IP Library Granted Patent US 11,861,006
Granted Patent B2
US 11,861,006 · App. 17/151,462 · Granted Jan 2, 2024

High-confidence malware severity classification of reference file set

Inventors: Martin Bálek (Teplice, CZ); Fabrizio Biondi (Prague, CZ); Dmitry Kuznetsov (Prague, CZ); Olga Petrova (Vrsovice, CZ)
Assignee: Avast Software s.r.o.
G06F21/566G06F18/217G06F21/54G06F21/568G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,861,006
App. No.
17/151,462
Granted
Jan 2, 2024
Kind
B2
Abstract

A reference file set having high-confidence malware severity classification is generated by selecting a subset of files from a group of files first observed during a recent observation period and including them in the subset. A plurality of other antivirus providers are polled for their third-party classification of the files in the subset and for their third-party classification of a plurality of files from the group of files not in the subset. A malware severity classification is determined for the files in the subset by aggregating the polled classifications from the other antivirus providers for the files in the subset after a stabilization period of time, and one or more files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset are added to the subset.

Claims (37)

1. A method of generating a reference file set having high-confidence malware severity classification, comprising:

selecting a subset of files from a group of files first observed during a recent observation period;

polling a plurality of other antivirus providers for their third-party classification of the files in the subset of files and for their third-party classification of a plurality of files from the group of files not in the subset;

determining a malware severity classification for the files in the subset by aggregating the polled classifications from the other antivirus providers for the files in the subset after a stabilization period of time; and

adding one or more files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset.

2. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , further comprising adding one or more files to the subset of files selected to improve representation of malware types seen during recent observation period in a distribution of malware types in the subset.

3. The method of generating a reference file set having high-confidence malware severity classification of claim 2 , wherein malware types comprise at least one of malware families, malware having similar functions, and malware having similar severity.

4. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , further comprising determining a malware severity classification for the one or more added files having a third-party classification that changed during the stabilization by aggregating the polled classifications from the other antivirus providers for the one or more added files.

5. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , further comprising assigning the subset and malware severity classifications for the subset as immutable truth for the recent observation period for purposes of future testing.

6. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , wherein the recent observation period comprises a day, three days, or a week.

7. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , wherein selecting the subset of files from the group of files is done randomly.

8. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , wherein the stabilization period comprises a period of two days to one week.

9. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , wherein determining classification further comprises using at least one of majority voting, statistical estimation, and machine learning using third-party classification of the files from the polled third-party antivirus providers.

10. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , wherein adding one or more files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset comprises adding all files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period.

11. The method of generating a reference file set having high-confidence malware severity classification of claim 1 , wherein adding one or more files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset increases the percentage of files in the subset that are more difficult to classify, thereby improving complexity of the subset.

12. A method of estimating the effectiveness of an anti-malware algorithm, comprising:

testing the anti-malware algorithm against a reference file set; and

evaluating the accuracy of the malware algorithm in characterizing a malware severity of each file in the reference set;

wherein the reference file set is constructed by:

selecting a subset of files from a group of files first observed during a recent observation period;

polling a plurality of other antivirus providers for their third-party classification of the files in the subset of files and for their third-party classification of a plurality of files from the group of files not in the subset;

determine a malware severity classification for the files in the subset by aggregating the polled classifications from the other antivirus providers for the files in the subset after a stabilization period of time; and

adding one or more files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset.

13. The method of estimating the effectiveness of an anti-malware algorithm of claim 12 , wherein the reference file set is further constructed by adding one or more files to the subset of files selected to improve representation of malware types seen during recent observation period in a distribution of malware types in the subset.

14. The method of estimating the effectiveness of an anti-malware algorithm of claim 12 , wherein the reference file set is further constructed by determining a malware severity classification for the one or more added files having a third-party classification that changed during the stabilization by aggregating the polled classifications from the other antivirus providers for the one or more added files.

15. The method of estimating the effectiveness of an anti-malware algorithm of claim 12 , wherein the recent observation period comprises a period of one day to one week, and the stabilization period comprises a period of two days to one week.

16. A method of generating a reference file set having high-confidence malware severity classification, comprising:

selecting a subset of files from a group of files first observed during a recent observation period;

polling a plurality of other antivirus providers for their third-party classification of the files in the subset of files and for their third-party classification of a plurality of files from the group of files not in the subset;

determining a malware severity classification for the files in the subset by aggregating the polled classifications from the other antivirus providers for the files in the subset after a stabilization period of time;

adding one or more first additional files to the subset having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period;

adding one or more second additional files to the subset selected to improve representation of malware types seen during recent observation period in a distribution of malware types in the subset;

determining a malware severity classification for the one or more first and second additional files added to the subset by aggregating the polled classifications from the other antivirus providers for the added files.

17. The method of generating a reference file set having high-confidence malware severity classification of claim 16 , further comprising assigning the subset and malware severity classifications for the subset as immutable truth for the recent observation period for purposes of future testing.

18. The method of generating a reference file set having high-confidence malware severity classification of claim 16 , wherein the recent observation period comprises a period of one day to one week, and the stabilization period comprises a period of two days to one week.

19. The method of generating a reference file set having high-confidence malware severity classification of claim 16 , wherein adding one or more files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset comprises adding all files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period.

20. The method of generating a reference file set having high-confidence malware severity classification of claim 16 , wherein adding one or more first additional files having a third-party classification from at least one of the polled other antivirus providers that changed during the stabilization period to the subset increases the percentage of files in the subset that are more difficult to classify, thereby improving complexity of the subset.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2022
From: BÁLEK, MARTIN; BIONDI, FABRIZIO; KUZNETSOV, DMITRY; PETROVA, OLGA
To: AVAST SOFTWARE S.R.O.
Reel/Frame 061052/0032 →
Continuity (1)
Related Publication 20220229906A1 · Jul 21, 2022