Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

549 results about "Malware" patented technology

Malware (a portmanteau for malicious software) is any software intentionally designed to cause damage to a computer, server, client, or computer network. Malware does the damage after it is implanted or introduced in some way into a target's computer and can take the form of directly executable code, scripts, so-called "active content" (Microsoft Windows), and other forms of data. Some kinds of malware are largely referred to in the media as computer viruses, worms, Trojan horses, ransomware, spyware, adware, and scareware, among other terms. Malware has a malicious intent, acting against the interest of the computer user—and so does not include software that causes unintentional harm due to some deficiency, which is typically described as a software bug.

Devices, systems, and methods for using linguistic approaches to understand malicious programs

Disclosed herein are devices, systems, and methods for detecting, understanding, and classifying malicious actions and / or behaviors in software (e.g., malware), including hidden malicious actions. Specifically, disclosed embodiments use natural language approaches to understand malicious software and provide explanations for classification results. At least one embodiment constructs a knowledge graph that includes textual explanations from source materials (e.g., articles), collecting one or more sets of dynamic program traces from one or more instances of malware, and constructing and training a model (also referred to herein as Trace-BERT) using the one or more sets of dynamic program traces. Forced execution of sample segments of computer code can also be used to identify hidden or novel malicious actions.
Owner:OCEANIT LABORATORIES INC

Neuro-Generative Adversarial System for real-time detection and combating of malware morphing in high-density edge networks

ActiveDE202025106911U1Platform integrity maintainanceData packEmbedded security
A system for real-time detection and mitigation of morphing malware in high-density edge networks, consisting of: a data acquisition unit configured to receive, normalize, and encode multimodal telemetry data streams originating from at least one of the following domains: network traffic, process behavior, system call sequences, binary instruction traces, and control flow graphs; the data acquisition unit is further configured to compute feature embeddings over sliding time windows and apply privacy-preserving redactions prior to storage; a generative neural processor that is operationally coupled to the data acquisition unit and configured to generate synthetic morphing malware variants by learning probabilistic transformations of previously observed malicious data representations, maintaining semantic functionality while varying structural and behavioral features; a discriminative neural processor trained adversarially with the generative neural processor, wherein the discriminative neural processor is configured to detect morphing malware by evaluating a probability distribution over multimodal telemetry embeddings and classifying anomalous process and flow behaviors in real time; a coordination processor that is communicatively connected to both the generative neural processor and the discriminative neural processor and is configured to orchestrate adversarial co-training, regulate detection thresholds, calculate reinforcement-based penalties for false negative results, and trigger countermeasures as soon as a detection confidence level exceeds a predefined adaptive threshold; a secure, system-integrated inference and enforcement unit configured to perform low-latency countermeasures at the network edge, including selective packet filtering, flow isolation, process interruption, or system microsegmentation, based on instructions from the coordinating processor; and a hardware-embedded security enclave that is embedded in the system and configured to store cryptographic keys, neural model parameters, and integrity affirmation data to ensure the confidentiality, authenticity, and immutability of model artifacts and policy configurations.
Owner:ANAJAVADIDHODDI RAMACHANDRA NAIK CHAYAPATHI BENGALURU +7

Deep learning for in-line detection of malicious command and control traffic from unstructured payloads

Various techniques for providing deep learning for inline detection of malicious command and control (C2) traffic from unstructured payloads are disclosed. In some embodiments, a system / process / computer program product for providing deep learning for inline detection of malicious C2 traffic from unstructured payloads includes monitoring a session at a security platform, wherein the session includes network traffic; executing a local deep learning model on the network traffic, wherein the local deep learning model is a machine learning implemented C2 (MLC2) model executed on the security platform; and performing an action in response to determining that the monitored session is associated with malware based at least in part on a verdict from the deep learning model.
Owner:PALO ALTO NETWORKS INC

Detecting malicious command and control cloud traffic

The technology disclosed relates to a method, system, and non-transitory computer-readable media that detects malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host, using a network security system. The network security system reroutes the cloud traffic to the network security system. The incoming requests of the cloud traffic are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources. The network security system analyzes the incoming requests, determines that the incoming requests are targeted at one or more malicious resources in the plurality of resources. Also, the network security system prevents transmission of the incoming requests to the malicious resources, by making the malicious resources unavailable for receiving future incoming requests, while keeping other resources in the plurality of resources available for receiving the future incoming requests.
Owner:NETSKOPE INC

ML based domain risk scoring and its applications to advanced URL filtering

The present application discloses a method, system, and computer system for providing real-time detection of malicious URLs based on a machine-learning powered domain risk scoring. The method includes (i) identifying a subset of higher risk websites, wherein the higher risk websites are at risk for potential malware injection or modification, and (ii) in response to identifying the subset of higher risk websites, performing an active measure based at least in part on the identified subset of higher risk websites.
Owner:PALO ALTO NETWORKS INC

Deep learning in a data plane

Various techniques for deep learning in a data plane are disclosed. In some embodiments, a system / process / computer program product for deep learning in a data plane includes monitoring a session at a security platform, wherein the session includes network traffic; executing a local deep learning model on the network traffic, wherein the local deep learning model is executed on the security platform; and performing an action in response to determining that the monitored session is associated with malware based at least in part on a verdict from the deep learning model.
Owner:PALO ALTO NETWORKS INC

Identification of variants of artificial intelligence generated malware

Source code for a type of malware is received. For example, the source code may be source code from a type of computer virus. An Artificial Intelligence (AI) algorithm is identified. For example, the AI algorithm may be ChatGPT. The source code of the type of malware is run through the AI algorithm to produce mutated source code for the type of malware. A prediction algorithm is used to predict a signature of the mutated source code for the type of malware. For example, the prediction algorithm is trained using existing source code of different types of malware to generate a prediction model. The signature of the mutated source code for the type of malware is then compared to a signature of a potentially new type of malware to determine if the signatures are similar.
Owner:MICRO FOCUS LLC

Indicating infected snapshots in a snapshot chain

Subject matter related to data management is discussed. A most recent snapshot in a snapshot chain that is not infected by malware may be identified based on mounting snapshots in the snapshot chain and determining whether the snapshots are infected. A graphical user interface showing individual snapshots in the snapshot change and indicating whether the snapshot is infected with malware may be displayed. The graphical user interface may provide a recover function for non-infected snapshots and may not enable the recover function for infected snapshots. A command to recover a non-infected snapshot in the snapshot chain may be received. Based on receiving the command, the non-infected snapshot may be recovered.
Owner:RUBRIK INC

Specific file detection baked into machine learning pipelines

A set of features including a first feature and a second feature is received at a server. A subset of the set of features is determined for use in generating a model usable by a device to locally make a malware classification decision. The device has reduced computing resources as compared to computing resources of the server. The subset of the set of features is used to generate the model. The generated model includes the first feature and does not include the second feature. A determination is made, at a time subsequent to the generation of the model, that an updated model should be deployed to the device. An updated model is generated.
Owner:PALO ALTO NETWORKS INC

Using cross workloads signals to remediate password spraying attacks

A method for detecting password spray attacks. The method includes obtaining information from an on-machine malware detection application for a particular machine indicating that a password spray tool is detected on the particular machine. Information is obtained indicating that the particular machine has performed failed sign in attempts. As a result, a determination is made that the particular machine is performing password spray attacks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Rule generation using entropy profile for malware detection

In some embodiments, a method receives a file. The file is packed using a packing method. An entropy profile is generated for the file. The entropy profile describes an entropy of data over positions in the file. The method generates a rule to detect the entropy profile of the file by analyzing entropy values from the entropy profile in slices in the file. The rule is output. The rule is usable to detect in other files that use the packing method based on analyzing entropy in slices of the other files.
Owner:SALESFORCE INC

Block chain-based trusted IoT (Internet of Things) access method and equipment

The embodiment of the invention provides a trusted IoT (Internet of Things) access method and equipment based on a block chain. The method is applied to the technical field of communication, and comprises the following steps: firstly, generating a key for the Internet of Things in a TEE environment of an intelligent gateway, encrypting a resource address of an Internet of Things device, preventing the key from being acquired by malicious software, preventing the key from being counterfeited, and ensuring the security of the Internet of Things device accessing a block chain network, and a block chain stores a key index instead of the key, so that the security of the Internet of Things device accessing a block chain network is ensured. The risk of key leakage is further reduced; by setting a device management contract and a policy authority contract, the authority of a user for accessing the Internet of Things device is inquired and managed, fine control of the access authority is realized, and only the user having the authority can obtain a corresponding secret key from an intelligent gateway to decrypt an encrypted resource address provided in a block chain. According to the arrangement, leakage of the resource address is effectively prevented, and sensitive information is prevented from being leaked.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD

Electric power industrial control system malicious software identification and analysis method based on artificial intelligence

The invention relates to the technical field of malicious software identification and analysis, and discloses an electric power industrial control system malicious software identification and analysis method based on artificial intelligence, and the method comprises the steps: collecting static operation sample data and dynamic operation sample data of software in an electric power working condition system in a software test environment, and carrying out the feature extraction; performing feature fusion on the static feature sequence and the dynamic feature sequence by using a physical information neural network based on an improved feature dimension reduction strategy; and classifying the fusion features of the software by adopting a local mean neighbor classification model of a fusion heuristic algorithm to obtain software categories corresponding to the fusion features. According to the method, feature adaptive fusion is realized by combining improved feature dimension reduction and a physical information neural network, and higher classification precision and robustness are realized under the support of optimal subset and neighbor number selection by combining a local mean neighbor classification method of a heuristic algorithm, so that the identification performance of the malicious software of the electric power industrial control system is effectively improved.
Owner:北京珞安科技有限责任公司

Systems and methods for threat detection and warning

The present disclosure relates generally to computer security, and, more particularly, to systems and methods for assisting a user in avoiding the accidental disclosure of confidential or sensitive information, as well as avoiding potential security breaches, including phishing and impersonation, malware, and security issues, particularly with respect to websites and electronic communications.
Owner:MIMECAST SERVICES LTD

System and method for automated machine-learning, zero-day malware detection

Improved systems and methods for automated machine-learning, zero-day malware detection. Embodiments include a system and method for detecting malware using multi-stage file-typing and, optionally pre-processing, with fall-through options. The system and method receive a set of training files which are each known to be either malign or benign, partition the set of training files into a plurality of categories based on file-type, in which the partitioning file-types a subset of the training files into supported file-type categories, train file-type specific classifiers that distinguish between malign and benign files for the supported file-type categories of files, associate supported file-types with a file-type processing chain that includes a plurality of file-type specific classifiers corresponding to the supported file-types, train a generic file-type classifier that applies to file-types that are not supported file-types, and construct a composite classifier using the file-type specific classifiers and the generic file-type classifier.
Owner:BLUVECTOR INC

Malicious code detection method based on behavior analysis

The invention relates to the technical field of malicious software detection, in particular to a malicious code detection method based on behavior analysis, which comprises the following steps of: monitoring a system event stream and process resource occupation data, fixed time interval sampling is adopted to capture a network data packet arrival time interval, CPU occupancy rate fluctuation, a target file lock contention state and a mouse cursor pixel position. According to the method, multi-dimensional system event streams and process resource occupation data such as network data packet arrival time intervals, CPU occupancy rate fluctuation, target file lock contention states and mouse cursor pixel positions are monitored, mutual information entropy between different event streams is calculated, and hidden association which cannot be perceived by a traditional detection method can be revealed. The mode is no longer limited to analysis of isolated behaviors of a single process, but captures weak signals generated when malicious software performs communication or data leakage by using a covert channel by quantifying statistical dependency between seemingly unrelated events.
Owner:江苏中控普惠信息科技有限公司

System and method for security platform and services for protecting an artificial intelligence system and its components against threats, risks and vulnerabilities

A system for a security platform and services for protecting an artificial intelligence system, comprising: wherein the security platform detects all events and creates a log of anomalous events; wherein a detector detects malware based on the anomalous events; wherein the security platform analyzes the malware by creating a risk analysis based on each detected malware; wherein based on the risk analysis, the security platform engages in adversarial threat mapping; wherein adversarial threat mapping includes input filtering, output filtering and masking; wherein the security platform also tracks the malware utilizing a variety of tracking services; wherein, if malware is detected, then the security platform informs a user of the system that the user has been hacked; wherein if the malware is contained, the security platform attempts to identify where the malware came from; wherein 1 form of finding an origin of the malware is engaging in incident correlation.
Owner:TAG SECURITY NETWORKS INC

LLM technology for polymorphic generation of samples of malware for future malware detection

Systems, methods, and computer-readable media are disclosed for detecting a malware sample by creating polymorphic variants of a malware sample using a large language model. The technology can obtain a known malware sample and decompose the known malware sample into behavioral characterizations of the known malware sample that correspond to respective processes taken by the known malware sample. The technology can then train a large language model with data corresponding to the behavioral characterizations and generate polymorphic variants of the known malware sample with a large language model based on the behavioral characterizations. When the technology later receives a potential malware sample, it can analyze the potential malware sample by comparing the potential malware sample to the polymorphic variants of the known malware sample generated by the large language model.
Owner:CISCO TECHNOLOGY INC

Large language model (LLM) powered detection reasoning solution

Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and / or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.
Owner:PALO ALTO NETWORKS INC

Techniques for detecting malicious software in a computing asset

Some embodiments provide techniques for detecting presence of malicious software in a computing asset. The techniques identify, from among a plurality of memory locations allocated for use by a process managed by an operating system (OS) associated with the computing asset, memory location(s) to monitor in furtherance of detecting presence of malicious software in the computing asset, monitor threads initialized by the process using the identified memory location(s) to determine a number of threads so initialized, identify value(s) for visibility characteristic(s) of the process indicative of whether the process is attempting to evade detection of its execution on the computing asset, and determine whether the process is a malicious software process based on the number of threads and the value(s) for the visibility characteristic(s).
Owner:RAPID7 INC

Expert system for detecting malware in binaries

This disclosure describes an expert system that can be used to automatically understand the function of a binary. The expert system includes a large language model (LLM) to determine investigatory steps that are implemented by a suite of tools. One application is malware detection. The expert system uses the tools to gather data and manipulate the binary to gain greater understanding of its function. Data generated during the investigation can be stored and retrieved from a memory representation system. This involves the LLM designing an investigation plan based on both default choices and responses to the data gathered using the tools. The expert system can adjust the plan after each step. Translators use expert knowledge and understanding of tool functions to convert tool outputs into natural language prompts that can be meaningfully understood by the LLM and to convert natural language output by the LLM into calls to the tools.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Ground truth determination for network detections on text-based protocols by llm

PendingUS20260050774A1Ensemble learningBiological modelsGround truthText-based protocol
The present application discloses a method, system, and computer system for enriching a ground truth of a machine learning-based detection using a large language model (LLM). The method includes: (a) obtaining a machine learning (ML)-based prediction for a security detection, (b) prompting a large language model (LLM) for an LLM-based prediction for the security detection based at least in part on a set of examples of malware, and (c) determining a ground truth of the ML-based prediction for the security detection based at least in part on a response from the LLM.
Owner:PALO ALTO NETWORKS INC

Classifying cybersecurity threats using machine learning on non-euclidean data

Systems, methods, and devices for cybersecurity are disclosed herein that can employ machine learning approaches with a better understanding of the complex relationships and sequencing associated with behavior-based data, and that can effectively apply machine learning for behavior-based analysis, malware detection, and identifying and classifying threats in real-time.
Owner:SENTINELONE INC

Method for detection of malware

For improving the efficiency of malware detection, a method is proposed that can handle computer files (1) of varying types and sizes and at the same time maintain a high detection performance by classifying a number of different types (A, B, C, D, E) of images (4), each calculated or derived from a particular computer file under test (1) (CFUT), using artificial intelligence methods such as machine learning, in particular deep learning, for example as provided by neuronal networks (24) or supervised deep learning algorithms. The different image types (A, B, C, D, E) are generated using different image conversion techniques and a number of approaches are presented for computing images (4) of uniform size Si that contain relevant information for classifying the CFUT (1).
Owner:INLYSE GMBH

Quantum-enhanced multi-modal large language model security protection

Disclosed are various embodiments for quantum-enhanced multi-modal large language model (LLM) security protection. Various embodiments can receive a request to cause an LLM to process a text prompt and a multimedia input. The prompt request can include the text prompt and the multimedia input, which are comprised of multimedia bits. Various embodiments can convert the multimedia bits of the multimedia input into quantum bits (qubits) of a quantum multimedia representation. Various embodiments can then direct a quantum computing device to identify the presence of one or more attributes (e.g., threats, malware, etc.) within the quantum multimedia representation that could be harmful to the LLM, if processed. Various embodiments can then prevent the LLM from processing the text prompt and multimedia input in response to identifying the presence of the one or more attributes within the quantum multimedia representation.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Data enhancement method and system for Android malicious software family classification

The invention belongs to the technical field of network technology and security correlation, and discloses a data enhancement method and system for Android malicious software family classification, and the method comprises the steps: generating an adversarial sample based on a target sample, and carrying out the data enhancement of a target small family; wherein the reinforcement learning strategy network is constructed to generate a selection probability according to an original sample; establishing a reward function, wherein the reward value is higher when the classification result of the disturbed sample is closer to the target small family more easily; training the strategy network according to the reward value and selecting a target sample; and performing family tree analysis on samples in the target small family, and generating an evolution sample according to a family evolution path to perform data enhancement. According to the invention, the discrimination capability of the model near the boundary is improved by using the adversarial sample; the evolution sample improves the distribution density and the coverage range of the small categories in the space, the adversarial sample and the evolution sample are organically combined, and a new technical approach is provided for solving the family classification problem under long-tail distribution.
Owner:HUAZHONG UNIV OF SCI & TECH

Android malicious software dynamic detection method fusing API sequence semantics and graph structure features

The invention discloses an Android malicious software dynamic detection method fusing API sequence semantics and graph structure features. The method comprises the following steps that an Android application program runs in a simulator environment, a runtime log is monitored and collected, an API method name sequence is extracted from the log, and calling sequence semantic information is reserved; constructing a global API dependency relationship graph based on a point-by-point mutual information PMI theory; generating joint feature representation by combining semantic embedding and graph structure embedding, including semantic embedding, graph structure embedding and joint embedding; inputting the fusion embedding into a pre-training BERT encoder, extracting features through a self-attention mechanism, and outputting a detection result through a classifier by using [CLS] flag bit vectors; according to the method, the detection performance is remarkably improved, and the method has high practical application value.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Automated generation of behavioral signatures for malicious web campaigns

Techniques for automated generation of behavioral signatures for malicious web campaigns are disclosed. In some embodiments, a system / process / computer program product for automated generation of behavioral signatures for malicious web campaigns includes crawling a plurality of web sites associated with a malware campaign; determining discriminating repeating attributes (e.g., behavior related attributes, which can be determined using dynamic analysis, and static related attributes, which can be determined using static analysis) as malware campaign related footprint patterns, wherein the discriminating repeating attributes are not associated with benign web sites; and automatically generating a human-interpretable malware campaign signature based on the malware campaign related footprint patterns.
Owner:PALO ALTO NETWORKS INC

System and method for securely connecting to a peripheral device

A device connectable between a host computer and a computer peripheral over a standard bus interface is disclosed, used to improve security, and to detect and prevent malware operation. Messages passing between the host computer and the computer peripherals are intercepted and analyzed based on pre-configured criteria, and legitimate messages transparently pass through the device, while suspected messages are blocked. The device communicates with the host computer and the computer peripheral using proprietary or industry standard protocol or bus, which may be based on a point-to-point serial communication such as USB or SATA. The messages may be stored in the device for future analysis, and may be blocked based on current or past analysis of the messages. The device may serve as a VPN client and securely communicate with a VPN server using the host Internet connection.
Owner:GATEKEEPER LTD