Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

309 results about "Malware" patented technology

Malware (a portmanteau for malicious software) is any software intentionally designed to cause damage to a computer, server, client, or computer network. Malware does the damage after it is implanted or introduced in some way into a target's computer and can take the form of directly executable code, scripts, so-called "active content" (Microsoft Windows), and other forms of data. Some kinds of malware are largely referred to in the media as computer viruses, worms, Trojan horses, ransomware, spyware, adware, and scareware, among other terms. Malware has a malicious intent, acting against the interest of the computer user—and so does not include software that causes unintentional harm due to some deficiency, which is typically described as a software bug.

Devices, systems, and methods for using linguistic approaches to understand malicious programs

Disclosed herein are devices, systems, and methods for detecting, understanding, and classifying malicious actions and / or behaviors in software (e.g., malware), including hidden malicious actions. Specifically, disclosed embodiments use natural language approaches to understand malicious software and provide explanations for classification results. At least one embodiment constructs a knowledge graph that includes textual explanations from source materials (e.g., articles), collecting one or more sets of dynamic program traces from one or more instances of malware, and constructing and training a model (also referred to herein as Trace-BERT) using the one or more sets of dynamic program traces. Forced execution of sample segments of computer code can also be used to identify hidden or novel malicious actions.
Owner:OCEANIT LABORATORIES INC

Detecting malicious command and control cloud traffic

The technology disclosed relates to a method, system, and non-transitory computer-readable media that detects malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host, using a network security system. The network security system reroutes the cloud traffic to the network security system. The incoming requests of the cloud traffic are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources. The network security system analyzes the incoming requests, determines that the incoming requests are targeted at one or more malicious resources in the plurality of resources. Also, the network security system prevents transmission of the incoming requests to the malicious resources, by making the malicious resources unavailable for receiving future incoming requests, while keeping other resources in the plurality of resources available for receiving the future incoming requests.
Owner:NETSKOPE INC

Using cross workloads signals to remediate password spraying attacks

A method for detecting password spray attacks. The method includes obtaining information from an on-machine malware detection application for a particular machine indicating that a password spray tool is detected on the particular machine. Information is obtained indicating that the particular machine has performed failed sign in attempts. As a result, a determination is made that the particular machine is performing password spray attacks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Large language model (LLM) powered detection reasoning solution

Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and / or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.
Owner:PALO ALTO NETWORKS INC

Ground truth determination for network detections on text-based protocols by llm

PendingUS20260050774A1Ensemble learningBiological modelsGround truthText-based protocol
The present application discloses a method, system, and computer system for enriching a ground truth of a machine learning-based detection using a large language model (LLM). The method includes: (a) obtaining a machine learning (ML)-based prediction for a security detection, (b) prompting a large language model (LLM) for an LLM-based prediction for the security detection based at least in part on a set of examples of malware, and (c) determining a ground truth of the ML-based prediction for the security detection based at least in part on a response from the LLM.
Owner:PALO ALTO NETWORKS INC

Quantum-enhanced multi-modal large language model security protection

Disclosed are various embodiments for quantum-enhanced multi-modal large language model (LLM) security protection. Various embodiments can receive a request to cause an LLM to process a text prompt and a multimedia input. The prompt request can include the text prompt and the multimedia input, which are comprised of multimedia bits. Various embodiments can convert the multimedia bits of the multimedia input into quantum bits (qubits) of a quantum multimedia representation. Various embodiments can then direct a quantum computing device to identify the presence of one or more attributes (e.g., threats, malware, etc.) within the quantum multimedia representation that could be harmful to the LLM, if processed. Various embodiments can then prevent the LLM from processing the text prompt and multimedia input in response to identifying the presence of the one or more attributes within the quantum multimedia representation.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Behavior analysis based on finite-state machine for malware detection

A system and method are disclosed for identifying malicious activity on a target device based on behavior analysis of the target device. The system includes a behavioral analyzer run on a virtual machine connected to the target device. The virtual machine collects system events and parameters from the target device and run a script, independent of the target device, to detect a threat. The script is a set of instructions executed to analyze behavior of an object by processing and correlating the events. The script includes a rule structure which stores signatures and expressions of the known malwares. By correlating the selected event parameters with known malware parameters, it is determined whether the event imposes a threat or not. A finite state machine is used for the state transition table.
Owner:ACRONIS INT

Simulation of malware with changing signatures

A computer-implemented method of simulating a propagation of a malware through a set of computer systems, the method comprising: identifying a simulated computer system infected with a simulated malware; determining a first signature of the simulated malware; determining that a mutation condition for the simulated malware has been met; and in response to determining that the mutation period has been met, changing the first signature of the simulated malware to a second signature.
Owner:BRITISH TELECOM PLC

Malware detection model training method and device based on itemized reward and operation index linkage

The invention discloses a malicious software detection model training method and device based on item reward and operation index linkage, and belongs to the technical field of artificial intelligence and malicious software detection. The method comprises the following steps: constructing a reinforcement learning model containing a policy network; the policy network is configured to receive software feature input and output multi-modal actions including classification results, structured interpretation text and detection confidence; based on the training sample, generating a multi-modal action by utilizing a strategy network, and calculating a composite reward value for the generated multi-modal action by utilizing a preset subitem reward; the subitem rewards at least comprise a structure consistency reward, a key element hit reward and a confidence coefficient calibration reward; and calculating advantage estimation based on the composite reward value to construct an objective function of a near-end policy optimization algorithm by using the advantage estimation, and maximizing the objective function by updating parameters of the policy network. The method can improve the explanatory and confidence of model output, and improves the recognition precision.
Owner:HARBIN ANTIY TECH

Malware activity detection for networked computing systems

Malware activity detection for networked computing systems is described. A network session record is provided to a machine learning (ML) model configured to generate an indication of whether the provided network session record evidences malware activity. The network session record indicates network traffic activity in a time period. Responsive to an indication by the ML model, correlation scores are calculated by, for each process session record in a process session record set, calculating a correlation score indicative of a correlation between the provided network session record and the process session record. Each process session record in the process session record set corresponds to a process executed by a computing device in the time period. A determination that a correlation score indicates a corresponding process session record is indicative of the evidenced malware activity is made. Responsive to the determination, a malware activity alert is generated.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Malicious software detection method based on multi-feature fusion and interpretability analysis

The invention relates to a malicious software detection method based on multi-feature fusion and interpretability analysis. According to the technical scheme, static features are extracted through'macroscopic-microscopic 'double paths, and a dynamic behavior knowledge graph is constructed in combination with sandbox monitoring, stain analysis and semantic abstraction and converted into feature vectors through graph embedding; multi-modal feature deep interaction and accurate classification are realized through a double-end cross attention-triple fusion-deep classification architecture; a hierarchical interpretable framework is constructed based on cross-modal causal alignment, case reasoning and anti-fact analysis, and a complete decision evidence chain is generated. The method has the advantages that comprehensive representation of the form, semantics and intention of malicious software is achieved, the detection precision and robustness are remarkably improved, meanwhile, the'black box 'dilemma of the model is solved, credible explanation is provided for security analysis, the method is suitable for complex network threat detection scenes, and it is verified through experiments that the method has good application prospects. According to the method, the detection rate of the Windows malicious software is remarkably increased, and the false alarm rate is effectively reduced.
Owner:XINJIANG UNIVERSITY

Detecting malware activity using kernel-based process discovery detection

Malware attacks seek to identify vulnerabilities that can be exploited by enumerating currently-executing processes in the operating system of a target device for injection of a malicious payload. By detecting process enumeration events occurring at the kernel level, known or suspected malware enumeration activity can be identified and mitigated.
Owner:SOPHOS LTD

Identification of .net malware with "unmanaged imphash"

The present application discloses a method, system, and computer system for detecting malicious files. The method includes receiving a sample that comprises a .NET file, obtaining imported API function names based at least in part on a .NET header of the .NET file, determining a hash of a list of unmanaged imported API function names, and determining whether the sample is malware based at least in part on the hash of the list of unmanaged imported API function names.
Owner:PALO ALTO NETWORKS INC

Web analyzer engine for identifying security-related threats

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.
Owner:CISCO TECHNOLOGY INC

Using packet fingerprinting at an endpoint to detect malware

Aspects of the present disclosure are directed to on-device firewall and library agents integrated with secure agents on network connected endpoints. The on-device firewall and library agents enable inline analysis and inspection of data packets using protocol fingerprints generated for the data packets using an on-device malware detection engine. In one aspect, a network device includes a driver configured to capture a plurality of data packets received at the network device; and an on-device malware detection engine configured to receive at least a subset of the plurality of packets, and generate a fingerprint for the subset of the plurality of packets, the fingerprint being indicative of whether the plurality of data packets are associated with an external malware communication.
Owner:CISCO TECHNOLOGY INC

Malware detection method and device based on subspace ensemble learning, equipment and medium

PendingCN122365492Aimprove accuracyReduce computing resourcesAlgorithmApplication programming interface
This invention discloses a method, apparatus, device, and medium for malware detection based on subspace ensemble learning. The method includes: acquiring the installation package file of the software to be detected; parsing the installation package file to obtain the application programming interface (API) call relationships of the software to be detected; determining the API call relationship graph based on the API call relationships; filtering each API in the call relationship graph to obtain a target API set; and determining the software detection result of the software to be detected based on the target API set and a feature subspace ensemble learning model. This invention obtains the target API set by filtering the API call relationships and employs a feature subspace ensemble learning model composed of multiple machine learning algorithms, which can capture malicious behavior in software from different perspectives, thereby improving the accuracy of malware detection.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +2

A functional sequence-based shell software clustering analysis method, system, device and medium

The present application relates to the technical field of shell software clustering analysis, and particularly relates to a shell software clustering analysis method, system, device and medium based on function sequences, which comprises: obtaining a plurality of shell software samples to be analyzed; parsing a function set from each sample and selecting a function subset with a program entry point as the core as a function sequence of the sample; identifying the function type of each function in each function sequence by using a semantic analysis model and assigning a function label to generate a function type sequence of the sample; performing clustering analysis based on all samples by using a density clustering algorithm to form a plurality of clusters; calculating the representative contribution value of the functions of each sample in each cluster to the cluster center characteristics; and selecting at least one representative function from each cluster based on the representative contribution value. The present application has the beneficial effect of significantly improving the explainability, automation degree and traceability analysis efficiency of malicious software clustering analysis.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

Aggregating input / output operation features extracted from storage devices to form a machine learning vector to check for malware

Provided are a computer program product, system, and method for aggregating input / output operation features extracted from storage devices to form a machine learning vector to check for malware. Feature extraction functions are generated for the storage devices, indicating I / O operation features for the storage devices to gather. The feature extraction functions are communicated to the storage devices. The feature extraction functions transmitted to the storage devices cause the storage devices to gather information on I / O operation features, identified in the feature extraction functions, from the storage devices and transmit the information on the I / O operation features to the storage controller. The information on the I / O operation features are received from the storage devices. Information based on the received information on the I / O operation features are inputted into a machine learning model to output indication whether data in the storage devices contains malware.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Server backup method and system based on Hash algorithm

The invention belongs to the technical field of data backup, and provides a server backup method and system based on a Hash algorithm, and the method comprises the following steps: adopting an incremental backup mode, and only backing up data which changes after last backup; in combination with an event notification mechanism of a file system, capturing generated data in real time and backing up the data, and meanwhile, carrying out duplicate removal and blocking processing on the data; the processed data is sent to a specified storage position after being subjected to Hash encryption; carrying out distributed processing on the received data, and managing and distributing the data to the local and the cloud; in the backup process, the monitoring operation state is continuously kept, and logs of backup activities are recorded; data are captured in real time by combining an event notification mechanism of a file system, and security protection measures are set, so that viruses and malicious software are effectively prevented from infecting backup data. And meanwhile, the processed data is encrypted and then sent to a specified storage position, so that the data is further prevented from being illegally accessed.
Owner:SHANGHAI MEISHAN IRON & STEEL CO LTD

Method for securely deploying a software framework on a machine learning (ML) platform and a system thereof

The present disclosure provides a method for deploying the software framework on the ML Platform in a secure manner. In particular, the present disclosure provides a method for securely deploying the ML models or the algorithms into the system by providing a multi-level scanning procedure. In an embodiment, the disclosed method performs multiple vulnerability scans on the ML model or the algorithm at multiple stages to check for malware and ensure that only models / algorithms that pass the security checks are imported into the system. If the security scan detects vulnerabilities at any stage then the files are placed in a quarantined zone and the import process is terminated. Thereby protecting the system and making it cyber-secure.
Owner:HONEYWELL INTERNATIONAL INC

Malware detection and screening systems

Systems and methods receive a malware detection and screening subscription request to screen software application downloads for different types of malware for user device(s) associated with an entity as part of a firewall subscription. The user device(s) are registered to apply the firewall subscription to screen software application download requests, and network traffic to the user device(s) is monitored via a network firewall. From the monitored network traffic, it is ascertained, via the network firewall, that a device of the user device(s) is initiating download of a software application. The software application is screen for the different types of malware, the screening including a screening protocol. Based on the screening, it is determined that the software application includes at least one type of malware, and a notification that the software application likely includes the at least one type of malware is transmitted to the device.
Owner:TRUIST BANK

Multi-level verification method and device for mobile storage and storage medium

The invention provides a multi-level verification method and device for mobile storage and a storage medium. The method comprises the following steps: when the mobile storage is used, acquiring a multi-level scanning result of the mobile storage by a central security monitoring system; judging whether the mobile storage is scanned or not and whether the multi-level scanning result is normal or not based on the multi-level scanning result; if not, prohibiting the use of the mobile storage and giving an alarm; providing use permission of the mobile storage step by step, and scanning the mobile storage based on a scanning rule corresponding to the use permission to obtain a current scanning result; judging whether a part, corresponding to the current scanning result, in the multi-stage scanning result is matched with the current scanning result or not; if yes, the next-level use permission is provided; and if not, locking the mobile storage and giving an alarm. According to the technical scheme, the scanning precision of the mobile storage device can be improved, the mobile storage using speed is increased, malicious software is prevented from bypassing basic inspection, and safety is improved.
Owner:SIEMENS AG

Artificial intelligence (AI)-based system for detecting malware in endpoint devices using a multi-source data fusion and method thereof

An artificial intelligence (AI)-based system for detecting malware in endpoint devices using a multi-source data fusion and method thereof are disclosed. The AI-based system collects at least one of: endpoint visibility data, publicly available information, and sandbox analysis data using the multi-source data fusion. By using the collected data, the AI-based system generates one or more numerical embeddings for at least one of: one or more files and one or more applications of each endpoint device using one or more AI models. The AI-based system is configured with the one or more AI models to generate one or more dynamic directed graphs based on the generated one or more numerical embeddings to compute a maliciousness risk score. The maliciousness risk score of at least one of the: one or more files and one or more applications is used for detecting the malware in the one or more endpoint devices.
Owner:PRIVAFY INC

Host controller and method operating in a computer system including a host

A host controller is provided for operation in a computer system including a host. The host controller is also configured to receive a process to be executed and run at least one false system service. In addition, the false system service carries a name known to the malware system. And, the host controller is to execute the process and detect an attempt to disable the false system service. Thereafter, if detected, the host controller is used to efficiently and accurately determine that the process includes malware. Therefore, the overall data security of the computer system is improved.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Android malicious software detection method based on multi-task learning mechanism

The invention provides an Android malicious software detection method based on a multi-task learning mechanism, and belongs to the technical field of mobile security and malicious software detection. Comprising the steps of 1, extracting malicious family correlation, and extracting correlation among different malicious families through a multi-task learning mechanism by adopting a deep learning model based on a CNN (convolutional neural network) and a Bi-LSTM (bidirectional long short-term memory) network; 2, generating a malicious space, and depicting a high-risk sample region through feature space generation, threat region identification and region priority ranking; 3, identifying high-risk samples, and screening the samples based on region priorities and position attributes; and step 4, decision optimization: carrying out fine adjustment on the detection model by combining high-risk samples and known sample anchor points so as to improve the detection capability of unknown malicious families. According to the method, through multi-task learning and malicious space analysis, the detection effect of the method on unknown Android malicious software is improved.
Owner:JIANGSU UNIV

System and method for intrusion detection of malware traffic

A system-on-a-chip (SoC) and corresponding method implement an intrusion detection system. The SoC comprises a plurality of hardware engines. The SoC employs the plurality of hardware engines to implement the intrusion detection system. The intrusion detection system is capable of detecting malware traffic in (i) a non-encrypted traffic stream, (ii) an encrypted traffic stream that can be decrypted by the SoC, and (iii) an encrypted traffic stream that cannot be decrypted by the SoC. The intrusion detection system performs an action responsive to detecting the malware traffic. The action is performed toward preventing malicious activity otherwise caused by the malware traffic.
Owner:MARVELL ASIA PTE LTD

Malicious software detection method based on class distance optimization

The invention provides a malicious software detection method based on class distance optimization, and the method comprises the steps: obtaining malicious software sample data, and carrying out the preprocessing of the malicious software sample data; decompiling the preprocessed data to obtain a source code file; selecting byte code features from the source code file, and converting the byte code features into an RGB three-channel image; the RGB three-channel image is expanded by adopting the optimized GAN architecture, and an expanded malicious software sample is obtained; inputting the expanded malicious software sample into a deep neural network to obtain a malicious software family classification result; the generated high-quality malicious software image can be used for data enhancement, so that the model is more stable when facing various malicious software variants, the over-fitting risk is reduced, the reliability of a detection system is improved, the data acquisition cost is reduced, a data set is over-expanded, and the detection accuracy is improved. The deep learning model covers more possible malicious software features in the training process, so that manual intervention is reduced, and the automation level of a detection system is improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Feature refining method and device based on dynamic security context

The invention discloses a feature refining method and device based on a dynamic security context, and belongs to the technical field of network security. The method comprises the following steps: acquiring a previous round of iteration feature and a current round of security context; the last round of iteration features are features used by the malicious software detection model in the last round of training process; generating a reserved mask for the last round of iteration features by using the current round of security context; screening out reserved features from the last round of iteration features by using the reserved mask; and carrying out the current round of training on the malicious software detection model by utilizing the reserved features, and carrying out malicious software detection by utilizing the malicious software detection model obtained by the current round of training. According to the method, dynamic feature activation can be performed on the last round of iteration features by using the current round of security context, so that the malicious software detection model can focus on the reserved features most related to the current security environment during updating training, and the detection capability on novel threats is improved.
Owner:HARBIN ANTIY TECH

Malware undetectable sandbox

Embodiments are directed to preventing sandbox environments from being detected by potentially malicious applications. To this end, execution of an application is monitored and information about the execution is provided to a reinforcement learning machine learning model. The model generates suggested modifications to be made to the executing application. The model is provided information indicating whether the application successfully executed and this information is used to train the model for other modifications. By modifying the execution of potentially malicious software during execution, detection of the sandbox environment can be prevented and better analysis of potentially malicious application features can be understood.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method of generating training data for training machine learning model for identifying malware

The invention relates to a method for generating training data for training a machine learning model for identifying malware, in particular malware in operating software for an engineering system, such as a control device, comprising: providing (110) malware data comprising a plurality of decomposition parts, wherein the decomposition units respectively include functional blocks obtained or already obtained by decomposing the attack vector; providing (120) good software data comprising a plurality of decomposition parts, wherein the decomposition parts respectively comprise functional blocks obtained or already obtained by decomposing the good software samples; generating (130) training data on the basis of the malware data and the good software data, the training data comprising adapted good software samples, the good software samples being respectively based on functional blocks of the corresponding good software samples, the functional blocks supplementing one or more functional blocks of the malware data; and training data is provided for training the machine learning model.
Owner:ROBERT BOSCH GMBH