IP Library › Granted Patent US 12,432,225
Granted Patent B2
US 12,432,225 · App. 17/702,687 · Granted Sep 30, 2025

Inline malware detection

Inventors: William Redington Hewlett, II (Mountain View, CA); Suiqiang Deng (Fremont, CA); Sheng Yang (Santa Clara, CA); Ho Yu Lam (Santa Clara, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1416G06N5/022H04L63/0227H04L63/145H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,225
App. No.
17/702,687
Granted
Sep 30, 2025
Kind
B2
Abstract

Detection of malicious files is disclosed. A set comprising a plurality of sample classification models is received and stored. A determination is made that n-gram analysis should be performed on a sequence of received packets associated with a received file. Performing the n-gram analysis includes using a determined filetype associated with the sequence of received packets to select at least one stored sample classification model included in the set for use in performing the n-gram analysis. A determination is made that the received file is malicious based at least in part on the n-gram analysis of the sequence of received packets. In response to determining that the file is malicious, propagation of the received file is prevented.

Claims (54)

1. A system, comprising:

a processor configured to:

receive and store a set comprising a plurality of sample classification models;

receive an indication that a file, having an associated transmitting device, and intended for a transmittee, is being transmitted as part of a network session comprising a sequence of packets, including by using a protocol decoder to detect a start of the file in a first portion of the sequence of packets of the network session;

perform n-gram analysis on a second portion of the sequence of received packets of the network session, wherein performing the n-gram analysis includes using a determined filetype associated with the sequence of received packets to select at least one stored sample classification model included in the set for use in performing the n-gram analysis, and wherein the n-gram analysis continues until a predetermined end-of-file criteria is met, wherein the criteria comprises at least one of: (1) an end-of-file context previously marked by the protocol decoder or (2) a predetermined, purported end-of-file is reached; and

determine, during the performing of the n-gram analysis on the second portion of the sequence of received packets of the network session, that the file is malicious based at least in part on the n-gram analysis of the second portion of the sequence of received packets, and in response to determining that the file is malicious, take a remedial action, including against the associated transmitting device;

wherein the maliciousness determination is made, during active transmission of the file transmission and before the file transmission is complete, without requiring that the entire sequence of received packets be subjected to n-gram analysis; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is configured to perform the n-gram analysis at least in part by comparing n-grams in the received packets against a predetermined list of n-grams.

3. The system of claim 2 , wherein the predetermined list of n-grams was generated using a plurality of previously collected malware samples.

4. The system of claim 1 , wherein the processor is configured to select, from the plurality of sample classification models, a linear classification model, based on the determined filetype associated with the sequence of received packets.

5. The system of claim 1 , wherein performing the n-gram analysis includes accumulating a set of weights corresponding to observed n-grams.

6. The system of claim 5 , wherein the set of weights are accumulated in a single float value.

7. The system of claim 1 , wherein the processor is configured to select, from the plurality of sample classification models, a non-linear classification model, based on the determined filetype associated with the sequence of received packets.

8. The system of claim 7 , wherein the non-linear classification model includes n-gram features and non n-gram features.

9. The system of claim 8 , wherein at least one non n-gram feature is associated with a file size.

10. The system of claim 8 , wherein at least one non n-gram feature is associated with a presence of an overlay.

11. The system of claim 1 , wherein performing the n-gram analysis includes updating a value for a feature in a feature vector whenever the feature is matched.

12. The system of claim 1 , wherein the end-of-file context is a purported file length that is not an actual file length and the determination is made prior to reaching an actual end of the file.

13. The system of claim 1 , wherein the processor is further configured to receive at least one updated classification model.

14. The system of claim 1 , wherein the n-gram analysis is performed inline with other types of packet analyses as a single pass analysis.

15. The system of claim 1 , wherein the processor is further configured to use a set of whitelisted n-grams when performing the n-gram analysis.

16. The system of claim 1 , wherein the processor is further configured to transmit a copy of the file to a security platform and perform the n-gram analysis while awaiting a verdict from the security platform.

17. The system of claim 1 , wherein the remedial action comprises terminating the session.

18. The system of claim 1 , wherein the remedial action comprises placing the file in a quarantine area.

19. A method for evaluating and selectively blocking network traffic, comprising:

receiving and storing a set comprising a plurality of sample classification models;

receiving an indication that a file, having an associated transmitting device, and intended for a transmittee, is being transmitted as part of a network session comprising a sequence of packets, including by using a protocol decoder to detect a start of the file in a first portion of the sequence of packets of the network session;

performing n-gram analysis on a second portion of the sequence of received packets of the network session, wherein performing the n-gram analysis includes using a determined filetype associated with the sequence of received packets to select at least one stored sample classification model included in the set for use in performing the n-gram analysis, and wherein the n-gram analysis continues until a predetermined end-of-file criteria is met, wherein the criteria comprises at least one of: (1) an end-of file context previously marked by the protocol decoder or (2) a predetermined, purported end-of-file is reached; and

determining, during the performing of the n-gram analysis on the second portion of the sequence of received packets of the network session, that the file is malicious based at least in part on the n-gram analysis of the second portion of the sequence of received packets, and in response to determining that the file is malicious, taking a remedial action, including against the associated transmitting device;

wherein the maliciousness determination is made, during active transmission of the file transmission and before the file transmission is complete, without requiring that the entire sequence of received packets be subjected to n-gram analysis.

20. The method of claim 19 , wherein performing the n-gram analysis includes comparing n-grams in the received packets against a predetermined list of n-grams.

21. The method of claim 20 , wherein the predetermined list of n-grams was generated using a plurality of previously collected malware samples.

22. The method of claim 19 , wherein selecting the at least one stored sample classification model includes selecting a linear classification model based on the determined filetype associated with the sequence of received packets.

23. The method of claim 19 , wherein performing the n-gram analysis includes accumulating a set of weights corresponding to observed n-grams.

24. The method of claim 23 , wherein the set of weights are accumulated in a single float value.

25. The method of claim 19 , wherein selecting the at least one stored sample classification model includes selecting a non-linear classification model based on the determined filetype associated with the sequence of received packets.

26. The method of claim 25 , wherein the non-linear classification model includes n-gram features and non n-gram features.

27. The method of claim 26 , wherein at least one non n-gram feature is associated with a file size.

28. The method of claim 26 , wherein at least one non n-gram feature is associated with a presence of an overlay.

29. The method of claim 19 , wherein performing the n-gram analysis includes updating a value for a feature in a feature vector whenever the feature is matched.

30. The method of claim 19 , wherein the end-of-file context is a purported file length that is not an actual file length and the determination is made prior to reaching an actual end of the file.

31. The method of claim 19 , further comprising receiving at least one updated classification model.

32. The method of claim 19 , wherein the n-gram analysis is performed inline with other types of packet analyses as a single pass analysis.

33. The method of claim 19 , further comprising using a set of whitelisted n-grams when performing the n-gram analysis.

34. The method of claim 19 , further comprising transmitting a copy of the received file to a security platform and performing the n-gram analysis while awaiting a verdict from the security platform.

35. The method of claim 19 , wherein the remedial action comprises terminating the session.

36. The method of claim 19 , wherein the remedial action comprises placing the file in a quarantine area.

37. A computer program product comprising non-transitory computer readable storage medium and comprising computer instructions for:

receiving and storing a set comprising a plurality of sample classification models;

receiving an indication that a file, having an associated transmitting device, and intended for a transmittee, is being transmitted as part of a network session comprising a sequence of packets, including by using a protocol decoder to detect a start of the file in a first portion of the sequence of packets of the network session;

performing n-gram analysis on a second portion of the sequence of received packets of the network session, wherein performing the n-gram analysis includes using a determined filetype associated with the sequence of received packets to select at least one stored sample classification model included in the set for use in performing the n-gram analysis, and wherein the n-gram analysis continues until a predetermined end-of-file criteria is met, wherein the criteria comprises at least one of: (1) an end-of-file context previously marked by the protocol decoder or (2) a predetermined, purported end-of-file is reached; and

determining, during the performing of the n-gram analysis on the second portion of the sequence of received packets of the network session, that the file is malicious based at least in part on the n-gram analysis of the second portion of the sequence of received packets, and in response to determining that the file is malicious, taking a remedial action, including against the associated transmitting device;

wherein the maliciousness determination is made, during active transmission of the file transmission and before the file transmission is complete, without requiring that the entire sequence of received packets be subjected to n-gram analysis.

Continuity (2)
Continuation 16517463 · Jul 19, 2019
Related Publication 20220217164A1 · Jul 7, 2022
References Cited (65)
US 7792850B1 · Raffill · 2010 [cited by applicant]
US 9037967B1 · Al-Jefri · 2015 [cited by examiner]
US 9396334B1 · Ivanov · 2016 [cited by applicant]
US 10681080B1 · Chen · 2020 [cited by examiner]
US 10878124B1 · Sitaraman · 2020 [cited by applicant]
US 10942963B1 · Huang · 2021 [cited by applicant]
US 20050256716A1 · Bangalore · 2005 [cited by applicant]
US 20060037080A1 · Maloof · 2006 [cited by applicant]
US 20090319536A1 · Parker · 2009 [cited by applicant]
US 20100064369A1 · Stolfo · 2010 [cited by examiner]
US 20110126286A1 · Nazarov · 2011 [cited by applicant]
US 20110320498A1 · Flor · 2011 [cited by examiner]
US 20120317644A1 · Kumar · 2012 [cited by applicant]
US 20140033307A1 · Schmidtler · 2014 [cited by applicant]
US 20140223565A1 · Cohen · 2014 [cited by applicant]
US 20150244730A1 · Vu · 2015 [cited by applicant]
US 20170004306A1 · Zhang · 2017 [cited by applicant]
US 20170085585A1 · Morkovský · 2017 [cited by applicant]
US 20170262633A1 · Miserendino · 2017 [cited by examiner]
US 20180013772A1 · Schmidtler · 2018 [cited by applicant]
US 20180048659A1 · Salsamendi · 2018 [cited by applicant]
US 20180089365A1 · Beal · 2018 [cited by applicant]
US 20180203998A1 · Maisel · 2018 [cited by applicant]
US 20180293381A1 · Tseng · 2018 [cited by applicant]
US 20180300482A1 · Li · 2018 [cited by examiner]
US 20190034632A1 · Tsao · 2019 [cited by applicant]
US 20190087574A1 · Schmidtler · 2019 [cited by applicant]
US 20190095820A1 · Pourmohammad · 2019 [cited by applicant]
US 20190096214A1 · Pourmohammad · 2019 [cited by applicant]
US 20190180175A1 · Meteer · 2019 [cited by applicant]
US 20190354682A1 · Finkelshtein · 2019 [cited by applicant]
US 20200067861A1 · Leddy · 2020 [cited by examiner]
US 20200076835A1 · Ladnai · 2020 [cited by examiner]
US 20200097655A1 · Rihn · 2020 [cited by applicant]
US 20200125728A1 · Savir · 2020 [cited by applicant]
US 20200213325A1 · Scherman · 2020 [cited by applicant]
US 20200364334A1 · Pevny · 2020 [cited by applicant]
US 20210019408A1 · Chrysaidos · 2021 [cited by examiner]
US 20210224534A1 · Miller · 2021 [cited by examiner]
CN 102779249 · 2015 [cited by applicant]
CN 103618744 · 2017 [cited by applicant]
EP 2182458 · 2010 [cited by applicant]
JP 2012003463 · 2012 [cited by applicant]
WO 2010011411 · 2010 [cited by applicant]
WO 2020006415 · 2020 [cited by applicant]
WO WO2020006415A1 · 2020 [cited by examiner]
Chen et al., TinyDroid: A Lightweight and Efficient Model for Android Malware Detection and Classification, Mobile Information Systems, 2018, vol. 2018. [cited by applicant]
Hadžiosmanović et al., N-Gram Against the Machine: On the Feasibility of the N-Gram Network Analysis for Binary Protocols, International Workshop on Recent Advances in Intrusion Detection, 2012, pp. 354-373. [cited by applicant]
Kang et al., N-gram Opcode Analysis for Android Malware Detection, Intl. Journal on Cyber Situational Awareness, 2016, vol. 1, No. 1. [cited by applicant]
Li et al., Fileprints: Identifying File Types by n-gram Analysis, Proceedings of the 2005 IEEE Workshop on Information Assurance, Jun. 2005. [cited by applicant]
Oza et al., HTTP Attack Detection Using N-Gram Analysis, Computers & Security 45, 2014, pp. 242-254. [cited by applicant]
Pektas et al., Proposal of N-gram Based Algorithm for Malware Classification, The Fifth International Conference on Emerging Security Information, Systems and Technologies, Aug. 2011, pp. 7-13. [cited by applicant]
Raff et al., Hash-Grams: Faster N-Gram Features for Classification and Malware Detection, Proceedings of the ACM Symposium on Document Engineering, Jul. 2018, ACM. [cited by applicant]
Santos et al., N-Grams-Based File Signatures for Malware Detection, ICEIS, 2009, pp. 317-320. [cited by applicant]
Shafiq et al, Embedded Malware Detection Using Markov n-Grams, Proceedings of the 5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Jul. 2008, pp. 88-107, Springer-Verlag. [cited by applicant]
Adityaram et al. : “HTTP Attack Detection using N-gram Analysis HTTP Attack Detection using N-gram Analysis”, San Jose State University, May 1, 2013 (May 1, 2013), Retrieved from the Internet: URL:https://scholarworks.s… [cited by applicant]
Li et al., “Fileprints: Identifying File Types by N-Gram Analysis”, Systems, Man and Cybernetics (SMC) Information Assurance Workshop, 200 5, Proceedings From the Sixth Annual IEEE, Jun. 15-17, 2005, Jun. 15, 2005 (Jun.… [cited by applicant]
Wressnegger et al. : “A Close Look on N-Grams in Intrusion Detection”, Artificial Intelligence and Security, ACM, Nov. 4, 2013 (Nov. 4, 2013), pp. 67-76. [cited by applicant]
Beebe et al., “Sceadan: Using Concatenated N-Gram Vectors for Improved File and Data Type Classification”, IEEE Transactions on Information Forensics and Security, IEEE, USA, vol. 8, No. 9, Sep. 1, 2013 (Sep. 1, 2013), … [cited by applicant]
Gil et al., “Mal-ID: Automatic Malware Detection Using Common Segment Analysis and Meta-Features”, Journal of Machine Learning Research, Feb. 28, 2012 (Feb. 28, 2012), pp. 1-33. [cited by applicant]
Lin et al., “Feature Selection and Extraction for Malware Classification”, Journal of Information Science and Engineering, vol. 31, Jan. 1, 2015 (Jan. 1, 2015), pp. 965-992. [cited by applicant]
Mas'Ud et al., “A Comparative Study on Feature Selection Method for N-gram Mobile Malware Detention”, International Journal of Network Security, Sep. 30, 2017, pp. 727-733. [cited by applicant]
Chew et al., Latent Morpho-Semantic Analysis: Multilingual Information Retrieval with Character N-Grams and Mutual Information; Proceedings of the 22nd International Conference on Computational Linguistics (Coling 2008)… [cited by applicant]
Beebe et al., Sceadan: Using Concatenated N-Gram Vectors for Improved File and Data Type Classification, IEEE Transactions on Information Forensics and Security, Dec. 31, 2013, pp. 1519-1530. [cited by applicant]
Li et al., Fileprints: Identifying File Types by n-gram Analysis, Proceedings of the 2005 IEEE Workshop on Information Assurance and Security, pp. 64-71. [cited by applicant]