IP Library › Granted Patent US 12,455,814
Granted Patent B2
US 12,455,814 · App. 18/345,228 · Granted Oct 28, 2025

Grayware analysis

Inventors: Md Sajidul Islam Sajid (Charlotte, NC); Frederico Araujo (Mahopac, NY); Teryl Paul Taylor (Colorado Springs, CO); Jiyong Jang (Chappaqua, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F11/3698G06F21/53G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,455,814
App. No.
18/345,228
Granted
Oct 28, 2025
Kind
B2
Abstract

Methods and systems for grayware analysis include running a software application in a sandbox. Activity information is collected from the software application that represents actions performed by the software application within an environment of the sandbox. The collected activity information is matched to a grayware activity description to identify the software application as performing a grayware activity. A corrective action is performed on the software application.

Claims (32)

1 . A computer-implemented method for grayware analysis, comprising:

mapping a set of grayware activity descriptions to grayware categories using linguistic vector analysis;

running a software application in a sandbox;

collecting activity information from the software application that represents actions performed by the software application within an environment of the sandbox;

matching the collected activity information to a grayware activity description to identify the software application as performing a grayware activity; and

performing a corrective action on the software application that is tailored to the grayware activity, to limit an impact of the grayware activity without stopping the software application from running otherwise.

2 . The method of claim 1 , wherein mapping includes forming a document-term matrix from the set of grayware activity descriptions, with rows of the document-term matrix representing respective grayware activity descriptions and with columns of the document-term matrix representing individual terms.

3 . The method of claim 2 , wherein a category is selected based on the similarity score to determine information about the grayware activity.

4 . The method of claim 1 , wherein mapping includes determining a similarity score between a vector representing a grayware activity description and a vector representing a category of grayware behavior.

5 . The method of claim 1 , further comprising downloading the software application from a remote app store prior to running.

6 . The method of claim 5 , wherein performing the corrective action includes disabling access to the software application on the remote app store.

7 . The method of claim 1 , wherein collecting activity information includes monitoring system event logs, network activities, file operations, registry operations, notification activities, and peripheral accesses, and further includes taking periodic screenshots.

8 . The method of claim 1 , wherein matching the collected activity information to a grayware activity description includes comparing the collected activity information to behaviors in an ontology that has descriptions for a plurality of different grayware behavior types to identify a relevant grayware behavior.

9 . A computer program product for grayware analysis, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a hardware processor to cause the hardware processor to:

run a software application in a sandbox;

collect activity information from the software application that represents actions performed by the software application within an environment of the sandbox;

match the collected activity information to a grayware activity description to identify the software application as performing a grayware activity; and

perform a corrective action on the software application that is tailored to the grayware activity, to limit an impact of the grayware activity without stopping the software application from running otherwise.

10 . A system for grayware analysis, comprising:

a hardware processor; and

a memory that stores a computer program which, when executed by the hardware processor, causes the hardware processor to:

wherein the computer program further causes the hardware processor to map a set of grayware activity descriptions to grayware categories using linguistic vector analysis;

ran a software application in a sandbox;

collect activity information from the software, application that represents actions performed by the software application within an environment of the sandbox;

match the collected activity information to a grayware activity description te identify the software application as performing a grayware activity; and

perform a corrective action on the software application that is tailored ta the grayware activity, to limit an impact of the grayware activity without stopping the software application from running otherwise.

11 . The system of claim 10 , wherein the computer program further causes the hardware processor to form a document-term matrix from the set of grayware activity descriptions, with rows of the document-term matrix representing respective gray ware activity descriptions and with columns of the document-term matrix representing individual terms.

12 . The system of claim 11 , wherein a category is selected based on the similarity score to determine information about the grayware activity.

13 . The system of claim 10 , wherein the computer program further causes the hardware processor to determine a similarity score between a vector representing a gray ware activity description and a vector representing a category of grayware behavior.

14 . The system of claim 10 , wherein the computer program further causes the hardware processor to download the software application from a remote app store prior to running.

15 . The system of claim 14 , wherein the computer program further causes the hardware processor to disable access to the software application on the remote app store.

16 . The system of claim 10 , wherein the computer program further causes the hardware processor to monitor system event logs, network activities, file operations, registry operations, notification activities, and peripheral accesses, and further includes taking periodic screenshots.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2023
From: SAJID, MD SAJIDUL ISLAM; ARAUJO, FREDERICO; TAYLOR, TERYL PAUL; JANG, JIYONG
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064127/0623 →
Continuity (1)
Related Publication 20250004922A1 · Jan 2, 2025
References Cited (28)
US 7434218B2 · Fries · 2008 [cited by examiner]
US 7634262B1 · Li · 2009 [cited by examiner]
US 7934261B1 · Saguiguit · 2011 [cited by examiner]
US 8499354B1 · Satish et al. · 2013 [cited by applicant]
US 9083733B2 · Georgiev · 2015 [cited by applicant]
US 9823737B2 · Mazed · 2017 [cited by examiner]
US 9912680B2 · Torres et al. · 2018 [cited by applicant]
US 10230749B1 · Rostami-Hesarsorkh · 2019 [cited by examiner]
US 10305929B2 · Kulkarni et al. · 2019 [cited by applicant]
US 10482250B1 · Joshi · 2019 [cited by examiner]
US 10616267B2 · Bartos et al. · 2020 [cited by applicant]
US 11036856B2 · Graun · 2021 [cited by examiner]
US 11113389B1 · Salehpour · 2021 [cited by examiner]
US 11321453B2 · Kosarev · 2022 [cited by examiner]
US 11405237B2 · Rudnik · 2022 [cited by examiner]
US 20190068641A1 · Araujo · 2019 [cited by examiner]
US 20200210647A1 · Panuganty · 2020 [cited by examiner]
US 20220124102A1 · Zhang et al. · 2022 [cited by applicant]
CN 102082802A · 2011 [cited by applicant]
JP 5851311B2 · 2016 [cited by applicant]
Spreitzenbarth, et al, “Mobile-Sandbox: Having a Deeper Look into Android Applications”, ACM, pp. 1-8 (Year: 2013). [cited by examiner]
Suarez-Tangil, et al, “Evolution, Detection and Analysis of Malware for Smart Devices”, IEEE, pp. 1-27 (Year: 2014). [cited by examiner]
Dunlap et al, “A Study of Application Sandbox Policies in Linux”, ACM, pp. 1-12 (Year: 2022). [cited by examiner]
Guo et al, “The Achieve of Power Manager Application Honey Pot Based on Sandbox”, IEEE, pp. 1-5 (Year: 2015). [cited by examiner]
Blasing et al, “An Android Application Sandbox System for Suspicious Software Detection”, IEEE, pp. 1-8 (Year: 2010). [cited by examiner]
Endicott, S., Attackers are Stealing Data With Fake Microsoft Store App Listings, Retrieved from: https://www.windowscentral.com/attackers-stealing-data-fake-microsoft-store-app-listings, Apr. 21, 2021, 13 pages. [cited by applicant]
Huillet, M., Detected Cryptojacking Prompts Microsoft to Remove Eight Free Apps from Microsoft Store, Retrieved from: https://cointelegraph.com/news/detected-cryptojacking-prompts-microsoft-to-remove-eight-free-apps-fro… [cited by applicant]
Tavares, P., Electron Bot Malware is Disseminated via Microsoft's Official Store And is Capable of Controlling Social Media Apps, Retrieved from: https://www.infosecinstitute.com/resources/malware-analysis/electron-bot-… [cited by applicant]