IP Library Granted Patent US 12,321,450
Granted Patent B2
US 12,321,450 · App. 18/177,396 · Granted Jun 3, 2025

Antimalware systems and methods using optimal triggering of artificial intelligence modules

Inventors: Radu M. Portase (Cluj-Napoca, RO); Botond Fulop (Cluj-Napoca, RO); Gheorghe F. Hajmasan (Cluj-Napoca, RO)
Assignee: Bitdefender IPR Management Ltd.
G06F21/56G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,450
App. No.
18/177,396
Granted
Jun 3, 2025
Kind
B2
Abstract

Some embodiments determine optimal trigger events for executing a malware-detecting artificial intelligence (AI) module by tracking a performance of the respective module over a lifetime of each software sample of a training corpus. Computational costs associated with the respective AI module may be substantially reduced by executing the respective module only sporadically, in response to detecting an occurrence of one of the identified trigger events. In some embodiments, a malware detector employs multiple AI modules, each having its own specific triggers. The choice of triggers may be updated at any time, without affecting other aspects of the malware detector.

Claims (79)

1. A computer system comprising at least one hardware processor configured to:

determine a trigger event for executing a malware-detecting artificial intelligence (AI) module, wherein determining the trigger event comprises:

determining a plurality of provisional verdicts indicative of whether a training software entity is malicious, each verdict of the plurality of provisional verdicts associated with a distinct event of a plurality of events caused by an execution of the training software entity, and wherein determining each verdict comprises:

updating a feature vector characterizing the training software entity according to the distinct event, and

executing the AI module to determine a respective verdict according to the updated feature vector, and

in response to determining the plurality of provisional verdicts, selecting the trigger event from the plurality of events according to the plurality of provisional verdicts; and

in response to determining the trigger event, configure a malware detector to selectively execute another instance of the AI module in response to an occurrence of the trigger event, to determine whether a target software entity is malicious.

2. The computer system of claim 1 , wherein the at least one hardware processor is further configured to:

determine another trigger event for executing the AI module by selecting the other trigger event from the plurality of events according to the plurality of provisional verdicts; and

configure the malware detector to selectively execute the other instance of the AI module in response to an occurrence of the other trigger event, to determine whether the target software entity is malicious.

3. The computer system of claim 1 , wherein the at least one hardware processor is configured to determine each verdict of the plurality of provisional verdicts according to an order of occurrence of the plurality of events during the execution of the training software entity.

4. The computer system of claim 1 , wherein determining the trigger event further comprises:

determining a malware detection performance of the trigger event over a collection of training software entities, the malware detection performance determined according to another plurality of provisional verdicts, each verdict of the other plurality of provisional verdicts indicating whether a respective entity of the collection is malicious, each verdict of the other plurality of provisional verdicts associated with an occurrence of the trigger event during an execution of the respective entity; and

selecting the trigger event from the plurality of training events further according to the malware detection performance of the trigger event.

5. The computer system of claim 4 , wherein the at least one hardware processor is configured to determine the malware detection performance of the trigger event according to a count of true positive verdicts within the other plurality of provisional verdicts.

6. The computer system of claim 5 , wherein the at least one hardware processor is configured to determine the malware detection performance of the trigger event according to:

2

t

p

2

t

p

+

f

p

+

f

n

,

wherein t p denotes the count of true positive verdicts, f p denotes a count of false positive verdicts, and f n denotes a count of false negative verdicts within the other plurality of provisional verdicts.

7. The computer system of claim 4 , wherein the at least one hardware processor is configured to determine the malware detection performance of the trigger event according to a count of false positive verdicts within the other plurality of provisional verdicts, and further according to a count of false negative verdicts within the other plurality of provisional verdicts.

8. The computer system of claim 1 , wherein configuring the malware detector comprises formulating a specification of the trigger event and transmitting the specification of the trigger event to a client device executing the malware detector.

9. The computer system of claim 8 , wherein the specification of the trigger event further includes a specification of a trigger predicate comprising a condition for executing the other instance of the AI module in response to the occurrence of the trigger event.

10. The computer system of claim 1 , wherein the malware detector comprises a plurality of detection modules including the other instance of the AI module, and wherein selectively executing the other instance of the AI module comprises selecting the other instance of the AI module for execution from the plurality of detection modules in response to the occurrence of the trigger event.

11. A computer security method comprising employing at least one hardware processor of a computer system to:

determine a trigger event for executing a malware-detecting artificial intelligence (AI) module, wherein determining the trigger event comprises:

determining a plurality of provisional verdicts indicative of whether a training software entity is malicious, each verdict of the plurality of provisional verdicts associated with a distinct event of a plurality of events caused by an execution of the training software entity, and wherein determining each verdict comprises:

updating a feature vector characterizing the training software entity according to the distinct event, and

executing the AI module to determine a respective verdict according to the updated feature vector, and

in response to determining the plurality of provisional verdicts, selecting the trigger event from the plurality of events according to the plurality of provisional verdicts; and

in response to determining the trigger event, configure a malware detector to selectively execute another instance of the AI module in response to an occurrence of the trigger event, to determine whether a target software entity is malicious.

12. The method of claim 11 , further comprising employing the at least one hardware processor to:

determine another trigger event for executing the AI module by selecting the other trigger event from the plurality of events according to the plurality of provisional verdicts; and

configure the malware detector to selectively execute the other instance of the AI module in response to an occurrence of the other trigger event, to determine whether the target software entity is malicious.

13. The method of claim 11 , comprising determining each verdict of the plurality of provisional verdicts according to an order of occurrence of the plurality of events during the execution of the training software entity.

14. The method of claim 11 , wherein determining the trigger event further comprises:

determining a malware detection performance of the trigger event over a collection of training software entities, the malware detection performance determined according to another plurality of provisional verdicts, each verdict of the other plurality of provisional verdicts indicating whether a respective entity of the collection is malicious, each verdict of the other plurality of provisional verdicts associated with an occurrence of the trigger event during an execution of the respective entity; and

selecting the trigger event from the plurality of training events further according to the malware detection performance of the trigger event.

15. The method of claim 14 , comprising determining the malware detection performance of the trigger event according to a count of true positive verdicts within the other plurality of provisional verdicts.

16. The method of claim 15 , comprising determining the malware detection performance of the trigger event according to:

2

t

p

2

t

p

+

f

p

+

f

n

,

wherein t p denotes the count of true positive verdicts, f p denotes a count of false positive verdicts, and f n denotes a count of false negative verdicts within the other plurality of provisional verdicts.

17. The method of claim 14 , comprising determining the malware detection performance of the trigger event according to a count of false positive verdicts within the other plurality of provisional verdicts, and further according to a count of false negative verdicts within the other plurality of provisional verdicts.

18. The method of claim 11 , wherein configuring the malware detector comprises formulating a specification of the trigger event and transmitting the specification of the trigger event to a client device executing the malware detector.

19. The method of claim 18 , wherein the specification of the trigger event further includes a specification of a trigger predicate comprising a condition for executing the other instance of the AI module in response to the occurrence of the trigger event.

20. The method of claim 11 , wherein the malware detector comprises a plurality of detection modules including the other instance of the AI module, and wherein selectively executing the other instance of the AI module comprises selecting the other instance of the AI module for execution from the plurality of detection modules in response to the occurrence of the trigger event.

21. A non-transitory computer-readable medium storing instructions which, when executed by at least one hardware processor of a computer system, cause the computer system to:

determine a trigger event for executing a malware-detecting artificial intelligence (AI) module, wherein determining the trigger event comprises:

determining a plurality of provisional verdicts indicative of whether a training software entity is malicious, each verdict of the plurality of provisional verdicts associated with a distinct event of a plurality of events caused by an execution of the training software entity, and wherein determining each verdict comprises:

updating a feature vector characterizing the training software entity according to the distinct event, and

executing the AI module to determine a respective verdict according to the updated feature vector, and

in response to determining the plurality of provisional verdicts, selecting the trigger event from the plurality of events according to the plurality of provisional verdicts; and

in response to determining the trigger event, configure a malware detector to selectively execute another instance of the AI module in response to an occurrence of the trigger event, to determine whether a target software entity is malicious.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: PORTASE, RADU M; FULOP, BOTOND; HAJMASAN, GHEORGHE F
To: BITDEFENDER IPR MANAGEMENT LTD.
Reel/Frame 063445/0599 →
Continuity (1)
Related Publication 20240296222A1 · Sep 5, 2024
References Cited (46)
US 8776231B2 · Moskovitch · 2014 [cited by applicant]
US 9306962B1 · Pinto · 2016 [cited by applicant]
US 10089465B2 · Hajmasan · 2018 [cited by applicant]
US 10282546B1 · Parikh · 2019 [cited by examiner]
US 10417420B2 · Zhang · 2019 [cited by applicant]
US 10867042B2 · Chistyakov · 2020 [cited by applicant]
US 10922604B2 · Zhao · 2021 [cited by examiner]
US 10949534B2 · Martin · 2021 [cited by applicant]
US 11025649B1 · Bilge · 2021 [cited by examiner]
US 11089034B2 · Dichiu · 2021 [cited by applicant]
US 11126720B2 · Miserendino · 2021 [cited by examiner]
US 11153332B2 · Dichiu · 2021 [cited by applicant]
US 11288369B1 · Grzonkowski · 2022 [cited by examiner]
US 11323459B2 · Dichiu · 2022 [cited by applicant]
US 11501120B1 · Petersen · 2022 [cited by examiner]
US 11843622B1 · Tellez · 2023 [cited by examiner]
US 11997131B1 · Sirianni · 2024 [cited by examiner]
US 20090007100A1 · Field · 2009 [cited by applicant]
US 20130247187A1 · Hsiao · 2013 [cited by examiner]
US 20130304677A1 · Gupta · 2013 [cited by applicant]
US 20140187177A1 · Sridhara · 2014 [cited by applicant]
US 20150013007A1 · Hartrell · 2015 [cited by applicant]
US 20160078362A1 · Christodorescu · 2016 [cited by examiner]
US 20170262633A1 · Misrendino · 2017 [cited by applicant]
US 20180018456A1 · Chen · 2018 [cited by examiner]
US 20180041536A1 · Berlin · 2018 [cited by examiner]
US 20180060569A1 · Kim · 2018 [cited by examiner]
US 20190034634A1 · Hajmasan · 2019 [cited by applicant]
US 20190228154A1 · Agrawal · 2019 [cited by examiner]
US 20200167464A1 · Griffin · 2020 [cited by examiner]
US 20200265139A1 · Zhao · 2020 [cited by applicant]
US 20200311262A1 · Nguyen · 2020 [cited by examiner]
US 20210019412A1 · Hewlett · 2021 [cited by applicant]
US 20210037035A1 · Graul · 2021 [cited by examiner]
US 20210326438A1 · Dichiu · 2021 [cited by applicant]
US 20210334371A1 · Ke · 2021 [cited by examiner]
US 20220121744A1 · Mishra · 2022 [cited by applicant]
US 20220164449A1 · Saxe · 2022 [cited by applicant]
US 20220253526A1 · Sanders · 2022 [cited by examiner]
US 20230281315A1 · Capellman · 2023 [cited by examiner]
US 20230344843A1 · Zaytsev · 2023 [cited by examiner]
US 20240004993A1 · Rozenberg · 2024 [cited by examiner]
US 20240031387A1 · Reynolds · 2024 [cited by examiner]
European Patent Office (EPO), International Search Report and Written Opinion mailed May 8, 2024 for PCT International Application No. PCT/EP2024/055331, international filing date Mar. 1, 2024, earliest priority date Ma… [cited by applicant]
Darem et al., “An Adaptive Behavioral-Based Incremental Batch Learning Malware Variants Detection Model Using Concept Drift Detection and Sequential Deep Learning,”, IEEE Access vol. 9 p. 97180-97196,, https://ieeexplor… [cited by applicant]
Darem et al., “An Adaptive Behavioral-Based Incremental Batch Learning Malware Variants Detection Model Using Concept Drift Detection and Sequential Deep Learning,”. [cited by applicant]