IP Library › Granted Patent US 11,017,079
Granted Patent B2
US 11,017,079 · App. 15/988,955 · Granted May 25, 2021

Identifying malicious activity using data complexity anomalies

Inventors: Jonathan Edward Andersson (Austin, TX); Josiah Dede Hagen (Austin, TX)
Assignee: Trend Micro Incorporated
G06F21/554G06F21/563G06F21/577H04L63/0245H04L63/1425G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,017,079
App. No.
15/988,955
Granted
May 25, 2021
Kind
B2
Abstract

Examples relate to identifying malicious activity using data complexity anomalies. In one example, a computing device may: receive a byte stream that includes a plurality of bytes; determine, for a least one subset of the byte stream, a measure of complexity of the subset; determine that the measure of complexity meets a predetermined threshold measure of complexity for a context associated with the byte stream; and in response to determining that the measure of complexity meets the threshold, provide an indication that the byte stream complexity is anomalous.

Claims (16)

1. A non-transitory machine-readable storage medium encoded with instructions executable by a hardware processor of a computing device, the machine-readable storage medium comprising instructions to cause the hardware processor to:

receive a byte stream that includes a plurality of bytes;

determine a measure of complexity of the byte stream, the byte stream being associated with a particular context of a plurality of contexts, the particular context being based on a type of information in the byte stream;

select, based on the particular context, a predetermined threshold measure of complexity from among a plurality of predetermined threshold measures of complexity;

compare the measure of complexity to the predetermined threshold measure of complexity to determine whether the byte stream is malicious; and

in response to determining that the measure of complexity meets the predetermined threshold measure of complexity, provide an indication that the byte stream is malicious.

2. The storage medium of claim 1 , wherein the hardware processor determines measures of complexity for each of a plurality of proper subsets of the byte stream.

3. The storage medium of claim 1 , wherein each the measure of complexity is based on a measure of compressibility.

4. The storage medium of claim 1 , wherein the threshold measure of complexity is a distribution threshold.

5. A method for identifying malicious activity using data complexity anomalies, implemented by a hardware processor, the method comprising:

receiving a byte stream,

the byte stream being associated with a particular context of a plurality of contexts, the particular context being based on a type of information in the byte stream;

selecting, based on the particular context, a predetermined threshold measure of complexity from among a plurality of predetermined threshold measures of complexity;

determining a measure of complexity for the byte stream;

comparing the measure of complexity to the predetermined threshold measure of complexity to determine whether the byte stream is malicious; and

determining that the byte stream is malicious in response to determining that the measure of complexity meets the predetermined threshold measure of complexity.

Continuity (2)
Continuation PCTUS2015067222 · Dec 21, 2015
Related Publication 20180268137A1 · Sep 20, 2018