IP Library Granted Patent US 11,436,330
Granted Patent B1
US 11,436,330 · App. 17/460,611 · Granted Sep 6, 2022

System for automated malicious software detection

Inventors: Joshua Holden Jennings (South Royalton, VT); Timothy Paul Kenney (Richmond, VT)
Assignee: SOOS LLC
G06F21/566G06F40/20G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,330
App. No.
17/460,611
Granted
Sep 6, 2022
Kind
B1
Abstract

A system for automated malicious software detection includes a computing device, the computing device configured to receive a software component, identify at least an element of software component metadata corresponding to the software component, determine a malicious quantifier as a function of the software component metadata, wherein determining the malicious quantifier further comprises obtaining a source repository, the source repository including at least an element of source metadata, and determining the malicious quantifier as a function of the at least an element of software component metadata and the at least an element of source repository metadata using a malicious machine-learning model, and transmit a notification as a function of the malicious quantifier and a predictive threshold.

Claims (63)

1. A system for automated malicious software detection, the system comprising a computing device, the computing device comprising:

a processor; and

a memory communicatively connected to the processor, the memory containing instructions configuring the processor to:

receive a software component;

identify at least an element of software component metadata corresponding to the software component, wherein the software component metadata comprises a component name;

determine a malicious quantifier as a function of the software component metadata, wherein determining the malicious quantifier further comprises:

obtaining a source repository, the source repository including at least an element of source metadata;

generating a malicious machine-learning model as a function of a malicious training set, wherein the training set correlates a metadata difference to a malicious identifier; and

determining the malicious quantifier as a function of the component name and the at least an element of source repository metadata, wherein determining the malicious quantifier further comprises:

identifying a string distance between the software component metadata and the at least an element of source metadata as a function of a name matching algorithm;

inputting the string distance to the malicious machine-learning model; and

determining, using the machine-learning model, the malicious quantifier based on the string distance; and

transmit a notification as a function of the malicious quantifier and a predictive threshold.

2. The system of claim 1 , wherein determining the malicious quantifier further comprises determining a similarity element.

3. The system of claim 2 , wherein determining the similarity element further comprises performing a similarity test.

4. The system of claim 1 , wherein determining the malicious quantifier further comprises identifying a malicious component embedded in the software component.

5. The system of claim 1 , wherein the name matching algorithm includes a language processing module.

6. The system of claim 1 , wherein determining the malicious quantifier further comprises generating a weighted vector.

7. The system of claim 1 , wherein training the machine-learning model further comprises:

obtaining a user input;

updating the training data as a function of the user input; and

training the machine-learning model using the updated training data.

8. The system of claim 1 , wherein transmitting the notification further comprises outputting a suggestive element.

9. The system of claim 1 , wherein determining the string distance further comprises:

determining a download count of the software component;

determining a download count of the at least an element of source data; and

determining the string distance as a function of a difference between the download count of the software component and the download count of the at least an element of source data.

10. The method of claim 1 , wherein determining the string distance further comprises:

determining a first difference between a contributor count of the software component and a contributor count of the at least an element of source data;

determining a second difference between a download count of the software component and a download count of the at least an element of source data; and

determining the string distance as a function of the first difference and the second difference.

11. A method for automated malicious software detection, the method comprising:

receiving, by a computing device, a software component;

identifying, by the computing device, at least an element of software component metadata corresponding to the software component, wherein the software component metadata comprises a component name;

determining, by the computing device, a malicious quantifier as a function of the software component metadata, wherein determining the malicious quantifier further comprises:

obtaining a source repository, the source repository including at least an element of source metadata;

generating a malicious machine-learning model as a function of a malicious training set, wherein the training set correlates a metadata difference to a malicious identifier; and

determining a malicious quantifier as a function of the software component metadata, wherein determining the malicious quantifier further comprises:

obtaining a source repository, the source repository including at least an element of source metadata;

generating a malicious machine-learning model as a function of a malicious training set, wherein the training set correlates a metadata difference to a malicious identifier; and

determining the malicious quantifier as a function of the component name and the at least an element of source repository metadata, wherein determining the malicious quantifier further comprises:

identifying a string distance between the software component metadata and the at least an element of source metadata as a function of a name matching algorithm;

inputting the string distance to the malicious machine-learning model; and

determining, using the machine-learning model, the malicious quantifier based on the string distance; and

transmit a notification as a function of the malicious quantifier and a predictive threshold.

12. The method of claim 11 , wherein determining the malicious quantifier further comprises determining a similarity element.

13. The method of claim 12 , wherein determining the similarity element further comprises performing a similarity test.

14. The method of claim 11 , wherein determining the malicious quantifier further comprises identifying a malicious component embedded in the software component.

15. The method of claim 11 , wherein the name matching algorithm includes a language processing module.

16. The method of claim 11 , wherein determining the malicious quantifier further comprises generating a weighted vector.

17. The method of claim 11 , wherein training the machine-learning model further comprises:

obtaining a user input;

updating the training data as a function of the user input; and

training the machine-learning model using the updated training data.

18. The method of claim 11 , wherein transmitting the notification further comprises outputting a suggestive element.

19. The system of claim 11 , wherein determining the string distance further comprises:

determining a download count of the software component;

determining a download count of the at least an element of source data; and

determining the string distance as a function of a difference between the download count of the software component and the download count of the at least an element of source data.

20. The method of claim 11 , wherein determining the string distance further comprises:

determining a first difference between a contributor count of the software component and a contributor count of the at least an element of source data;

determining a second difference between a download count of the software component and a download count of the at least an element of source data; and

determining the string distance as a function of the first difference and the second difference.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: JENNINGS, JOSHUA HOLDEN; KENNEY, TIMOTHY PAUL
To: SOOS LLC
Reel/Frame 057329/0975 →
Continuity (1)
Provisional Application 63203255 · Jul 14, 2021
Cited By (5)
US 12,229,249 US 12,229,545 US 12,632,548 US 12,664,274 US 12,699,773