Invention Grant
- Patent Title: Method and system for detecting malicious files using behavior patterns
-
Application No.: US16414832Application Date: 2019-05-17
-
Publication No.: US11227048B2Publication Date: 2022-01-18
- Inventor: Alexander S. Chistyakov , Alexey M. Romanenko , Alexander S. Shevelev
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO Kaspersky Lab
- Current Assignee: AO Kaspersky Lab
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: RU2018147233 20181228
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06N20/00 ; G06F21/56 ; G06F21/52 ; G06N3/08

Abstract:
Disclosed herein are methods and systems for detecting malicious files. An exemplary method comprises emulating execution of a file under analysis, forming a behavior log of the emulated execution of the file under analysis, forming one or more behavior patterns from commands and parameters selected from the behavior log, calculating a convolution of the one or more behavior patterns, selecting two or more models for detecting malicious files from a database, calculating a degree of maliciousness of the file being executed based using the convolution and the two or more models, forming a decision making template based on the degree of maliciousness and determining that the file is malicious when a degree of similarity between the decision making template and a predetermined decision making template exceeds a predetermined threshold value.
Public/Granted literature
- US20200210576A1 METHOD AND SYSTEM FOR DETECTING MALICIOUS FILES USING BEHAVIOR PATTERNS Public/Granted day:2020-07-02
Information query