IP Library › Granted Patent US 12,111,930
Granted Patent B2
US 12,111,930 · App. 17/818,262 · Granted Oct 8, 2024

Utilizing machine learning to detect ransomware in code

Inventors: Maha Nasser Alasmari (Al Khobar, SA); Abdullah Abdulaziz Alturaifi (Dhahran, SA); Sultan Saadaldean Alsharif (Al Khobar, SA)
Assignee: Saudi Arabian Oil Company
G06F21/566G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,111,930
App. No.
17/818,262
Granted
Oct 8, 2024
Kind
B2
Abstract

Implementations can provide a method that includes: accessing the source code of a script hosted by a remote server; extracting features from the source code in accordance with a machine-learning model comprising one or more layers of logic; at least based on the machine-learning model, determining, for each of the extracted features, a corresponding probability conditioned on the source code containing ransomware; and at least based on the machine-learning model, determining a combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present; comparing the combined probability with a threshold; in response to determining that the combined probability exceeds the threshold, flagging the source code as containing ransomware; and in response to determining that the combined probability does not exceed the threshold, flagging the source code as not containing ransomware.

Claims (59)

1. A computer-implemented method for screening a source code for ransomware before the source code can be executed by a local computer, the method comprising:

accessing the source code of a script hosted by a remote server;

extracting features from the source code in accordance with a machine-learning model comprising one or more layers of logic;

at least based on the machine-learning model, determining, for each of the extracted features, a corresponding probability conditioned on the source code containing ransomware; and

at least based on the machine-learning model, determining a combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present;

comparing the combined probability with a threshold;

in response to determining that the combined probability exceeds the threshold, flagging the source code as containing ransomware; and

in response to determining that the combined probability does not exceed the threshold, flagging the source code as not containing ransomware.

2. The computer-implemented method of claim 1 , wherein extracting features comprises: extracting keywords corresponding to at least one category of: a file input/output (IO) operation, a cryptography operation, a key generating operation, and a data communication operation, and

wherein the keywords are combined to be processed through the one or more layers of logic of the machine-learning model.

3. The computer-implemented method of claim 1 , further comprising:

at least based on the model, determining, for each of the extracted features, a corresponding probability conditioned on the source code not containing ransomware.

4. The computer-implemented method of claim 3 , further comprising:

at least based on the model, determining a combined probability for the extracted features conditioned on the source code not containing ransomware when the extracted features are jointly present.

5. The computer-implemented method of claim 4 , wherein comparing the combined probability with a threshold comprises:

comparing the combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present with the combined probability for the extracted features conditioned on the source code not containing ransomware when the extracted features are jointly present.

6. The computer-implemented method of claim 1 , further comprising:

in response to flagging the source code as containing ransomware, blocking the script from execution by the local computer.

7. The computer-implemented method of claim 1 , further comprising:

in response to flagging the source code as containing ransomware, blacklisting the remote server hosting the script.

8. A computer system for screening a source code for ransomware, the computer system comprising one or more processors configured to perform operations of:

accessing the source code of a script hosted by a remote server;

extracting features from the source code in accordance with a machine-learning model comprising one or more layers of logic;

at least based on the machine-learning model, determining, for each of the extracted features, a corresponding probability conditioned on the source code containing ransomware; and

at least based on the machine-learning model, determining a combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present;

comparing the combined probability with a threshold;

in response to determining that the combined probability exceeds the threshold, flagging the source code as containing ransomware; and

in response to determining that the combined probability does not exceed the threshold, flagging the source code as not containing ransomware.

9. The computer system of claim 8 , wherein extracting features comprises: extracting keywords corresponding to at least one category of: a file input/output (IO) operation, a cryptography operation, a key generating operation, and a data communication operation, and

wherein the keywords are combined to be processed through the one or more layers of logic of the machine-learning model.

10. The computer system of claim 8 , wherein the operations further comprise:

at least based on the model, determining, for each of the extracted features, a corresponding probability conditioned on the source code not containing ransomware when the feature is present.

11. The computer system of claim 10 , wherein the operations further comprise:

at least based on the model, determining a combined probability for the extracted features conditioned on the source code not containing ransomware when the extracted features are jointly present.

12. The computer system of claim 11 , wherein comparing the combined probability with a threshold comprises:

comparing the combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present with the combined probability for the extracted features conditioned on the source code not containing ransomware when the extracted features are jointly present.

13. The computer system of claim 8 , wherein the operations further comprise:

in response to flagging the source code as containing ransomware, blocking the script from execution by a local computer.

14. The computer system of claim 8 , wherein the operations further comprise:

in response to flagging the source code as containing ransomware, blacklisting the remote server hosting the script.

15. A non-transitory computer-readable medium comprising software, which, when executed by a computer, causes the computer to execute operations of:

accessing the source code of a script hosted by a remote server;

extracting features from the source code in accordance with a machine-learning model comprising one or more layers of logic;

at least based on the machine-learning model, determining, for each of the extracted features, a corresponding probability conditioned on the source code containing ransomware; and

at least based on the machine-learning model, determining a combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present;

comparing the combined probability with a threshold;

in response to determining that the combined probability exceeds the threshold, flagging the source code as containing ransomware; and

in response to determining that the combined probability does not exceed the threshold, flagging the source code as not containing ransomware.

16. The non-transitory computer-readable medium of claim 15 , wherein extracting features comprises: extracting keywords corresponding to at least one category of: a file input/output (IO) operation, a cryptography operation, a key generating operation, and a data communication operation, and

wherein the keywords are combined to be processed through the one or more layers of logic of the machine-learning model.

17. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

at least based on the model, determining, for each of the extracted features, a corresponding probability conditioned on the source code not containing ransomware when the feature is present.

18. The non-transitory computer-readable medium of claim 17 , wherein the operations further comprise:

at least based on the model, determining a combined probability for the extracted features conditioned on the source code not containing ransomware when the extracted features are jointly present.

19. The non-transitory computer-readable medium of claim 18 , wherein comparing the combined probability with a threshold comprises:

comparing the combined probability for the extracted features conditioned on the source code containing ransomware when the extracted features are jointly present with the combined probability for the extracted features conditioned on the source code not containing ransomware when the extracted features are jointly present.

20. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

in response to flagging the source code as containing ransomware, blocking the script from execution by a local computer; and

in response to flagging the source code as containing ransomware, blacklisting the remote server hosting the script.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2022
From: ALASMARI, MAHA NASSER; ALTURAIFI, ABDULLAH ABDULAZIZ; ALSHARIF, SULTAN SAADALDEAN
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 060755/0197 →
Continuity (1)
Related Publication 20240045957A1 · Feb 8, 2024
Cited By (2)
US 12,602,309 US 12,737,279