IP Library › Granted Patent US 12,645,797
Granted Patent B2
US 12,645,797 · App. 18/303,144 · Granted Jun 2, 2026

Malware detection from approximate indicators

Inventors: Brendan James Moran (Coton, GB); Michael Bartling (Austin, TX)
Assignee: ARM LIMITED
G06F21/566H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,797
App. No.
18/303,144
Granted
Jun 2, 2026
Kind
B2
Abstract

A method of malware detection includes performing, by a second device of a plurality of devices on a network, a fuzzy matching between a second sequence of events occurring at the second device and a first sequence of captured events that occurred at a first device of the plurality of devices on the network; determining, by the second device, that a result of the fuzzy matching reaches a first threshold; and in response to determining that the result of the fuzzy matching reaches the first threshold, initiating a detailed instrumentation at the second device. The method can further include determining, by the second device, that a first condition is satisfied; and in response to determining that the first condition is satisfied: generating a second malware behavior package including information from the detailed instrumentation; and communicating the second malware behavior package over the network.

Claims (59)

1 . A method of malware detection comprising:

receiving, at a second device of a plurality of devices on a network directly from a first device of the plurality of devices over the network, a first malware behavior package of a first possible threat, wherein the first malware behavior package comprises a first sequence of captured events that occurred at the first device of the plurality of devices on the network;

performing, by the second device, a fuzzy matching between a second sequence of events and the first sequence of captured events, wherein the second sequence of events comprises information of local events occurring at the second device and relative time between occurrences of the local events;

determining, by the second device, that a result of the fuzzy matching reaches a first threshold;

in response to determining that the result of the fuzzy matching reaches the first threshold, initiating a detailed instrumentation at the second device;

determining, by the second device, that a first condition is satisfied; and

in response to determining that the first condition is satisfied:

generating a second malware behavior package comprising information from the detailed instrumentation; and

communicating the second malware behavior package over the network; and

receiving an update to the first condition that modifies the first condition,

wherein the update to the first condition that modifies the first condition is received in response to the second device being in a low power mode, wherein the update to the first condition is a change to reduce an amount of time for collecting the information from the detailed instrumentation.

2 . The method of malware detection of claim 1 , wherein performing, by the second device, the fuzzy matching between the second sequence of events and the first sequence of captured events comprises:

performing a convolution of the first sequence with a distance function over the second sequence.

3 . The method of malware detection of claim 1 , wherein the detailed instrumentation at the second device comprises recording the second sequence of events, wherein information from the detailed instrumentation recording the second sequence of events comprises a sequence of captured events of the second sequence of events.

4 . The method of malware detection of claim 1 , wherein the detailed instrumentation at the second device comprises monitoring network traffic, monitoring system calls, monitoring file Input/Output (I/O), or a combination thereof.

5 . The method of malware detection of claim 1 , wherein determining that the first condition is satisfied comprises determining that the result of the fuzzy matching reaches a second threshold.

6 . The method of malware detection of claim 1 , wherein determining that the first condition is satisfied comprises determining that a specified amount of time has passed after initiating the detailed instrumentation.

7 . The method of malware detection of claim 1 , wherein determining that the first condition is satisfied comprises determining from the information of the local events that a trigger behavior is present.

8 . The method of malware detection of claim 1 , wherein determining that the first condition is satisfied comprises determining that a trigger behavior occurred based on the information from the detailed instrumentation.

9 . The method of malware detection of claim 1 , wherein communicating the second malware behavior package over the network comprises communicating the second malware behavior package to a monitor system that monitors the plurality of devices on the network.

10 . The method of malware detection of claim 1 , wherein communicating the second malware behavior package over the network comprises communicating the second malware behavior package to other devices of the plurality of devices on the network.

11 . The method of malware detection of claim 1 , further comprising:

identifying, by a local detector of the second device, behavior of the second device during execution of a code, wherein the local detector produces, from the behavior of the second device during execution of the code, the information of the local events and the relative time between occurrences of the local events.

12 . The method of malware detection of claim 1 , wherein the first malware behavior package is received from a monitoring system that is in communication with the plurality of devices on the network.

13 . The method of malware detection of claim 12 , wherein the first malware behavior package further comprises information captured from at least one other device of the plurality of devices that is combined, by the monitoring system, with the first sequence of captured events that occurred at the first device to form a refined first sequence of captured events.

14 . The method of malware detection of claim 1 , wherein the first malware behavior package is received from the first device.

15 . The method of malware detection of claim 1 , further comprising:

receiving, at the second device, a plurality of malware behavior packages in addition to the first malware behavior package; and

performing, by the second device, fuzzy matching between the second sequence of events and sequences of captured events indicated by the plurality of malware behavior packages, wherein the detailed instrumentation is initiated upon any results of fuzzy matching reaching the first threshold.

16 . A computer-readable storage medium having instructions stored thereon that when executed by a processor of a device, direct the device to:

receive, at the device of a plurality of devices on a network, a first malware behavior package of a first possible threat, wherein the first malware behavior package comprises a first sequence of captured events that occurred at a first device of the plurality of devices on the network;

perform, by the device, a fuzzy matching between a second sequence of events and the first sequence of captured events, wherein the second sequence of events comprises information of local events and relative time between occurrences of the local events;

determine, by the device, that a result of the fuzzy matching reaches a first threshold;

in response to the result of the fuzzy matching reaching the first threshold, initiate a detailed instrumentation at the device;

determine, by the device, that a first condition is satisfied;

in response to the first condition being satisfied:

generate a second malware behavior package comprising information from the detailed instrumentation; and

communicate the second malware behavior package over the network;

determine, by the device, that a first condition is satisfied; and

receive an update to the first condition that modifies the first condition,

wherein the update to the first condition that modifies the first condition is received in response to the device being in a low power mode, wherein the update to the first condition is a change to reduce an amount of time for collecting the information from the detailed instrumentation.

17 . The computer-readable storage medium of claim 16 , wherein the detailed instrumentation comprises recording the second sequence of events.

18 . The computer-readable storage medium of claim 16 , wherein the detailed instrumentation comprises monitoring network traffic, monitoring system calls, monitoring file Input/Output (I/O), or a combination thereof.

19 . The computer-readable storage medium of claim 16 , wherein the instructions that direct the device to determine that the first condition is satisfied further comprise instructions that direct the device to determine that the result of the fuzzy matching reaches a second threshold.

20 . A device comprising:

a processor;

a network interface;

a memory; and

instructions stored on the memory that when executed by the processor direct the device to:

receive, at the device of a plurality of devices on a network directly from a first device of the plurality of devices over the network, a first malware behavior package of a first possible threat, wherein the first malware behavior package comprises a first sequence of captured events that occurred at the first device of the plurality of devices on the network;

perform, by the device, a fuzzy matching between a second sequence of events and the first sequence of captured events, wherein the second sequence of events comprises information of local events and relative time between occurrences of the local events;

determine, by the device, that a result of the fuzzy matching reaches a first threshold;

in response to the result of the fuzzy matching reaching the first threshold, initiate a detailed instrumentation at the device;

determine, by the device, that a first condition is satisfied; and

in response to the first condition being satisfied:

generate a second malware behavior package comprising information from the detailed instrumentation; and

communicate the second malware behavior package over the network; and

receive an update to the first condition that modifies the first condition,

wherein the update to the first condition that modifies the first condition is received in response to the device being in a low power mode, wherein the update to the first condition is a change to reduce an amount of time for collecting the information from the detailed instrumentation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2023
From: MORAN, BRENDAN JAMES; BARTLING, MICHAEL
To: ARM LIMITED
Reel/Frame 063378/0001 →
Continuity (1)
Related Publication 20240354410A1 · Oct 24, 2024
References Cited (20)
US 9419996B2 · Porat · 2016 [cited by examiner]
US 9503465B2 · Coskun · 2016 [cited by examiner]
US 10104100B1 · Bogorad · 2018 [cited by examiner]
US 10360089B2 · Crosby et al. · 2019 [cited by applicant]
US 11055405B1 · Jin · 2021 [cited by examiner]
US 20150096025A1 · Ismael · 2015 [cited by examiner]
US 20150205961A1 · Franklin · 2015 [cited by examiner]
US 20150220735A1 · Paithane et al. · 2015 [cited by applicant]
US 20160285717A1 · Kim · 2016 [cited by examiner]
US 20170017793A1 · Davis · 2017 [cited by examiner]
US 20180165142A1 · Harutyunyan · 2018 [cited by examiner]
US 20190114421A1 · Das · 2019 [cited by examiner]
US 20190166144A1 · Mirsky · 2019 [cited by examiner]
US 20190171622A1 · Zong · 2019 [cited by examiner]
US 20190238565A1 · Wang · 2019 [cited by examiner]
US 20200210576A1 · Chistyakov · 2020 [cited by examiner]
US 20210409431A1 · Wang et al. · 2021 [cited by applicant]
US 20230114821A1 · Thomas · 2023 [cited by examiner]
US 20230308460A1 · Thomas · 2023 [cited by examiner]
International Search Report and Written Opinion issued in International Application No. PCT/GB2024/050356, mailed Mar. 18, 2024, 15 pages. [cited by applicant]