Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5 results about "Malware analysis" patented technology

Malware analysis is the study or process of determining the functionality, origin and potential impact of a given malware sample such as a virus, worm, trojan horse, rootkit, or backdoor. Malware or malicious software is any computer software intended to harm the host operating system or to steal sensitive data from users, organizations or companies. Malware may include software that gathers user information without permission.

Execution behavior analysis text-based ensemble malware detector

A malware detector has been designed that uses a combination of NLP techniques on dynamic malware analysis reports for malware classification of files. The malware detector aggregates text-based features identified in different pre-processing pipelines that correspond to different types of properties of a dynamic malware analysis report. From a dynamic malware analysis report, the pre-processing pipelines of the malware detector generate a first feature set based on individual text tokens and a second feature set based on n-grams. The malware detector inputs the first feature set into a trained neural network having an embedding layer. The malware detector then extracts a dense layer from the trained neural network and aggregates the extracted layer with the second feature set to form an input for a trained boosting model. The malware detector inputs the cross-pipeline feature values into the trained boosting model to generate a malware detection output.
Owner:PALO ALTO NETWORKS INC

Ontology mapping system

ActiveUS12689651B2Malware analysisTheoretical computer science
An article of manufacture includes a non-transitory medium including machine-readable instructions. The instructions are to be read and executed by a processor. The instructions, when read and executed by the processor, to cause the processor to receive a malware analysis of a malware from a computer security source and receive other malware analyses. Each other malware analysis is of another malware from another computer security source. The instructions may further cause the processor to perform a fuzzy matching algorithm to quantify a similarity of the malware analyses, determine that the malware is a same malware as other malware based upon results of the fuzzy matching algorithm, and later take a same corrective action for malware based upon a receipt of the malware analysis.
Owner:SECURONIX INC

Explainable malware analysis

Embodiments of the present disclosure relate to explainable malware analysis. Systems, methods, and software can be used to detect malware files. In some aspects, a method includes obtaining features from a binary file to be classified as a malware file or a non-malware file; inputting the obtained features to a first trained machine learning model; outputting, by the first trained machine learning model, an encoding vector; inputting the encoding vector to a second trained machine learning model that generates text as an output; and outputting, by the second trained machine learning model, a human understandable textual explanation of malicious activities that can be performed by the binary file, the human understandable textual explanation being generated without executing the binary file, the textual explanation supporting classification of the binary file.
Owner:BLACKBERRY LTD

Explainable malware analysis

PendingUS20260178735A1Platform integrity maintainanceMalware analysisArtificial intelligence
Systems, methods, and software can be used to detect a malware file. In some aspects, a method includes: obtaining features from a binary file to be classified as either a malware file or a non-malware file; inputting the obtained features to a first trained machine learning model; outputting, by the first trained machine learning model, an encoded vector; inputting the encoded vector to a second trained machine learning model, the second trained machine learning model generating text as output; and outputting, by the second trained machine learning model, a human-understandable text explanation of malicious activities that can be performed by the binary file, the human-understandable text explanation being generated without executing the binary file, the text explanation enabling a classification of the binary file.
Owner:BLACKBERRY LTD