IP Library Granted Patent US 12,223,045
Granted Patent B1
US 12,223,045 · App. 17/894,690 · Granted Feb 11, 2025

Protecting customers against supply chain attacks by detecting a behavior change between versions of an application program

Inventors: Shih-Han Hsu (Taipei, TW); Wei-Jen Chang (Taipei, TW); Yao-Tang Chang (Taipei, TW); Yi-Li Cheng (Taipei, TW)
Assignee: VicOne Corporation
G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,045
App. No.
17/894,690
Granted
Feb 11, 2025
Kind
B1
Abstract

Versions of an application program are evaluated to protect a customer from a supply chain attack. The versions of the application program are executed in to identify behaviors exhibited by the versions of the application program, each of the behaviors including activities that perform computer operations. A behavior change is detected by identifying a behavior that is not common to the versions of the application program.

Claims (28)

1. A method of evaluating an application program to protect a customer against a supply chain attack, the method comprising:

executing a first version of the application program to identify a first set of behaviors exhibited by the first version of the application program during execution, each behavior of the first set of behaviors comprising activities that perform computer operations;

executing a second version of the application program to identify a second set of behaviors exhibited by the second version of the application program during execution, each behavior of the second set of behaviors comprising activities that perform computer operations;

identifying a first behavior in the first set of behaviors that is not present in the second set of behaviors;

identifying a second behavior in the second set of behaviors that is not present in the first set of behaviors;

identifying a third behavior in the first set of behaviors that is not present in the second set of behaviors;

merging the second behavior and the third behavior together in response to determining that the second behavior is similar to the third behavior;

after merging the second behavior and the third behavior together, detecting a behavior change of the application program in response to identifying the first behavior; and

issuing a behavior change notification in response to detecting the behavior change of the application program.

2. The method of claim 1 , further comprising, before detecting the behavior change of the application program:

identifying the second behavior in the second set of behaviors that is not present in the first set of behaviors;

determining that the first behavior is not similar to the second behavior.

3. The method of claim 2 , wherein each behavior in the first and second set of behaviors is represented as a vector and determining that the first behavior is not similar to the second behavior includes calculating a distance between a first vector that represents the first behavior and a second vector that represents the second behavior.

4. The method of claim 1 , wherein the application program is provided by a supplier to the customer over the Internet.

5. The method of claim 4 , wherein the first and second versions of the application program are evaluated in an evaluation system that is external to the supplier and the customer.

6. A method of evaluating an application program to protect a customer against a supply chain attack, the method comprising:

executing a first version of the application program to detect a plurality of activities of the first version of the application program that perform computer operations;

representing the plurality of activities as a plurality of activity vectors;

clustering the plurality of activity vectors into a plurality of clusters, a center of each cluster being designated as a behavior vector that represents a behavior of the first version of the application program;

receiving a second version of the application program;

identifying a first behavior vector of the second version of the application program that is not common to both the first and second versions of the application program;

identifying a second behavior vector of the second version of the application program that is not common to both the first and second versions of the application program;

identifying a first behavior vector of the first version of the application program that is not common to both the first and second versions of the application program;

merging the second behavior vector of the second version of the application program and the first behavior vector of the first version of the application program to generate a behavior vector that is common to both the first and second versions of the application program in response to determining that the second behavior vector of the second version of the application program is within a predetermined distance to the first behavior vector of the first version of the application program; and

after merging the second behavior vector of the second version of the application program and the first behavior vector of the first version of the application program, detecting a behavior change of the application program in response to identifying the first behavior vector of the second version of the application program that is not common to both the first and second versions of the application program.

7. The method of claim 6 , further comprising, before detecting the behavior change of the application program,

determining that the first behavior vector of the first version of the application program is not within a predetermined distance to the first behavior vector of the second application program.

8. The method of claim 6 , wherein the application program is provided by a supplier to the customer over the Internet.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2023
From: TREND MICRO INCORPORATED; VICONE CORPORATION
To: VICONE CORPORATION
Reel/Frame 064668/0813 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2022
From: HSU, SHIH-HAN; CHANG, WEI-JEN; CHANG, YAO-TANG; CHENG, YI-LI
To: TREND MICRO INCORPORATED
Reel/Frame 061217/0547 →
References Cited (15)
US 11455400B2 · Fox · 2022 [cited by examiner]
US 12019749B2 · Yerra · 2024 [cited by examiner]
US 20190138717A1 · Ben-Shalom · 2019 [cited by examiner]
US 20190319977A1 · Gottschlich · 2019 [cited by examiner]
US 20210056209A1 · Fox · 2021 [cited by examiner]
US 20230259620A1 · Schaefer · 2023 [cited by examiner]
David et al., “DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification”, International Joint Conference on Neural Networks (IJCNN), Oct. 18, 2016, DOI: 10.1109/IJCNN.2015.7280815. [cited by applicant]
Pan et al., “Malware Classification Based on the Behavior Analysis and Back Propagation Neural Network”, ITM Web of Conferences, Nov. 21, 2016, pp. 1.5, DOI:10.1051/itmconf/20160702001. [cited by applicant]
Sutskever et al., “Sequence to Sequence Learning with Neural Networks”, Advances in Nueral Information Processing Systems27 (NeurIPS Proceedings 2014), Dec. 14, 2014, ISBN: 9781510800410. [cited by applicant]
“DBSCAN”, Wikipedia, last edited Apr. 24, 2022, https://en.wikipedia.org/w/index.php?title=DBSCAN&oldid=1084395414. [cited by applicant]
“Dimensionality reduction”, Wikipedia, last edited Jul. 1, 2022, https://en.wikipedia.org/w/index.php?title=Dimensionality_reduction&oldid=1096032691. [cited by applicant]
“Jaccard index”, Wikipedia, last edited Jun. 19, 2022, https://en.wikipedia.org/w/index.php?title=Jaccard_index&oldid=1093922825. [cited by applicant]
Trinius et al, “A Malware Instruction Set for Behavior-Based Analysis”, pp. 1-11, University of Mannheim, Germany. [cited by applicant]
Process Status API, Microsoft, Jul. 27, 2022, https://learn.microsoft.com/en-us/windows/win32/api/_psapi/. [cited by applicant]
“Word embedding”, Wikipedia, Nov. 2022, https://en.wikipedia.org/wiki/Word_embedding. [cited by applicant]