17th International Conference on Information Warfare and Security, 2022, 10 pages. [cited by applicant]
Wikipedia, “Swiss cheese model”, access on Feb. 3, 2023, 3 pages, <https://en.wikipedia.org/wiki/Swiss_cheese_model>. [cited by applicant]
Zhang, et al., “Classification of Ransomware Families with Machine Learning Based on N-Gram of Opcodes”, Future Generation Computer Systems 90, 2019, 11 pages. [cited by applicant]
Danducci II et al., “Detection of Malicious Encryption Based on Machine Learning”, U.S. Appl. No. 18/341,841, filed Jun. 27, 2023, 31 pages. [cited by applicant]
IBM Appendix P, list of patents and patent applications treated as related, Filed Herewith, 2 pages. [cited by applicant]
Wikipedia, “Logistic regression”, Retrieved from: https://web.archive.org/web/20240101081307/https://en.wikipedia.org/wiki/Logistic_regression, Retrieval date, Jan. 1, 2024, 28 pages. [cited by applicant]