Invention Grant
- Patent Title: Static anomaly-based detection of malware files
-
Application No.: US16115430Application Date: 2018-08-28
-
Publication No.: US10860720B2Publication Date: 2020-12-08
- Inventor: Andrew Thomas Hartnett , Douglas Stuart Swanson
- Applicant: Malwarebytes Inc.
- Applicant Address: US CA Santa Clara
- Assignee: MALWAREBYTES INC.
- Current Assignee: MALWAREBYTES INC.
- Current Assignee Address: US CA Santa Clara
- Agency: Fenwick & West LLP
- Main IPC: G06N5/02
- IPC: G06N5/02 ; G06N5/04 ; G06F21/56 ; G06N20/00 ; G06F21/55

Abstract:
A protection application detects and remediates malicious files on a client. The protection application trains models using known samples of static clean files, and the models characterize features of the clean files. A model may be selected based on metadata obtained from a target file. By processing features of the clean files and features of the target file, the model may generate an anomaly score indicating a level of dissimilarity between the target file and the sample. The protection application compares the anomaly score to one or more threshold scores to classify the target file. Additionally, the target file may be provided to a security server to check against a whitelist or blacklist for classification. Responsive to a classification as malicious, the protection application remediates the target file on the client.
Public/Granted literature
- US20190012460A1 STATIC ANOMALY-BASED DETECTION OF MALWARE FILES Public/Granted day:2019-01-10
Information query