Invention Grant
- Patent Title: Systems and methods for intercepting malicious messages based on application priority
-
Application No.: US16745425Application Date: 2020-01-17
-
Publication No.: US11323461B2Publication Date: 2022-05-03
- Inventor: Georgy A. Regentov
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO Kaspersky Lab
- Current Assignee: AO Kaspersky Lab
- Current Assignee Address: RU Moscow
- Agency: ArentFox Schiff LLP
- Agent Michael Fainberg
- Priority: RURU2019120221 20190628
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06N20/00 ; H04L29/06

Abstract:
Disclosed herein are systems and method for intercepting malicious messages for training a malware detection classifier. In an exemplary aspect, an application selection module may select, from a plurality of applications, an application for execution in an execution environment based on a priority level of the application. During the execution of the selected application, a network interception module may monitor network activity comprising information about data being sent and received over a network connected to the execution environment and storing the network activity in memory of the execution environment (e.g., in a network activity log). A message selection module may subsequently extract, from the stored network activity, an electronic message, in response to determining that the electronic message corresponds to the selected application, may storing the electronic message in a message database used for training the malware detection classifier.
Information query