IP Library › Granted Patent US 12,596,787
Granted Patent B1
US 12,596,787 · App. 17/978,063 · Granted Apr 7, 2026

Prediction of execution behaviors in sandbox

Inventors: Qiang Huang (Nanjing, CN); Hu Cao (Nanjing, CN); Weichao Dai (Nanjing, CN)
Assignee: Trend Micro Incorporated
G06F21/53G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,787
App. No.
17/978,063
Granted
Apr 7, 2026
Kind
B1
Abstract

A sandbox module on a host computer executes sample programs and includes a dynamic analysis module that collects run-time behaviors of the sample program. A static analysis module collects static behaviors of the sample programs. The behaviors are sent to a recurrent neural network to train one or more models. Each model is trained on a type of sample file. During prediction, the sequence network inputs the behaviors from an unknown sample program. An encoder encodes the behaviors into numerical tuples. A recurrent neural network model inputs the tuples and outputs a predicted behavior of the sample program based upon the tuples. A decoder decodes a numerical tuple representing the predicted behavior and outputs the predicted behavior into a decision engine. The decision engine of the sandbox outputs a decision regarding whether the sample program is malicious or not. Look up tables permit mapping between tuples and the textual behaviors.

Claims (57)

1 . A method of predicting a behavior of a sample program, said method comprising:

executing said sample program in a sandbox module on a host computer;

collecting first behaviors of said sample program using dynamic analysis;

feeding said first behaviors into a model of a recurrent neural network that has been trained to predict behaviors of a computer program;

predicting, by said model, a first predicted behavior of said sample program based upon said first behaviors, wherein said predicting occurs after said collecting and wherein said first predicted behavior is a future behavior at the time of said predicting and is not available from said dynamic analysis;

outputting said first predicted behavior and taking an action upon said sample program based upon said first predicted behavior.

2 . A method as recited in claim 1 wherein said taking an action includes outputting a result that said sample program is malicious software.

3 . A method as recited in claim 1 further comprising:

feeding said first behaviors into a classifier before said feeding into said model in order to select said model of said recurrent neural network based upon a file type of said sample program.

4 . A method as recited in claim 1 further comprising:

outputting said first predicted behavior to a decision engine of said host computer that performs said taking an action based upon a rule of said decision engine.

5 . A method as recited in claim 1 wherein said first predicted behavior is a numerical tuple, said method further comprising:

encoding said first behaviors;

feeding said encoded first behaviors into said model;

decoding said first predicted behavior to produce a textual representation of said predicted behavior.

6 . A method as recited in claim 5 further comprising:

decoding said predicted behavior using a table that maps numerical identifiers of listed behaviors to textual representations of said listed behaviors.

7 . A method as recited in claim 1 further comprising:

predicting, by said model, a second predicted behavior of said sample program based upon a subset of said first behaviors and said first predicted behavior; and

outputting said first and second predicted behaviors and taking an action upon said sample program based upon said first and second predicted behaviors.

8 . A method of predicting a behavior of a sample program, said method comprising:

executing said sample program in a sandbox module on a host computer;

collecting first behaviors of said sample program using dynamic analysis;

collecting second behaviors of said sample program using static analysis;

feeding said first and second behaviors into a model of a recurrent neural network (RNN) that has been trained to predict behaviors of a computer program; and

predicting, by said model, a first predicted behavior of said sample program based upon said first and second behaviors, wherein said predicting occurs after said steps of collecting and wherein said first predicted behavior is a future behavior at the time of said predicting and is not available from said dynamic analysis; and

outputting said first predicted behavior and taking an action upon said sample program based upon said first predicted behavior.

9 . A method as recited in claim 8 wherein said taking an action includes outputting a result that said sample program is malicious software.

10 . A method as recited in claim 8 further comprising:

feeding said first and second behaviors into a classifier before said feeding into said model in order to select said model of said recurrent neural network based upon a file type of said sample program.

11 . A method as recited in claim 8 wherein said first predicted behavior is not one of said first or second behaviors.

12 . A method as recited in claim 8 further comprising:

outputting said first predicted behavior to a decision engine of said host computer that performs said taking an action based upon a rule of said decision engine.

13 . A method as recited in claim 8 wherein said first predicted behavior is a numerical tuple, said method further comprising:

decoding said first predicted behavior to produce a textual representation of said first predicted behavior.

14 . A method as recited in claim 13 further comprising:

decoding said first predicted behavior using a table that maps numerical identifiers of listed behaviors to textual representations of said listed behaviors.

15 . A method as recited in claim 8 further comprising:

predicting, by said model, a second predicted behavior of said sample program based upon a subset of said first and second behaviors and said first predicted behavior; and

outputting said first and second predicted behaviors and taking an action upon said sample program based upon said first and second predicted behaviors.

16 . A method as recited in claim 8 further comprising:

inputting said first predicted behavior into said model of said recurrent neural network in order to train said model.

17 . A program behavior prediction system comprising:

a sandbox module executing upon a host computer arranged to execute a sample program, said sandbox module including

a dynamic analysis module arranged to collect run-time behaviors of said sample program,

a decision engine arranged to output a decision regarding said sample program based upon an output first predicted behavior from a machine learning network model; and

a sequence network executing upon said host computer arranged to input said run-time behaviors from said sample program, said sequence network including

an encoder arranged to encode said run-time behaviors into numerical tuples,

said machine learning network model that inputs said numerical tuples and is trained to output said first predicted behavior of said sample program based upon said numerical tuples, wherein said first predicted behavior is a future behavior at the time of said output from said machine learning network model and is not available from said dynamic analysis module, and

a decoder arranged to decode a numerical tuple representing said predicted behavior into an output predicted behavior for delivery to said decision engine.

18 . A system as recited in claim 17 wherein said network further includes

a plurality of machine learning network models, and

a classifier that classifies said sample program as being of a particular file type, wherein said classifier routes said run-time behaviors to one of said models based upon said file type of said sample program.

19 . A system as recited in claim 17 wherein said model predicts a second predicted behavior of said sample program based upon a subset of said first behaviors and said first predicted behavior, and wherein said model outputs said first and second predicted behaviors and takes an action upon said sample program based upon said first and second predicted behaviors.

20 . A method as recited in claim 5 further comprising:

feeding said textual representation of said first predicted behavior into a decision engine; and

said decision engine performing an action based upon said collected behaviors and said textual representation of said first predicted behavior.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2023
From: HUANG, QIANG; CAO, HU; DAI, WEICHAO
To: TREND MICRO INC.
Reel/Frame 065088/0820 →
Continuity (1)
Division 16502788 · Jul 3, 2019
References Cited (16)
US 11108787B1 · Shen et al. · 2021 [cited by applicant]
US 20110138471A1 · Van De Weyer · 2011 [cited by examiner]
US 20130291111A1 · Zhou et al. · 2013 [cited by applicant]
US 20140090061A1 · Avasarala et al. · 2014 [cited by applicant]
US 20150106931A1 · Mankin et al. · 2015 [cited by applicant]
US 20160277423A1 · Apostolescu et al. · 2016 [cited by applicant]
US 20160381057A1 · Das et al. · 2016 [cited by applicant]
US 20170251003A1 · Rostami-Hesarsorkh · 2017 [cited by examiner]
US 20170262633A1 · Miserendino et al. · 2017 [cited by applicant]
US 20190213099A1 · Schmidt · 2019 [cited by examiner]
US 20190384911A1 · Caspi et al. · 2019 [cited by applicant]
CN 108334781A · 2018 [cited by examiner]
CN 109492395 · 2019 [cited by applicant]
Xiao, X., Zhang, S., Mercaldo, F. et al. Android malware detection based on system call sequences and LSTM. Multimed Tools Appl 78, 3979-3999 (2019). https://doi.org/10.1007/s11042-017-5104-0 (Year: 2017). [cited by examiner]
Lindorfer, Martina, Matthias Neugschwandtner, and Christian Platzer. “Marvin: Efficient and comprehensive mobile app classification through static and dynamic analysis.” 2015 IEEE 39th annual computer software and appli… [cited by examiner]
Huang et al., U.S. Appl. No. 16/502,788, filed Jul. 3, 2019. [cited by applicant]