IP Library Granted Patent US 12,282,555
Granted Patent B2
US 12,282,555 · App. 18/645,717 · Granted Apr 22, 2025

Multi-dimensional malware analysis

Inventors: Steven Grobman (El Dorado Hills, CA); Jonathan B. King (Hillsboro, OR); Yonghong Huang (Portland, OR); Amit Kumar (Bangalore, IN)
Assignee: McAfee, LLC
G06F21/566G06F21/54G06F21/568G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,555
App. No.
18/645,717
Granted
Apr 22, 2025
Kind
B2
Abstract

There is disclosed a computer-implemented system and method of analyzing a batch of objects, including bucketizing the batch of objects into a plurality of buckets according to a feature of the objects; for objects within a batch, performing malware analysis on the objects to assign a malware analysis score, and adjusting the malware analysis score based on the batch; and performing respective security actions on the objects within the batch, based on the adjusted malware analysis score.

Claims (32)

1. A computer-implemented method of analyzing a batch of objects, comprising:

bucketizing the batch of objects into a plurality of buckets according to a feature of the objects;

for objects within a batch, performing malware analysis on the objects to assign a malware analysis score, and adjusting the malware analysis score based on the batch; and

performing respective security actions on the objects within the batch, based on the adjusted malware analysis score.

2. The computer-implemented method of claim 1 , wherein the malware analysis is static analysis.

3. The computer-implemented method of claim 1 , wherein the malware analysis is dynamic analysis.

4. The computer-implemented method of claim 1 , wherein bucketizing the batch of objects comprises computing a set of probablistic curves associated with the feature.

5. The computer-implemented method of claim 1 , wherein bucketizing the batch of objects comprises computing bucketized predictions for the objects.

6. The computer-implemented method of claim 1 , wherein the feature is a predicted reputation for an object.

7. The computer-implemented method of claim 1 , wherein the feature is a reputation for a uniform resource locator (URL) or internet protocol (IP) address associated with an object.

8. The computer-implemented method of claim 1 , wherein the feature comprises certificate reputation for an object.

9. The computer-implemented method of claim 1 , wherein adjusting the malware analysis score comprises looking up an adjustment in an adjustment table.

10. The computer-implemented method of claim 9 , wherein the adjustment table is bucketized.

11. The computer-implemented method of claim 9 , wherein looking up the adjustment comprises querying a second computing apparatus.

12. The computer-implemented method of claim 9 , wherein looking up the adjustment comprises querying a cloud service.

13. The computer-implemented method of claim 1 , wherein the malware analysis score is normalized to between 1 and 0.

14. The computer-implemented method of claim 13 , wherein a threshold to detect an object as malware is approximately 0.5.

15. The computer-implemented method of claim 1 , wherein performing respective security action based on the adjusted malware analysis score comprises comparing the adjusted malware analysis score to a malware threshold.

16. One or more tangible, nontransitory computer-readable storage media having stored thereon executable instructions to analyze a batch of object, the instructions to:

bucketize the batch of objects into a plurality of buckets according to a feature of the objects;

for objects within a batch, perform malware analysis on the objects to assign a malware analysis score, and adjust the malware analysis score based on the batch; and

perform respective security actions on the objects within the batch, based on the adjusted malware analysis score.

17. The one or more tangible, nontransitory computer-readable storage media of claim 16 , wherein the malware analysis is static analysis.

18. The one or more tangible, nontransitory computer-readable storage media of claim 16 , wherein the malware analysis is dynamic analysis.

19. A computing apparatus, comprising:

a hardware platform comprising a processor circuit and a memory; and

instructions encoded within the memory to instruct the processor circuit to:

receive a batch of objects;

bucketize the batch of objects into a plurality of buckets according to a feature of the objects;

for objects within a batch, perform malware analysis on the objects to assign a malware analysis score, and adjust the malware analysis score based on the batch; and

perform respective security actions on the objects within the batch, based on the adjusted malware analysis score.

20. The computing apparatus of claim 19 , wherein the malware analysis is static analysis.

Priority Claims (1)
IN 202041039840 · Sep 15, 2020 · national
Continuity (3)
Continuation 17978624 · Nov 1, 2022
Continuation 17083457 · Oct 29, 2020
Related Publication 20240289460A1 · Aug 29, 2024
References Cited (4)
US 11003773B1 · Fang · 2021 [cited by examiner]
US 11170104B1 · Stickle · 2021 [cited by examiner]
US 20160226904A1 · Bartos · 2016 [cited by examiner]
US 20210303675A1 · Petersen · 2021 [cited by examiner]