IP Library › Granted Patent US 12,111,928
Granted Patent B2
US 12,111,928 · App. 18/474,524 · Granted Oct 8, 2024

Utilizing machine learning to detect malicious executable files efficiently and effectively

Inventors: Changsha Ma (Campbell, CA); Nirmal Singh (Mohali, IN); Naveen Selvan (Mohali, IN); Tarun Dewan (Mohali, IN); Uday Pratap Singh (Mohali, IN); Deepen Desai (San Ramon, CA); Bharath Meesala (Bengaluru, IN); Rakshitha Hedge (Bengaluru, IN); Parnit Sainion (Morgan Hill, CA); Shashank Gupta (Sunnyvale, CA); Narinder Paul (Sunnyvale, CA); Rex Shang (Los Altos, CA); Howie Xu (Palo Alto, CA)
Assignee: Zscaler, Inc.
G06F21/565G06F21/53G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,111,928
App. No.
18/474,524
Granted
Oct 8, 2024
Kind
B2
Abstract

Systems and methods include performing inline monitoring of production traffic between users, the Internet, and cloud services via a cloud-based system; utilizing a trained machine learning model to inspect static properties of files in the production traffic; and classifying the traffic as one of malicious or benign based on the trained machine learning model.

Claims (38)

1. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors in a cloud-based system to perform steps of:

responsive to training a machine learning model with a combination of knowledge features and non-knowledge features, wherein the knowledge features include features associated with executable files determined to be effective for training, and wherein non-knowledge features include n-grams, entropy, and file size, receiving the machine learning model;

performing inline monitoring of production traffic between users, the Internet, and cloud services;

utilizing the trained machine learning model to inspect files in the production traffic; and

classifying the traffic as one of malicious or benign based on the trained machine learning model.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the files in the production traffic include executable files.

3. The non-transitory computer-readable storage medium of claim 2 , wherein the classifying includes classifying executable files in the production traffic as being one of malicious or benign.

4. The non-transitory computer-readable storage medium of claim 3 , wherein the executable files are Portable Executable (PE) files.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include:

distributing the trained machine learning model to a plurality of nodes via a central authority.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the steps further include:

obtaining data related to use of the trained machine learning model in production; and

retraining the machine learning model based on the data.

7. A method, implemented in a cloud-based system comprising steps of:

responsive to training a machine learning model with a combination of knowledge features and non-knowledge features, wherein the knowledge features include features associated executable files determined to be effective for training, and wherein non-knowledge features include n-grams, entropy, and file size, receiving the machine learning model;

performing inline monitoring of production traffic between users, the Internet, and cloud services;

utilizing the trained machine learning model to inspect files in the production traffic; and

classifying the traffic as one of malicious or benign based on the trained machine learning model.

8. The method of claim 7 , wherein the files in the production traffic include executable files.

9. The method of claim 8 , wherein the classifying includes classifying executable files in the production traffic as being one of malicious or benign.

10. The method of claim 9 , wherein the executable files are Portable Executable (PE) files.

11. The method of claim 7 , wherein the steps further include:

distributing the trained machine learning model to a plurality of nodes via a central authority.

12. The method of claim 7 , wherein the steps further include:

obtaining data related to use of the trained machine learning model in production; and

retraining the machine learning model based on the data.

13. A server in a cloud-based system comprising:

one or more processors; and

memory storing instructions that, when executed, cause the one or more processors to:

responsive to training a machine learning model with a combination of knowledge features and non-knowledge features, wherein the knowledge features include features associated with executable files determined to be effective for training, and wherein non-knowledge features include n-grams, entropy, and file size, receive the machine learning model;

perform inline monitoring of production traffic between users, the Internet, and cloud services;

utilize the trained machine learning model to inspect files in the production traffic; and

classify the traffic as one of malicious or benign based on the trained machine learning model.

14. The server of claim 13 , wherein the files in the production traffic include executable files.

15. The server of claim 14 , wherein the classifying includes classifying executable files in the production traffic as being one of malicious or benign.

16. The server of claim 15 , wherein the executable files are Portable Executable (PE) files.

17. The server of claim 13 , wherein the instructions further cause the one or more processors to:

distribute the trained machine learning model to a plurality of nodes via a central authority.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2023
From: MA, CHANGSHA; SINGH, NIRMAL; SELVAN, NAVEEN; DEWAN, TARUN; SINGH, UDAY PRATAP; DESAI, DEEPEN; MEESALA, BHARATH; HEDGE, RAKSHITHA; SAINION, PARNIT; GUPTA, SHASHANK; PAUL, NARINDER; SHANG, REX; XU, HOWIE
To: ZSCALER, INC.
Reel/Frame 065027/0318 →
Priority Claims (1)
IN 202011039471 · Sep 11, 2020 · national
Continuity (2)
Continuation 17079809 · Oct 26, 2020
Related Publication 20240028721A1 · Jan 25, 2024
Cited By (2)
US 12,682,053 US 12,711,227