Invention Grant
- Patent Title: Malware detection via data transformation monitoring
-
Application No.: US15759014Application Date: 2016-09-23
-
Publication No.: US10685114B2Publication Date: 2020-06-16
- Inventor: Walter N. Scaife , Patrick G. Traynor , Henry Carter , Kevin Butler
- Applicant: University of Florida Research Foundation, Incorporated
- Applicant Address: US FL Gainesville
- Assignee: University of Florida Research Foundation, Incorporated
- Current Assignee: University of Florida Research Foundation, Incorporated
- Current Assignee Address: US FL Gainesville
- Agency: Alston & Bird LLP
- International Application: PCT/US2016/053365 WO 20160923
- International Announcement: WO2017/053745 WO 20170330
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F21/56 ; G06F21/62

Abstract:
Techniques and systems are described for detecting malware's bulk transformation of a user's data before the malware is able to complete the data transformation. Included are methods and systems for enabling malware detection by monitoring the file operations of a computer application or process for particular kinds of suspicious data transformation indicators. Indicators include primary indicators, such as file-type signature changes, notable changes in file data entropy, and out-of-range similarity measurements between the read and write versions of file data, as well as secondary indicators, such as a large number of file deletions and a large reduction in the number of file-types written versus read by a process over time. When indicators are triggered by a process, an adjustment to the process' malware score is made; in the event that the process' malware score reaches a malware detection threshold, the process is marked as malware and appropriate actions are taken.
Public/Granted literature
- US20190228153A1 MALWARE DETECTION VIA DATA TRANSFORMATION MONITORING Public/Granted day:2019-07-25
Information query