IP Library Granted Patent US 11,886,586
Granted Patent B1
US 11,886,586 · App. 16/811,651 · Granted Jan 30, 2024

Malware families identification based upon hierarchical clustering

Inventors: Yin-Ming Chang (Taipei, TW); Hsing-Yun Chen (Taipei, TW); Hsin-Wen Kung (Taipei, TW); Li-Chun Sung (Taipei, TW); Si-Wei Wang (Taipei, TW)
Assignee: Trend Micro, Inc.
G06F21/566G06F9/54G06F18/23213G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,586
App. No.
16/811,651
Granted
Jan 30, 2024
Kind
B1
Abstract

Behavior report generation monitors the behavior of unknown sample files executing in a sandbox. Behaviors are encoded and feature vectors created based upon a q-gram for each sample. Prototypes extraction includes extracting prototypes from the training set of feature vectors using a clustering algorithm. Once prototypes are identified in this training process, the prototypes with unknown labels are reviewed by domain experts who add a label to each prototype. A K-Nearest Neighbor Graph is used to merge prototypes into fewer prototypes without using a fixed distance threshold and then assigning a malware family name to each remaining prototype. An input unknown sample can be classified using the remaining prototypes and using a fixed distance. For the case that no such prototype is close enough, the behavior report of a sample is rejected and tagged as an unknown sample or that of an emerging malware family.

Claims (47)

1. A method of classifying a suspicious file, said method comprising:

determining a plurality of prototype feature vectors, each prototype feature vector having an associated group of feature vectors;

merging said groups of feature vectors into clusters without using a fixed-distance threshold, each of said clusters representing an identified malware family;

creating a feature vector for a behavior report of said suspicious file, said feature vector representing API (application programming interface) calls of said suspicious file;

determining a distance between said feature vector and one of said prototype feature vectors having a first malware family name;

when it is determined that said distance is less than a fixed-distance classification threshold, determining that said suspicious file belongs to said first malware family name; and

taking an action based upon said suspicious file belonging to said first malware family name.

2. A method as recited in claim 1 , further comprising:

determining said plurality of prototype feature vectors based upon a plurality of feature vectors of unknown sample files and using said fixed-distance classification threshold.

3. A method as recited in claim 1 further comprising:

generating said behavior report by executing said suspicious file in a sandbox software application on a computer.

4. A method as recited in claim 1 wherein taking an action includes outputting an alert to a user of a computer that said suspicious file belongs to said first malware family name, blocking said suspicious file from executing on said computer, cleaning said suspicious file from said computer.

5. A method as recited in claim 1 wherein each of said feature vectors is based upon a q-gram of said behavior report.

6. A method as recited in claim 1 further comprising:

encoding said behavior report; and

creating said feature vector from said encoded behavior report.

7. A method as recited in claim 1 further comprising:

displaying using a visualization tool said groups of feature vectors on a computer; and

accepting user input on said computer indicating said clusters of feature vectors.

8. A method as recited in claim 7 wherein said visualization tool is a k-NNG (k-nearest neighbor graph).

9. A method as recited in claim 8 further comprising:

accepting said user input on said computer indicating a value for k in said k-NNG before said accepting.

10. A method of classifying a suspicious file, said method comprising:

determining a plurality of prototype feature vectors that each represent an identified malware family;

creating a feature vector for a behavior report of said suspicious file, said feature vector representing API (application programming interface) calls of said suspicious file;

determining a distance between said feature vector and each of said prototype feature vectors, each of said prototype feature vectors having a malware family name;

determining that each of said distances is greater than a fixed-distance classification threshold;

determining that said suspicious file does not belong to one of said malware family names; and

outputting a result indicating that said suspicious file is an emerging malware family.

11. A method as recited in claim 10 , further comprising:

determining said plurality of prototype feature vectors based upon a plurality of feature vectors of unknown sample files and using said fixed-distance classification threshold.

12. A method as recited in claim 10 further comprising:

generating said behavior report by executing said suspicious file in a sandbox software application on a computer.

13. A method as recited in claim 10 further comprising:

taking an action which includes one of outputting an alert to a user of a computer that said suspicious file belongs to an emerging malware family, blocking said suspicious file from executing on said computer, cleaning said suspicious file from said computer.

14. A method as recited in claim 10 wherein each of said feature vectors is based upon a q-gram of said behavior report.

15. A method as recited in claim 10 further comprising:

encoding said behavior report; and

creating said feature vector from said encoded behavior report.

16. A method as recited in claim 10 wherein each of said prototype feature vectors has an associated group of feature vectors, said method further comprising:

merging said groups of feature vectors into clusters without using a fixed-distance threshold, each of said clusters representing one of said malware family names.

17. A method as recited in claim 16 further comprising: displaying using a visualization tool said groups of feature vectors on a computer; and

accepting user input on said computer indicating said clusters of feature vectors.

18. A method as recited in claim 17 wherein said visualization tool is a k-NNG (k-nearest neighbor graph).

19. A method as recited in claim 18 further comprising:

accepting said user input on said computer indicating a value for k in said k-NNG before said accepting.

20. A method as recited in claim 10 wherein said determining that said suspicious file does not belong is based upon said determining that each of said distances is greater.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2020
From: CHANG, YIN-MING; CHEN, HSING-YUN; KUNG, HSIN-WEN; SUNG, LI-CHUN; WANG, SI-WEI
To: TREND MICRO INC,
Reel/Frame 052042/0342 →
Cited By (6)
US 12,277,223 US 12,418,558 US 12,430,436 US 12,609,944 US 12,645,796 US 12,689,651