IP Library Granted Patent US 12,399,992
Granted Patent B2
US 12,399,992 · App. 17/663,879 · Granted Aug 26, 2025

Network systems, classification methods, and related apparatuses for security analyses of electronic messages

Inventors: Matthew W. Anderson (Idaho Falls, ID); Matthew R. Sgambati (Rigby, ID); Brandon S. Biggs (Idaho Falls, ID)
Assignee: Battelle Energy Alliance, LLC
G06F21/563G06F8/53G06F9/45558H04L63/02H04L63/20G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,399,992
App. No.
17/663,879
Granted
Aug 26, 2025
Kind
B2
Abstract

Network systems, classification methods, and related apparatuses for security analyses of electronic messages are disclosed. An apparatus includes an input terminal to receive message data corresponding to an electronic message to be delivered to a destination device and processing circuitry. The processing circuitry is configured to, if the electronic message includes an attached file, disassemble the attached file to obtain assembly code from the attached file. The processing circuitry is also configured to translate the assembly code to generate function labels corresponding to functions the assembly code is configured to instruct the destination device to perform. The processing circuitry is further configured to classify the electronic message as anomalous responsive to one or more of the generated function labels being identified as suspicious.

Claims (47)

1. An apparatus, comprising:

an input terminal to receive message data corresponding to an electronic message to be delivered to a destination device; and

processing circuitry configured to, if the electronic message includes one or more attached files:

disassemble the one or more attached files to obtain assembly code from the one or more attached files;

translate the assembly code to generate function labels corresponding to functions the assembly code is configured to instruct the destination device to perform; and

classify the electronic message as anomalous responsive to one or more of the generated function labels being identified as a suspicious function label indicating malicious code in the one or more attached files.

2. The apparatus of claim 1 , wherein the processing circuitry is configured to identify the one or more of the generated function labels as the suspicious function label indicating the malicious code if one of the generated function labels indicates a decrypt function.

3. The apparatus of claim 1 , wherein the processing circuitry is configured to identify the one or more of the generated function labels as the suspicious function label indicating the malicious code if one of the generated function labels indicates a key create function.

4. The apparatus of claim 1 , wherein the processing circuitry is configured to identify the one or more of the generated function labels as the suspicious function label indicating the malicious code if one of the generated function labels indicates a message digest (MD) process block function.

5. The apparatus of claim 1 , wherein the generated function labels include human-readable function labels.

6. The apparatus of claim 1 , wherein the processing circuitry is configured to deliver the electronic message to a virtual machine separated from the destination device by a firewall responsive to a determination that the electronic message is anomalous.

7. The apparatus of claim 1 , wherein if the electronic message includes a link, the processing circuitry is further configured to obtain a link label corresponding to the link.

8. The apparatus of claim 7 , wherein the processing circuitry is configured to determine that the electronic message is anomalous responsive to a determination that the link label is suspicious.

9. The apparatus of claim 8 , wherein the processing circuitry includes a variational autoencoder implemented thereon, the variational autoencoder trained to identify suspicious function labels and suspicious link labels, the processing circuitry configured to provide the generated function labels and the link label, if any, to the variational autoencoder to identify whether the electronic message is anomalous.

10. The apparatus of claim 1 , wherein the processing circuitry includes a machine translator implemented thereon, the machine translator trained to translate the assembly code to the generated function labels.

11. The apparatus of claim 1 , wherein the processing circuitry is configured to provide the generated function labels to a classifier trained to identify suspicious function labels indicating malicious code.

12. The apparatus of claim 11 , wherein the processing circuitry is configured to provide the generated function labels to the classifier trained to identify the suspicious function labels indicating the malicious code comprising malware or ransomware.

13. A network system, comprising:

one or more destination devices;

a network interface configured to receive message data corresponding to an electronic message to be delivered to one of the one or more destination devices;

a network distribution device configured to deliver the received message data to the one of the one or more destination devices responsive to a determination that the electronic message includes neither an attached file nor a link; and

a programmable device including logic circuitry configured to:

translate, if the electronic message includes an attached file, assembly code from the attached file to generate function labels corresponding to functions the assembly code is configured to instruct the one of the one or more destination devices to perform;

classify the electronic message as anomalous responsive to a determination that one or more of the generated function labels include a suspicious function label indicating malicious code in the attached file; and

deliver the electronic message to the one of the one or more destination devices responsive to a classification of the electronic message as not anomalous.

14. The network system of claim 13 , further comprising computing circuitry configured to implement a virtual machine separated from the one of the one or more destination devices by a firewall, wherein the programmable device is configured to deliver the electronic message to the virtual machine responsive to a classification of the electronic message as anomalous.

15. The network system of claim 14 , wherein the virtual machine is configured to interact with the electronic message to determine whether the electronic message includes a threat.

16. The network system of claim 15 , further comprising a firewall exception port communicatively connecting the virtual machine to the one of the one or more destination devices, wherein the virtual machine is configured to deliver the electronic message via the firewall exception port responsive to a determination that the electronic message does not include a threat.

17. The network system of claim 13 , wherein the programmable device including the logic circuitry includes a variational autoencoder implemented thereon, the variational autoencoder trained to identify suspicious function labels indicating malicious code, the programmable device configured to provide the generated function labels to the variational autoencoder to classify the electronic message as anomalous or not anomalous.

18. A classification method, comprising:

determining whether a received electronic message includes an attached file;

disassembling the attached file responsive to a determination that the received electronic message includes the attached file to obtain assembly code from the attached file;

translating the assembly code to generate function labels corresponding to functions the assembly code is configured to instruct a destination device to perform;

classifying the generated function labels, using a variational autoencoder trained to identify suspicious function labels indicating malicious code, as suspicious or not suspicious;

classifying the received electronic message as anomalous responsive to a classification of one or more of the generated function labels of the attached file as suspicious; or

classifying the received electronic message as not anomalous responsive to a classification of the generated function labels of the attached file as not suspicious.

19. The classification method of claim 18 , further comprising:

determining whether the received electronic message includes a link;

assign a link label to the link responsive to a determination that the received electronic message includes the link;

classifying the link label, using the variational autoencoder, as suspicious or not suspicious;

classifying the received electronic message as anomalous responsive to a classification of the link label as suspicious; or

classifying the received electronic message as not anomalous responsive to a classification of the link label as not suspicious.

20. The classification method of claim 18 , further comprising delivering the received electronic message to the destination device responsive to a classification of the received electronic message as not anomalous.

21. The classification method of claim 18 , further comprising sequestering the received electronic message to a virtual machine implemented on computing circuitry separated from the destination device by a firewall responsive to a classification of the received electronic message as anomalous.

22. The classification method of claim 18 , wherein classifying the generated function labels as suspicious comprises identifying one of the generated function labels as a decrypt function.

23. The classification method of claim 18 , further comprising:

sending the generated function labels of the attached file to the variational autoencoder trained to identify the suspicious function labels indicating malicious code.

Assignments (2)
CONFIRMATORY LICENSE Recorded Sep 21, 2022
From: BATTELLE ENERGY ALLIANCE/IDAHO NAT'L LAB
To: UNITED STATES DEPARTMENT OF ENERGY
Reel/Frame 061165/0935 →
NUNC PRO TUNC ASSIGNMENT Recorded May 25, 2022
From: ANDERSON, MATTHEW W.; SGAMBATI, MATTHEW R.; BIGGS, BRANDON S.
To: BATTELLE ENERGY ALLIANCE, LLC
Reel/Frame 060017/0637 →
Continuity (1)
Related Publication 20230409711A1 · Dec 21, 2023
References Cited (47)
US 9032525B2 · Sallam · 2015 [cited by applicant]
US 9721099B2 · Sinclair et al. · 2017 [cited by applicant]
US 10021128B2 · McDougal · 2018 [cited by applicant]
US 10505956B1 · Pidathala · 2019 [cited by examiner]
US 10523609B1 · Subramanian · 2019 [cited by examiner]
US 10581898B1 · Singh · 2020 [cited by examiner]
US 10609050B2 · Caspi et al. · 2020 [cited by applicant]
US 10685293B1 · Heimann et al. · 2020 [cited by applicant]
US 10848519B2 · Howard et al. · 2020 [cited by applicant]
US 10880328B2 · Farhady et al. · 2020 [cited by applicant]
US 11227162B1 · Lu et al. · 2022 [cited by applicant]
US 11537902B1 · Aydore · 2022 [cited by examiner]
US 11556644B1 · Zeppenfeld · 2023 [cited by examiner]
US 11657269B2 · Che et al. · 2023 [cited by applicant]
US 20070112824A1 · Lock · 2007 [cited by examiner]
US 20140095425A1 · Sipple · 2014 [cited by applicant]
US 20180103302A1 · Bell · 2018 [cited by applicant]
US 20190044964A1 · Chari et al. · 2019 [cited by applicant]
US 20190132334A1 · Johns et al. · 2019 [cited by applicant]
US 20190166144A1 · Mirsky et al. · 2019 [cited by applicant]
US 20190228312A1 · Andoni et al. · 2019 [cited by applicant]
US 20190272375A1 · Chen · 2019 [cited by applicant]
US 20190294729A1 · Jiang et al. · 2019 [cited by applicant]
US 20200076840A1 · Peinador et al. · 2020 [cited by applicant]
US 20200076841A1 · Hajimirsadeghi et al. · 2020 [cited by applicant]
US 20200076842A1 · Zhou et al. · 2020 [cited by applicant]
US 20200092311A1 · Avrahami et al. · 2020 [cited by applicant]
US 20200104498A1 · Smith et al. · 2020 [cited by applicant]
US 20200134423A1 · Shinde et al. · 2020 [cited by applicant]
US 20200175161A1 · Giaconi · 2020 [cited by applicant]
US 20200218806A1 · Cho · 2020 [cited by applicant]
US 20200257985A1 · West et al. · 2020 [cited by applicant]
US 20200274787A1 · Dasgupta et al. · 2020 [cited by applicant]
US 20200280573A1 · Johnson et al. · 2020 [cited by applicant]
US 20200364338A1 · Ducau et al. · 2020 [cited by applicant]
US 20210048993A1 · Burke · 2021 [cited by applicant]
US 20210099474A1 · Huang et al. · 2021 [cited by applicant]
US 20220070195A1 · Sern et al. · 2022 [cited by applicant]
US 20220172050A1 · Dalli et al. · 2022 [cited by applicant]
US 20220358214A1 · Anderson · 2022 [cited by examiner]
US 20230027149A1 · Kuan et al. · 2023 [cited by applicant]
US 20230224277A1 · Tarighat · 2023 [cited by applicant]
US 20230379345A1 · Anderson · 2023 [cited by examiner]
US 20240086527A1 · Rosen · 2024 [cited by examiner]
WO 2020159439A1 · 2020 [cited by applicant]
An, J., et al., “Variational Autoencoder Based Anomaly Detection Using Reconstruction Probability,” Special Lecture on IE, Dec. 27, 2015, pp. 18. [cited by applicant]
Artuso, F., et al., “In Nomine Function: Naming Functions in Stripped Binaries with Neural Networks,” Machine Learning, Feb. 4, 2021, pp. 15. [cited by applicant]