Invention Grant
- Patent Title: Model development and application to identify and halt malware
-
Application No.: US15967024Application Date: 2018-04-30
-
Publication No.: US10956568B2Publication Date: 2021-03-23
- Inventor: Celeste R. Fralick , Jonathan King , Carl D. Woodward , Andrew V. Holtzmann , Kunal Mehta , Sherin M. Mathews
- Applicant: McAfee, LLC
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, LLC
- Current Assignee: McAfee, LLC
- Current Assignee Address: US CA Santa Clara
- Agency: Hanley, Flight & Zimmerman, LLC
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/60 ; H04L9/30

Abstract:
A method for halting malware includes: monitoring plural file system events with a system driver to detect an occurrence of a file system event having a predetermined file type and log event type; triggering a listening engine for file system event stream data of a file associated with the detection of the file system event, the file system event stream data indicating data manipulation associated with the file due to execution of a process; obtaining one or more feature values for each of plural different feature combinations of plural features of the file based on the file system event stream data; inputting one or more feature values into a data analytics model to predict a target label value based on the one or more feature values of the plural different feature combinations and agnostic to the process; and performing a predetermined operation based on the target label value.
Public/Granted literature
- US20190332769A1 MODEL DEVELOPMENT AND APPLICATION TO IDENTIFY AND HALT MALWARE Public/Granted day:2019-10-31
Information query