Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

30 results about "Malware analysis" patented technology

Malware analysis is the study or process of determining the functionality, origin and potential impact of a given malware sample such as a virus, worm, trojan horse, rootkit, or backdoor. Malware or malicious software is any computer software intended to harm the host operating system or to steal sensitive data from users, organizations or companies. Malware may include software that gathers user information without permission.

Malware analysis of data / files prior to storage in isolated secure environment

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.
Owner:PALO ALTO NETWORKS INC

Malware analysis continuation system and malware analysis continuation method

ActiveUS20250291919A1Platform integrity maintainanceMalware analysisEngineering
Communication of dynamically analyzed malware is mediated. Even in a case where communication with the attacker server is stopped, a response accumulated as past data is returned to continue dynamic analysis.
Owner:HITACHI LTD

Execution behavior analysis text-based ensemble malware detector

A malware detector has been designed that uses a combination of NLP techniques on dynamic malware analysis reports for malware classification of files. The malware detector aggregates text-based features identified in different pre-processing pipelines that correspond to different types of properties of a dynamic malware analysis report. From a dynamic malware analysis report, the pre-processing pipelines of the malware detector generate a first feature set based on individual text tokens and a second feature set based on n-grams. The malware detector inputs the first feature set into a trained neural network having an embedding layer. The malware detector then extracts a dense layer from the trained neural network and aggregates the extracted layer with the second feature set to form an input for a trained boosting model. The malware detector inputs the cross-pipeline feature values into the trained boosting model to generate a malware detection output.
Owner:PALO ALTO NETWORKS INC

Identification method, system and equipment for open set shelled software and medium

PendingCN121256784APlatform integrity maintainanceMalware analysisFeature vector
The invention relates to the technical field of recognition for open set shelled software, in particular to a recognition method, system, equipment and medium for open set shelled software, which comprises the following steps of: extracting function call graph structure information from a binary executable file to be recognized through a disassembling tool and a user-defined plug-in thereof; generating a structured graph representation file; on the basis of the graph representation file, graph statistical features and file section structure features are extracted, and a spliced feature vector is formed; and based on a multi-model single-class identification strategy constructed for open set identification, carrying out classification identification on the binary executable file corresponding to the current feature vector. The method has the beneficial effects that the identification efficiency of the shelled software is integrally improved, the detection capability of the unknown type of shelled software is particularly enhanced, and powerful support is provided for dynamic malicious software analysis.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

A Malware Analysis Method and Device Based on the PE File Format

ActiveCN116192462BSecuring communicationMalware analysisFeature vector
This application relates to the field of network information security technology, and in particular, to a method and device for malicious software analysis based on the PE file format. In this method, multiple PE files are obtained. The multiple PE files are parsed to obtain file information. According to the file information, the feature vectors corresponding to the multiple PE files are determined. Each feature vector in the feature vector set is clustered to obtain a cluster set. Among them, the similarity between any feature vectors included in any cluster in the cluster set is less than or equal to the first threshold. Each cluster in the cluster set is clustered to obtain a target cluster set. Among them, the similarity between any clusters included in any target cluster in the target cluster set is less than or equal to the second threshold, and the second threshold is greater than the first threshold. The target cluster set is displayed. The above solution uses a clustering method to analyze malicious software in the PE file format, improving the efficiency of malicious software analysis.
Owner:NSFOCUS INFORMATION TECHNOLOGY CO LTD +1

Security detection method and device of mobile application, computer equipment and storage medium

The embodiment of the invention discloses a security detection method and device of a mobile application, computer equipment and a storage medium. The method comprises the following steps: acquiring an installation package file of a target mobile application, and acquiring a decompiled file of the installation package file; performing static risk detection on the decompiled file according to a static risk analysis rule to obtain a static risk analysis result; configuring a Hook point of dynamic instrumentation for the target mobile application according to a static risk analysis result; running the target mobile application, and obtaining running behavior data of the target mobile application through the Hook point; performing dynamic risk detection on the operation behavior data according to a dynamic risk analysis rule to obtain a dynamic risk analysis result; performing feature matching on a preset malicious software feature library and the decompiled file to obtain a malicious software analysis result; and generating a security detection result of the target mobile application according to each analysis result. By implementing the method provided by the embodiment of the invention, the security detection precision of the mobile application can be improved.
Owner:SHENZHEN YEAHKA TECH

Ontology mapping system

ActiveUS12689651B2Malware analysisTheoretical computer science
An article of manufacture includes a non-transitory medium including machine-readable instructions. The instructions are to be read and executed by a processor. The instructions, when read and executed by the processor, to cause the processor to receive a malware analysis of a malware from a computer security source and receive other malware analyses. Each other malware analysis is of another malware from another computer security source. The instructions may further cause the processor to perform a fuzzy matching algorithm to quantify a similarity of the malware analyses, determine that the malware is a same malware as other malware based upon results of the fuzzy matching algorithm, and later take a same corrective action for malware based upon a receipt of the malware analysis.
Owner:SECURONIX INC

An Android software static analysis method based on hybrid mode

This invention proposes a hybrid-mode-based static analysis method for Android software, belonging to the field of malware analysis technology. It primarily addresses the accuracy degradation problem caused by existing Android cross-language static analysis frameworks using function digests for inter-function data flow connections. The main solutions include: function-level data flow analysis of the Android Java layer; lightweight inter-function data dependency analysis of the Android Native layer, generating dynamic function digests for each function; and full-program data flow analysis of the Android Java layer, where data flow connections involving Native function calls are reconstructed using function digests.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA +1

A malware analysis system and method

The present application provides a kind of malware analysis system and method, belong to malware analysis field.The system includes: sample acquisition module, for utilizing multiple acquisition methods to collect malware samples, and the malware samples are stored;Threat intelligence integration module, for utilizing multiple platforms to collect threat intelligence, and the threat intelligence is integrated and stored;Automated analysis module, utilizes automated analysis tool, combines analysis process and automated process, generates the automated analysis result of malware;Result verification module, utilizes selected verification method, combines multiple verification indexes, and the credibility of automated analysis result is checked;And report generation module, generates corresponding defense measures, generates malware analysis report.The present application improves the update speed of threat intelligence and the detection efficiency of new malware, reduces the false alarm rate, improves the determination accuracy, shortens the deployment time of defense measures, and reduces the amount of manual operation.
Owner:HUANENG INFORMATION TECH CO LTD

Software analysis method and device, computer device, medium and program product

ActiveCN116346402BSecuring communicationMalware analysisThe Internet
The application relates to a software analysis method and device, computer equipment, a storage medium and a computer program product. The method comprises the following steps: obtaining request information of software to be analyzed, and sending the request information to a target address; obtaining real response traffic generated by the target address based on the request information, and generating simulation response traffic based on the real traffic; sending the simulation response traffic to the software to be analyzed, and obtaining behavior data generated by the software to be analyzed based on the simulation response traffic. The application solves the problem that malicious software analysis cannot be performed in the case of no Internet environment or loss of effectiveness of the software to be analyzed, and improves the accuracy of malicious software analysis.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Distributed malware detection system and submission workflow thereof

A computerized method for cluster selection is described. Initially, a cloud-based enrollment service advertises features and capabilities of clusters performing malware analyses within a cloud-based malware detection system. Upon receiving an enrollment request message, including tenant credentials associated with a sensor having an object to be analyzed for malware, the cloud-based enrollment service returns an enrollment response message. The tenant credentials are used to authenticate the sensor and determine a type of subscription assigned to the sensor. The enrollment response message includes a portion of the advertised features and capabilities of a selected cluster of the cloud-based malware detection system in response to the sensor being authenticated. The portion of the advertised features and capabilities enables the sensor to establish communications with the selected cluster.
Owner:MAGENTA SECURITY HOLDINGS LLC

Artificial intelligence-based malicious code analysis reverse engineering large model training method

PendingCN122507398AMalware analysisAlgorithm
This invention discloses a method for training a large-scale reverse engineering model for malware analysis based on artificial intelligence, relating to the field of malware analysis technology. The method includes: assigning unified closed-loop identifiers to closed-loop source samples in a closed-loop source sample library for malicious behavior and vulnerability exploitation; generating closed-loop aligned intermediate representations; constructing shadow execution control samples based on a shadow redirection mechanism to obtain effective closed-loop aligned intermediate representations and corresponding shadow execution control samples; inputting the effective closed-loop aligned intermediate representations and corresponding shadow execution control samples into a dedicated training architecture, sequentially performing closed-loop consistency pre-training, supervised fine-tuning, and closed-loop evidence distillation processes to obtain a dedicated large-scale model for reverse engineering; performing reverse processing on the target sample to be tested to generate closed-loop aligned intermediate representations, inputting these representations into the dedicated large-scale model for reverse engineering, outputting structured analysis results, and writing the structured analysis results, which have undergone closed-loop integrity verification, into a security knowledge base.
Owner:ETHEREUM (BEIJING) TECHNOLOGY CO LTD

Multi-dimensional malware analysis

There is disclosed a computer-implemented system and method of analyzing a batch of objects, including bucketizing the batch of objects into a plurality of buckets according to a feature of the objects; for objects within a batch, performing malware analysis on the objects to assign a malware analysis score, and adjusting the malware analysis score based on the batch; and performing respective security actions on the objects within the batch, based on the adjusted malware analysis score.
Owner:MCAFEE LLC

Malicious software feature automatic conversion and unified management method, system and device based on MAEC standard and storage medium

The invention relates to the technical field of network security, in particular to an automatic malicious software feature conversion and unified management method, system and device based on an MAEC standard and a storage medium. The method comprises the following steps: acquiring a malicious software analysis report and analyzing static feature and dynamic feature data, establishing a field semantic mapping relationship based on a preset rule base, and automatically associating features to a behavior tag, a capability tag and a feature tag of an MAEC standard; feature extraction, mapping and standard object generation are achieved through a Python script, malicious software instance objects and behavior objects in the MAEC data model are instantiated, the incidence relation between the objects is created, and a structured description file meeting the MAEC-5. 0 standard is generated; performing semantic classification on the generated malicious software behavior objects, classifying the behavior objects related to semantics into behavior entities, and establishing a hierarchical relationship; a MongoDB and MySQL dual-database architecture is established to store an original report and structured data, and automatic operation is realized through a Linux timed task.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

Enhanced live virtual machine file system instrumentation for security analysis

Techniques for providing enhanced live virtual machine file system instrumentation for security analysis are disclosed. In some embodiments, a system / process / computer program product for providing enhanced live virtual machine file system instrumentation for security analysis includes receiving a sample for automated dynamic analysis using a computing environment; freezing time in the computing environment in response to detecting an event during execution of the sample in the computing environment and reassemble one or more files; and performing an automated malware analysis using results of the automated dynamic analysis and the one or more reassembled files.
Owner:PALO ALTO NETWORKS INC

Malicious software dynamic analysis-oriented automatic interaction method for data between virtual machine and host

The invention relates to a malicious software dynamic analysis-oriented automatic interaction method for data between a virtual machine and a host, which comprises the following steps of: S1, initializing the virtual machine, copying a daemon and a dynamic execution program to the virtual machine, and storing a current virtual machine snapshot; s2, resetting the virtual machine to the stored virtual machine snapshot, compressing a to-be-detected sample program, sending the compressed to-be-detected sample program to the virtual machine, and starting a daemon; s3, the virtual machine decompresses the compressed sample, and a dynamic execution program is used for testing; s4, the host program sends a keyboard event to simulate keyboard keys, and file copying is executed; and S5, when the host program detects that the virtual machine daemon program is ended, decompressing the compressed track flow file to a specified directory, finishing transmission of the decompressed track flow file, resetting the state of the virtual machine until the snapshot is stored, analyzing the track flow file, and finishing analysis and test of the malicious software. A network port and a shared directory do not need to be opened, risks caused in the transmission process are reduced, and the implementation is safer.
Owner:QUAN CHENG LABORATORY

A hierarchical classification-based method and system for malware analysis

ActiveCN121525038BPlatform integrity maintainanceCosine similarityMalware analysis
This application provides a hierarchical classification-based method and system for malware analysis. The application relates to the technical field of data processing, and includes: acquiring malware samples to be analyzed; extracting features from the malware samples to obtain feature vectors; inputting the feature vectors into a preset hierarchical classification model to obtain hierarchical classification results of the malware samples; calculating the contribution of each feature in the feature vector to each classification node in the hierarchical classification results; constructing high-dimensional numerical vectors based on the contribution; calculating the cosine similarity between the high-dimensional numerical vectors of different classification nodes; and performing correlation analysis on the cosine similarity to obtain a correlation analysis report between different malware categories. By using a hierarchical classification model to determine the family category and variant category of malware samples level by level, this method overcomes the problems of insufficient classification granularity, difficulty in characterizing category differences, and difficulty in analyzing category correlations when dealing with complex family systems or multiple variant malware.
Owner:JIANGXI INST OF FASHION TECH

Automatic malware detection method based on multiple features

The present invention discloses a multi-feature-based automated malware detection method, comprising the following steps: step S1: preprocessing data; step S2: extracting features from the data to obtain a feature vector; step S3: effectively aligning and fusing the binary feature vector obtained in the above step S2 and the operation code feature vector generated by the triangular attention mechanism to generate a final fusion vector; step S4: detecting and classifying malware; the present invention can more effectively detect malware variants with a higher accuracy. In an actual production environment, the present invention enhances the performance of automatic malware analysis tools by increasing the recognition efficiency of malware variants, thereby reducing labor costs.
Owner:SICHUAN UNIV

Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program

A cyber threat information processing method, a cyber threat information processing processor, and a storage medium storing a program for processing cyber threat information may process an executable file to ensure characteristic information of the executable file, transmit the ensured characteristic information of the executable file over an independent network, and receive malware profiling information generated based on the characteristic information of the executable file over the independent network.
Owner:SANDS LAB INC

Mobile application security detection method and device, computer device and storage medium

Embodiments of the present application disclose a mobile application security detection method and device, a computer device and a storage medium. The method comprises: obtaining an installation package file of a target mobile application, and obtaining a decompiled file of the installation package file; performing static risk detection on the decompiled file according to a static risk analysis rule to obtain a static risk analysis result; configuring a dynamic plug-in Hook point for the target mobile application according to the static risk analysis result; running the target mobile application, and obtaining running behavior data of the target mobile application through the Hook point; performing dynamic risk detection on the running behavior data according to a dynamic risk analysis rule to obtain a dynamic risk analysis result; performing feature matching on a preset malicious software feature library and the decompiled file to obtain a malicious software analysis result; and generating a security detection result of the target mobile application according to each analysis result. The security detection accuracy of the mobile application can be improved by implementing the method of the embodiments of the present application.
Owner:SHENZHEN YEAHKA TECH

Intranet environment infected botnet machine troubleshooting processing method, device, equipment and medium

PendingCN121333751ASecuring communicationMalware analysisInternet traffic
The invention provides a troubleshooting processing method, device, equipment and medium for a botnet infected machine in an intranet environment, and the method comprises the steps: carrying out the abnormality analysis of network flow and network behaviors corresponding to an intranet, so as to determine target equipment infected by a botnet from a plurality of pieces of communication equipment in communication connection with the intranet; isolating the target equipment from the intranet; the propagation module is used for carrying out malicious software analysis on the target equipment so as to extract the botnet from the target equipment; embedding an executable code corresponding to the propagation module into a preset special killing tool to obtain a disposal tool; the method comprises the following steps: comprehensively scanning an intranet environment through a disposal tool to determine transmission equipment with botnet infection; botnet clearing and reinforcement protection are performed on the target device and the propagation device, so that the protection capability of the infected machine in the intranet is further enhanced, and it is ensured that the infected machine does not become an attack target of the Botnet any more.
Owner:BEIJING ANTIY NETWORK SAFETY TECH CO LTD +1

Explainable malware analysis

Embodiments of the present disclosure relate to explainable malware analysis. Systems, methods, and software can be used to detect malware files. In some aspects, a method includes obtaining features from a binary file to be classified as a malware file or a non-malware file; inputting the obtained features to a first trained machine learning model; outputting, by the first trained machine learning model, an encoding vector; inputting the encoding vector to a second trained machine learning model that generates text as an output; and outputting, by the second trained machine learning model, a human understandable textual explanation of malicious activities that can be performed by the binary file, the human understandable textual explanation being generated without executing the binary file, the textual explanation supporting classification of the binary file.
Owner:BLACKBERRY LTD

Malicious software analysis system and method based on semantic embedding

PendingCN121569295APlatform integrity maintainanceMalware analysisCpu architecture
The invention provides a malicious software analysis system based on semantic embedding. The system comprises an input interface, a file parser, a cross-CPU architecture disassembling module, a deployed and similarity analysis module, an output interface and a malicious software similarity model training module. The input interface receives and converts suspicious malware into a machine readable format. A file parser pre-processes a binary file to generate a normalized binary file by detecting and reversing a bypass technique in a sandbox. The cross-CPU disassembly module lifts the binary file to an intermediate representation (IR), extracts and normalizes the function, and generates a function base block (NF). The deployed embedding model translates the function base block into semantic embedding. And the similarity analysis module queries the malicious sample library by using the embedded vector, calculates a similarity score and generates an analysis result containing a potential malicious software family. The output interface generates a malware report. The training module is used for offline training, and the trained model is used for runtime analysis.
Owner:HONG KONG APPLIED SCI & TECH RES INST

Systems and methods for A.I.-based malware analysis on offline endpoints in a network

Disclosed herein are systems and method for optimizing artificial intelligence (A.I)-based malware analysis on offline endpoints in a network. In one aspect, a method includes identifying a file that has not been executed on an endpoint system and scanning the endpoint system to detect malicious behavior using a machine learning algorithm. In response to determining that the endpoint system does not exhibit malicious behavior based on the machine learning algorithm, the method includes enabling execution of the file. Subsequent to the execution of the file, the method includes rescanning the endpoint system to detect malicious behavior using the machine learning algorithm. In response to determining that the endpoint system does exhibit malicious behavior subsequent to the execution, the method includes extracting attributes of the file and retraining the machine learning algorithm using the extracted attributes to detect malicious behavior associated with the file without having to execute the file.
Owner:ACRONIS INT

Anti-aging efficient malicious app detection method for constructing api correlation confidence

ActiveCN115203682BPlatform integrity maintainanceMalware analysisEngineering
The application relates to an anti-aging high-efficiency malicious APP detection method for constructing API correlation confidence, and belongs to the technical field of cyberspace security. First, the method is used for coping with the deviation caused by the continuous upgrading of an Android system on malicious software analysis by performing layer abstraction on API package names in APK files; second, the method is used for extracting high-level behavior semantics of software by calculating the correlation confidence between APIs; and finally, the method is used for completing the detection of malicious software by constructing classifiers for APKs in different release periods, selecting representative classifiers to learn the behavior patterns between API combinations, and completing the detection of malicious software. Current malicious software detection methods have weak software intention representation and anti-aging capability, and are difficult to detect continuously evolving and variant malicious software. The application establishes a high-level behavior intention representation mode, proposes an anti-aging strategy for a malicious software classifier, and can effectively detect continuously evolving malicious software, and has high detection efficiency and anti-aging property.
Owner:BEIJING INST OF TECH

Malicious software analysis system and method

The invention provides a malicious software analysis system and method, and belongs to the field of malicious software analysis. The system comprises a sample collection module used for collecting malicious software samples in multiple collection modes and storing the malicious software samples; the threat intelligence integration module is used for collecting threat intelligence by utilizing various platforms and integrating and storing the threat intelligence; the automatic analysis module is used for generating an automatic analysis result of the malicious software by utilizing an automatic analysis tool and combining the analysis process and the automatic process; the result verification module is used for carrying out credibility verification on the automatic analysis result by utilizing a selected verification method and combining various verification indexes; and the report generation module is used for generating corresponding defense measures and generating a malicious software analysis report. According to the method, the updating speed of threat intelligence and the detection efficiency of novel malicious software are improved, the false alarm rate is reduced, the judgment accuracy is improved, the defense measure deployment time is shortened, and the manual operation amount is reduced.
Owner:HUANENG INFORMATION TECH CO LTD

Malware behavior characteristic visualization method based on characteristic types and medium

The invention discloses a malicious software behavior feature visualization method based on feature types. The method comprises the following steps: extracting various features of malicious software; performing feature processing on each feature of the malicious software by adopting a corresponding processing mode; and carrying out visualization on each type of processed features. The method has the advantages that researchers can be helped to quickly identify similarity and difference between samples in the malicious software analysis process by integrating visualization modes of different types of features, so that the accuracy and efficiency of malicious software analysis are improved.
Owner:XUANCHENG VOCATIONAL & TECH COLLEGE

Execution behavior analysis text-based ensemble malware detector

A malware detector has been designed that uses a combination of NLP techniques on dynamic malware analysis reports for malware classification of files. The malware detector aggregates text-based features identified in different pre-processing pipelines that correspond to different types of properties of a dynamic malware analysis report. From a dynamic malware analysis report, the pre-processing pipelines of the malware detector generate a first feature set based on individual text tokens and a second feature set based on n-grams. The malware detector inputs the first feature set into a trained neural network having an embedding layer. The malware detector then extracts a dense layer from the trained neural network and aggregates the extracted layer with the second feature set to form an input for a trained boosting model. The malware detector inputs the cross-pipeline feature values into the trained boosting model to generate a malware detection output.
Owner:PALO ALTO NETWORKS INC

Systems and methods for selecting client backup files for maliciousness analysis

Disclosed herein are systems and methods for selecting files for malware analysis. In one aspect, a method may include identifying, in a cloud network, a backup of a client machine; extracting, from the backup, at least one file of a given file type; determining whether to include the at least one file in a sandbox of the cloud network by performing a static analysis of the at least one file; selecting the at least one file for inclusion in the sandbox based on the static analysis; monitoring, for a period of time, a behavior of the at least one file in the sandbox by performing a dynamic analysis of the at least one file; and in response to determining that the at least one file is malicious based on the dynamic analysis, performing a remediation action on the at least one file.
Owner:ACRONIS INT

Explainable malware analysis

PendingUS20260178735A1Platform integrity maintainanceMalware analysisArtificial intelligence
Systems, methods, and software can be used to detect a malware file. In some aspects, a method includes: obtaining features from a binary file to be classified as either a malware file or a non-malware file; inputting the obtained features to a first trained machine learning model; outputting, by the first trained machine learning model, an encoded vector; inputting the encoded vector to a second trained machine learning model, the second trained machine learning model generating text as output; and outputting, by the second trained machine learning model, a human-understandable text explanation of malicious activities that can be performed by the binary file, the human-understandable text explanation being generated without executing the binary file, the text explanation enabling a classification of the binary file.
Owner:BLACKBERRY LTD