IP Library Granted Patent US 12,367,283
Granted Patent B2
US 12,367,283 · App. 18/495,291 · Granted Jul 22, 2025

Methods and apparatus for machine learning based malware detection

Inventors: Joshua Daniel Saxe (Wichita, KS); Konstantin Berlin (Potomac, MD)
Assignee: Invincea, Inc.
G06F21/563G06N3/04G06N3/045G06N5/025G06N7/01G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,283
App. No.
18/495,291
Granted
Jul 22, 2025
Kind
B2
Abstract

Apparatus and methods describe herein, for example, a process that can include receiving a potentially malicious file, and dividing the potentially malicious file into a set of byte windows. The process can include calculating at least one attribute associated with each byte window from the set of byte windows for the potentially malicious file. In such an instance, the at least one attribute is not dependent on an order of bytes in the potentially malicious file. The process can further include identifying a probability that the potentially malicious file is malicious, based at least in part on the at least one attribute and a trained threat model.

Claims (54)

1. An apparatus, comprising:

a memory; and

a hardware processor operatively coupled to the memory, the hardware processor configured to:

receive a target file;

calculate a set of informational entropy values associated with the target file;

identify a set of Portable Executable (PE) values associated with the target file;

calculate a probability that the target file is malicious based on the set of informational entropy values and the set of PE values; and

perform a remedial action based on the probability.

2. The apparatus of claim 1 , wherein the set of PE values includes a PE import vector, the hardware processor configured to:

extract an import address table from a binary representation of the target file; and

calculate the PE import vector based on hashing values from the import address table.

3. The apparatus of claim 1 , wherein the set of PE values includes a PE metadata vector, the hardware processor configured to:

extract a set of numerical PE fields from a representation of the target file; and

calculate the PE metadata vector based on the set of numerical PE fields.

4. The apparatus of claim 3 , wherein the representation of the target file is a binary representation of the target file, the hardware processor further configured to generate the binary representation of the target file.

5. The apparatus of claim 3 , wherein each numerical PE field from the set of numerical PE fields is associated with a field name, the hardware processor further configured to:

apply a hash function on the field name associated with each numerical PE field from the set of numerical PE fields to calculate the PE metadata vector.

6. The apparatus of claim 1 , wherein the hardware processor is configured to perform the remedial action by at least one of quarantining the target file, deleting the target file, sending a notification to a user regarding the target file, cleaning the target file, or executing the target file within a virtual container.

7. The apparatus of claim 1 , wherein the set of PE values is a set of PE header values.

8. A method, comprising:

receiving a target file;

calculating an attribute value associated with the target file, the attribute value being based on a set of informational entropy values associated with the target file;

identifying a set of Portable Executable (PE) values associated with the target file;

calculating a probability that the target file is malicious based at least in part on the attribute value and the set of PE values; and

communicating a threat score based on the probability, the threat score associated with a potential threat to a user, device, or network.

9. The method of claim 8 , wherein the set of PE values includes a PE import vector, the method further comprising:

extracting an import address table from a binary representation of the target file; and

calculating the PE import vector based on hashing values from the import address table.

10. The method of claim 8 , wherein the set of PE values includes a PE metadata vector, the method further comprising:

extracting a set of numerical PE fields from a binary representation of the target file; and

calculating the PE metadata vector based on hashing a fieldname associated with each numerical PE field from the set of numerical PE fields.

11. The method of claim 8 , further comprising:

dividing the target file to define a set of file windows, each informational entropy value from the set of informational entropy values being associated with a file window from the set of file windows.

12. The method of claim 8 , further comprising:

based on the threat score, at least one of quarantining the target file, deleting the target file, taking a remedial action, sending a notification to a user regarding the target file, cleaning the target file, or executing the target file within a virtual container.

13. The method of claim 8 , wherein the set of PE values is a set of PE header values.

14. A non-transitory processor-readable medium storing code representing instructions to be executed by one or more processors, the instructions comprising code to cause the one or more processors to:

receive a target file;

divide the target file to define a set of file windows;

calculate a set of informational entropy values associated with the target file, each informational entropy value from the set of informational entropy values being associated with a different file window from the set of file windows;

identify a set of Portable Executable (PE) values associated with the target file;

provide a feature vector including the set of PE values and the set of informational entropy values as input to a trained threat model to produce an output including (1) a threat score or (2) a classification of at least one of a class of malware, a source of malware, or a severity of malware; and

perform a remedial action based on the output.

15. The non-transitory processor-readable medium of claim 14 , wherein the trained threat model is at least one of a random forest classifier or a deep neural network.

16. The non-transitory processor-readable medium of claim 14 , further comprising code to cause the one or more processors to:

select the trained threat model based on a type of the target file.

17. The non-transitory processor-readable medium of claim 14 , wherein the output is based on at least one of a security indication associated with a network, a type of business hosting the network, a rate of false positives associated with the trained threat model, or a rate of false negatives associated with the trained threat model.

18. The non-transitory processor-readable medium of claim 14 , wherein the set of PE values is a set of PE header values.

19. The non-transitory processor-readable medium of claim 14 , wherein the set of PE values includes a PE import vector, and the code to cause the one or more processors to identify the set of PE values associated with the target file includes code to cause the one or more processors to:

extract an import address table from a binary representation of the target file; and

calculate the PE import vector based on hashing values from the import address table.

20. The non-transitory processor-readable medium of claim 14 , wherein the set of PE values includes a PE metadata vector, and the code to cause the one or more processors to identify the set of PE values associated with the target file includes code to cause the one or more processors to:

extract a set of numerical PE fields from a binary representation of the target file; and

calculate the PE metadata vector based on the set of numerical PE fields.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: SAXE, JOSHUA DANIEL; BERLIN, KONSTANTIN; INVINCEA LABS, LLC
To: INVINCEA, INC.
Reel/Frame 065400/0025 →
Continuity (8)
Continuation 17115272 · Dec 8, 2020
Continuation 16415471 · May 17, 2019
Continuation 15877676 · Jan 23, 2018
Continuation 15616391 · Jun 7, 2017
Continuation 15228728 · Aug 4, 2016
Provisional Application 62201263 · Aug 5, 2015
Related Publication 20240134975A1 · Apr 25, 2024
Related Publication 20240232346A9 · Jul 11, 2024
References Cited (194)
US 6226629B1 · Cossock · 2001 [cited by applicant]
US 7231440B1 · Kouznetsov et al. · 2007 [cited by applicant]
US 7739100B1 · Muttik et al. · 2010 [cited by applicant]
US 8001583B2 · Waizumi et al. · 2011 [cited by applicant]
US 8028338B1 · Schneider et al. · 2011 [cited by applicant]
US 8056134B1 · Ogilvie · 2011 [cited by applicant]
US 8095981B2 · Rabinovitch et al. · 2012 [cited by applicant]
US 8181251B2 · Kennedy · 2012 [cited by applicant]
US 8291497B1 · Griffin et al. · 2012 [cited by applicant]
US 8312539B1 · Nachenberg et al. · 2012 [cited by applicant]
US 8312545B2 · Tuvell et al. · 2012 [cited by applicant]
US 8413244B1 · Nachenberg · 2013 [cited by applicant]
US 8505094B1 · Xuewen et al. · 2013 [cited by applicant]
US 8521667B2 · Zhu et al. · 2013 [cited by applicant]
US 8701190B1 · Chau et al. · 2014 [cited by applicant]
US 8709924B2 · Hanawa et al. · 2014 [cited by applicant]
US 8838992B1 · Zhu et al. · 2014 [cited by applicant]
US 9015814B1 · Zakorzhevsky et al. · 2015 [cited by applicant]
US 9130988B2 · Seifert et al. · 2015 [cited by applicant]
US 9177144B2 · Alme · 2015 [cited by applicant]
US 9361797B1 · Chen et al. · 2016 [cited by applicant]
US 9465940B1 · Wojnowicz et al. · 2016 [cited by applicant]
US 9672358B1 · Long et al. · 2017 [cited by applicant]
US 9690938B1 · Saxe et al. · 2017 [cited by applicant]
US 9705904B1 · Davis et al. · 2017 [cited by applicant]
US 9910986B1 · Saxe et al. · 2018 [cited by applicant]
US 9940459B1 · Saxe · 2018 [cited by applicant]
US 10104100B1 · Bogorad · 2018 [cited by applicant]
US 10303875B1 · Saxe et al. · 2019 [cited by applicant]
US 10318735B2 · Saxe · 2019 [cited by applicant]
US 10432653B2 · Sim et al. · 2019 [cited by applicant]
US 10474818B1 · Saxe · 2019 [cited by applicant]
US 10599844B2 · Schmidtler et al. · 2020 [cited by applicant]
US 10649970B1 · Saxe et al. · 2020 [cited by applicant]
US 10878093B2 · Saxe · 2020 [cited by applicant]
US 10896256B1 · Saxe et al. · 2021 [cited by applicant]
US 10972495B2 · Berlin · 2021 [cited by applicant]
US 11409869B2 · Schmidtler et al. · 2022 [cited by applicant]
US 11544380B2 · Saxe · 2023 [cited by applicant]
US 11841947B1 · Saxe et al. · 2023 [cited by applicant]
US 11853427B2 · Saxe · 2023 [cited by applicant]
US 20050050335A1 · Liang et al. · 2005 [cited by applicant]
US 20050166046A1 · Bellovin et al. · 2005 [cited by applicant]
US 20050187740A1 · Marinescu · 2005 [cited by applicant]
US 20050223238A1 · Schmid · 2005 [cited by examiner]
US 20060015630A1 · Stolfo et al. · 2006 [cited by applicant]
US 20060230453A1 · Flynn et al. · 2006 [cited by applicant]
US 20070006027A1 · Desouza et al. · 2007 [cited by applicant]
US 20070220607A1 · Sprosts et al. · 2007 [cited by applicant]
US 20070240221A1 · Tuvell et al. · 2007 [cited by applicant]
US 20070283440A1 · Yao et al. · 2007 [cited by applicant]
US 20080010232A1 · Kant et al. · 2008 [cited by applicant]
US 20080127336A1 · Sun et al. · 2008 [cited by applicant]
US 20080140662A1 · Pandya · 2008 [cited by applicant]
US 20080140751A1 · Ide et al. · 2008 [cited by applicant]
US 20090024992A1 · Kulaga et al. · 2009 [cited by applicant]
US 20090044024A1 · Oberheide et al. · 2009 [cited by applicant]
US 20090100055A1 · Wang · 2009 [cited by applicant]
US 20090172815A1 · Gu et al. · 2009 [cited by applicant]
US 20090254992A1 · Schultz et al. · 2009 [cited by applicant]
US 20090293125A1 · Szor · 2009 [cited by applicant]
US 20100115620A1 · Alme · 2010 [cited by applicant]
US 20100162395A1 · Kennedy · 2010 [cited by applicant]
US 20110154495A1 · Stranne · 2011 [cited by applicant]
US 20110179484A1 · Tuvell et al. · 2011 [cited by applicant]
US 20110214161A1 · Stolfo et al. · 2011 [cited by applicant]
US 20110225655A1 · Niemeläet al. · 2011 [cited by applicant]
US 20120121194A1 · Yagnik · 2012 [cited by applicant]
US 20120158626A1 · Zhu et al. · 2012 [cited by applicant]
US 20120159620A1 · Seifert et al. · 2012 [cited by applicant]
US 20120210423A1 · Friedrichs et al. · 2012 [cited by applicant]
US 20120233127A1 · Solmer et al. · 2012 [cited by applicant]
US 20120233693A1 · Stites et al. · 2012 [cited by applicant]
US 20120323829A1 · Stokes et al. · 2012 [cited by applicant]
US 20130167236A1 · Sick · 2013 [cited by applicant]
US 20130246352A1 · Spurlock et al. · 2013 [cited by applicant]
US 20130276114A1 · Friedrichs et al. · 2013 [cited by applicant]
US 20140090061A1 · Avasarala · 2014 [cited by examiner]
US 20140298460A1 · Xue et al. · 2014 [cited by applicant]
US 20150213376A1 · Ideses et al. · 2015 [cited by applicant]
US 20150242626A1 · Wang et al. · 2015 [cited by applicant]
US 20150302268A1 · Collet et al. · 2015 [cited by applicant]
US 20150312189A1 · Lee · 2015 [cited by applicant]
US 20150379427A1 · Dirac et al. · 2015 [cited by applicant]
US 20160014149A1 · Bradley et al. · 2016 [cited by applicant]
US 20160156460A1 · Feng et al. · 2016 [cited by applicant]
US 20160239706A1 · Dijkman et al. · 2016 [cited by applicant]
US 20170017795A1 · DiGiambattista · 2017 [cited by applicant]
US 20170085585A1 · Morkovsk · 2017 [cited by applicant]
US 20170134404A1 · Machlica et al. · 2017 [cited by applicant]
US 20170228641A1 · Sohn · 2017 [cited by applicant]
US 20170328194A1 · Liu et al. · 2017 [cited by applicant]
US 20170372071A1 · Saxe · 2017 [cited by applicant]
US 20180041536A1 · Berlin · 2018 [cited by applicant]
US 20180285740A1 · Smyth et al. · 2018 [cited by applicant]
US 20190095301A1 · Sim et al. · 2019 [cited by applicant]
US 20190278909A1 · Saxe · 2019 [cited by applicant]
US 20190364063A1 · Lee et al. · 2019 [cited by applicant]
US 20210165881A1 · Saxe · 2021 [cited by applicant]
US 20210392154A1 · Waplington · 2021 [cited by applicant]
US 20220083445A1 · Nyati et al. · 2022 [cited by applicant]
US 20220215182A1 · Morishita et al. · 2022 [cited by applicant]
US 20220253691A1 · Rokka Chhetri et al. · 2022 [cited by applicant]
US 20230067285A1 · Sridhar et al. · 2023 [cited by applicant]
US 20230195897A1 · Saxe · 2023 [cited by applicant]
US 20240152617A1 · Saxe · 2024 [cited by applicant]
CN 117811845A · 2024 [cited by applicant]
EP 3018879A1 · 2016 [cited by applicant]
JP 2012027710A · 2012 [cited by applicant]
WO WO2017011702A1 · 2017 [cited by applicant]
WO WO2017223294A1 · 2017 [cited by applicant]
WO WO2019092868A1 · 2019 [cited by applicant]
WO WO2022223940A1 · 2022 [cited by applicant]
Advisory Action for U.S. Appl. No. 14/212,659, mailed Sep. 1, 2017, 3 pages. [cited by applicant]
Advisory Action for U.S. Appl. No. 14/716,290, mailed Sep. 15, 2017, 3 pages. [cited by applicant]
Advisory Action for U.S. Appl. No. 15/666,859, mailed Sep. 16, 2020, 3 pages. [cited by applicant]
[Author Unknown] “Avira Virus Lab Natural language descriptor sample page” Avira [Online] https://web.archive.org/web/20101006002848/https://www.avira.com/en/support-virus-lab (Retrieved on Oct. 30, 2017); 2 pages. [cited by applicant]
[Author Unknown] “Geographic Distribution of Threats” ThreatExpert—Automated Threat Analysis (Jan. 15, 2013) [Online] http://web.archive.org/web/20130115040419/ http://threatexpert.com/ (Retrieved on Jan. 20, 2017); 2 p… [cited by applicant]
Berlin, K. et al., “Malicious Behavior Detection using Windows Audit Logs”, Proceedings of the 8th ACM Workshop on Artificial Intelligence and Security (Oct. 16, 2015); 10 pages. [cited by applicant]
Buitinck, L., et al., “API design for machine learning software: experiences from the scikit-learn project”, arXiv preprint (2013); 16 pages. [cited by applicant]
Bulut, I. et al., “Mobile malware detection using deep neural network”, Signal Processing and Communications Applications Conference (SIU) (May 15-18, 2017); 10 pages; with English Abstract. [cited by applicant]
Corrected Notice of Allowability for U.S. Appl. No. 14/716,290, mailed Jan. 25, 2018, 4 pages. [cited by applicant]
Dahl, G. E., et al., “Large-scale malware classification using random projections and neural networks”, International Workshop on Acoustic Signal Enhancement (2012); Institute of Electrical and Electronics Engineers (20… [cited by applicant]
Dai, J., et al., “Efficient Virus Detection Using Dynamic Instruction Sequences”, Journal of Computers (May 2009); 4(5): 405-414. [cited by applicant]
Devi, D., et al., “Detection of packed malware”, SecurIT'12 (Aug. 17-19, 2012); p. 22. [cited by applicant]
Doersch, C., “Tutorial on Variational Autoencoders”, arXiv:1606.05908v2 [stat.ML], (Aug. 16, 2016); 23 pages. [cited by applicant]
Elovici, Y., et al., “Applying machine learning techniques for detection of malicious code in network traffic”, KI 2007: Advances in Artificial Intelligence: 30th Annual German Conference on AI, KI 2007, Osnabrück, Germ… [cited by applicant]
Extended European Search Report for European Application No. 17816199.8 dated Apr. 9, 2019, 8 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/115,272 dated Apr. 12, 2023, 7 pages. [cited by applicant]
Gilbert, D., “Convolutional Neural Networks for Malware Classification”, A thesis presented for the degree of Master in Artificial Intelligence (Oct. 20, 2016); 100 pages. [cited by applicant]
Griffin, K. et al., “Automatic Generation of String Signatures for Malware Detection”, International Workshop on Recent Advances in Intrusion Detection, Springer Berlin Heidelberg (2009); 29 pages. [cited by applicant]
Henchiri, O., et al., “A feature selection and evaluation scheme for computer virus detection”, Proceedings of the Sixth International Conference on Data Mining (ICDM'06), IEEE Computer Society (2006); 5 pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2017/038715, mailed Sep. 6, 2017, 8 pages. [cited by applicant]
Joachims, T., “Making large-scale SVM learning practical LS-8 Report 24”, Technical Report, University of Dortmund (1998); 18 pages. [cited by applicant]
Kecman, V., “Support vector machines-an introduction”, StudFuzz, Springer-Verlag Berlin Heidelberg (2005); 177: 1-11. [cited by applicant]
Kolosnjaji, B., et al., “Empowering convolutional networks for malware classification and analysis”, 2017 International Joint Conference on Neural Networks (IJCNN) IEEE (2017); 8 pages. [cited by applicant]
Kolter, J. Z., et al., “Learning to detect and classify malicious executables in the wild”, Journal of Machine Learning Research (2006); 7(12): 2721-2744. [cited by applicant]
Kolter, J. Z., et al., “Learning to detect malicious executables in the wild”, Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (2004); 9 pages. [cited by applicant]
Kong, D. et al., “Discriminant malware distance learning on structural information for automated malware classification”, Proceedings of the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Minin… [cited by applicant]
Luo, Y., et al., “Deep Learning With Noise”, [Online] https://pdfs.semanticscholar.org/d79b/a428e1cf1b8aa5d320a93166315bb30b4765.pdf (Retrieved Oct. 15, 2019); 9 pages; (indicated by the Examiner in U.S. Appl. No. 15/66… [cited by applicant]
Menahem, E., et al., “Improving malware detection by applying multi-inducer ensemble”, Computational Statistics & Data Analysis (2009); 53: 1483-1494. [cited by applicant]
Monnappa, K. A., “Introduction to Malware Analysis”, Learning Malware Analysis: Explore the concepts, tools, and techniques to analyze and investigate Windows malware, Packt Publishing Ltd., Birmingham—Mumbai (2018); Ch… [cited by applicant]
Morris, R., “Counting large numbers of events in small registers”, Communications of the ACM (Oct. 1978); 21(10): 840-842. [cited by applicant]
Mukkamala, S., et al., “Intrusion detection using an ensemble of intelligent paradigms”, Journal of Network and Computer Applications (2005); 28(2): 167-182. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/068,090 dated Apr. 27, 2023, 19 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/115,272, Aug. 23, 2022, 12 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 14/212,659, mailed Jan. 8, 2020, 8 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 14/716,290, mailed Nov. 30, 2017, 7 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/630,495, mailed Jan. 28, 2019, 14 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/666,859, mailed Nov. 19, 2020, 10 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/877,676, mailed Jan. 18, 2019, 5 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/907,817, mailed Jul. 8, 2019, 7 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/415,471, mailed Sep. 10, 2020, 5 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/425,115, mailed Aug. 24, 2020, 5 pages. [cited by applicant]
Office Action for Indian Application No. IN201917002098 dated Aug. 31, 2023, 3 pages. [cited by applicant]
Office Action for UK Patent Application No. GB 1712454.6, dated May 24, 2021, 5 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/212,659, mailed Aug. 3, 2018, 32 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/212,659, mailed Jul. 22, 2016, 27 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/212,659, mailed May 16, 2019, 36 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/212,659, mailed May 19, 2017, 29 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/212,659, mailed Nov. 13, 2017, 31 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/716,290, mailed Aug. 4, 2016, 15 pages. [cited by applicant]
Office Action for U.S. Appl. No. 14/716,290, mailed Jun. 1, 2017, 14 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/228,728, mailed Oct. 21, 2016, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/616,391, mailed Sep. 22, 2017, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/666,859, mailed Apr. 29, 2020, 30 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/666,859, mailed Oct. 21, 2019, 25 pages. [cited by applicant]
Office Action for U.S. Appl. No. 15/877,676, mailed Sep. 14, 2018, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/415,471, mailed May 11, 2020, 5 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/425,115, mailed May 29, 2020, 10 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/125,280 mailed on Jul. 14, 2022, 15 pages. [cited by applicant]
Patterson, N., et al., “Semantic Hashing with Variational Autoencoders” [Online] https://pdfs.semanticscholar.org/f2c3/3951f347b5e0f7ac4946f0672fdb4ca5394b.pdf (2016); 12 pages. [cited by applicant]
Russell, S. J., “Kernel Machines”, Artificial Intelligence a Modern Approach, Pearson Education International (2010); Section 20(6): 749-751. [cited by applicant]
Sathyanarayan, V. S. et al., “Signature generation and detection of malware families”, Information Security and Privacy: 13th Australasian Conference, ACISP 2008, Wollongong, Australia (Jul. 7-9, 2008), Proceedings 13. … [cited by applicant]
Saxe, J. et al., “CrowdSource: Automated Inference of High Level Malware Functionality from Low-Level Symbols Using a Crowd Trained Machine Learning Model”, IEEE 9th International Conference (Oct. 28, 2014); pp. 8 pages. [cited by applicant]
Saxe, J. et al., “Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features”, arXiv:1508.03096v2 [cs.CR] (Sep. 3, 2015); 10 pages. [cited by applicant]
Saxe, J. et al., “Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features”, IEEE 2015,10th International Conference on Malicious and Unwanted Software: “Know Your Enemy” (Malware) (2015… [cited by applicant]
Saxe, J. et al., “expose: A Character-Level Convolutional Neural Network with Embeddings for Detecting Malicious URLs, File Paths and Registry Keys” arXiv:1702.08568v1 [cs.CR] [Online] https://arxiv.org/abs/1702.08568 (… [cited by applicant]
Saxe, J. et al., “Visualization of Shared System Call Sequence Relationships in Large Malware Corpora”, Proceedings of the ninth international symposium on visualization for cyber security, VizSec '12, Seattle, WA (Oct.… [cited by applicant]
Saxe, J., Presentation: “Why Security Data Science Matters and How its Different: Pitfalls and Promises of Data Science Based Breach Detection and Threat Intelligence”, Invincea (2015); 103 pages. [cited by applicant]
Saxe, J., “Why Security Data Science Matters and How its Different: Pitfalls and Promises of Data Science Based Breach Detection and Threat Intelligence”, Black Hat USA 2015 Briefings (Aug. 1-6, 2016) [Online] https://w… [cited by applicant]
Schroff, F. et al., “FaceNet: A Unified Embedding for Face Recognition and Clustering”, Computer Vision Foundation [Online] https://www.cv-foundation.org/openaccess/content_cvpr_2015/papers/Schroff_FaceNet_A_Unified_201… [cited by applicant]
Search Report for UK Patent Application No. GB 1712454.6, dated Jan. 16, 2018, 4 pages. [cited by applicant]
Sikorski, M., et al., “Practical malware analysis: the hands-on guide to dissecting malicious software”, no starch press (2012); pp. 2-3; pp. 11-13; p. 384; 12 pages. [cited by applicant]
Souppaya, M., et al., “Guide to malware incident prevention and handling for desktops and laptops”, NIST Special Publication 800-83 Revision 1 (2013); 47 pages. [cited by applicant]
Tahan, G., et al., “Mal-id: Automatic malware detection using common segment analysis and meta-features”, Journal of Machine Learning Research (2012); 13: 949-979. [cited by applicant]
Van Durme, B. et al., “Probabilistic counting with randomized storage”, In Proceedings of the 21st International Joint Conference on Artificial Intelligence (IJCAI'09), Hiroaki Kitano (ed.), Morgan Kaufmann Publishers I… [cited by applicant]
Wang, T., et al., “Detecting unknown malicious executables using portable executable headers”, 2009 Fifth International Joint Conference on INC, IMS and IDC. IEEE (2009); p. 278. [cited by applicant]
Wang, Y., et al., “A deep learning approach for detecting malicious JavaScript code”, Security and Communications Networks (2016); 9(11): 1520-1534. [cited by applicant]
Wilding, Ed., “The authoritative international publication on computer virus prevention, recognition and removal”, Virus Bulletin (Nov. 1990); 24 pages. [cited by applicant]
Ye, Y., et al., “SBMDS: an interpretable string based malware detection system using SVM ensemble with bagging”, Journal in Computer Virology (2009); 5: 283-293. [cited by applicant]
Ye, Y., et al., “Hierarchical associative classifier (HAC) for malware detection from the large and imbalanced gray list”, Journal of Intelligent Information Systems (2010); 35: 1-20. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/506,962, by Saxe, Joshua Daniel, mailed May 22, 2024, 26 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/506,962, by Saxe, Joshua Daniel, mailed Aug. 29, 2024, 9 pages. [cited by applicant]