Invention Grant
- Patent Title: System and method for detecting malicious scripts
-
Application No.: US16239942Application Date: 2019-01-04
-
Publication No.: US11574053B1Publication Date: 2023-02-07
- Inventor: Te-Ching Chen , Chih-Kun Ho , Yung-Hsiang Lee
- Applicant: Trend Micro Incorporated
- Applicant Address: JP Tokyo
- Assignee: Trend Micro Incorporated
- Current Assignee: Trend Micro Incorporated
- Current Assignee Address: JP Tokyo
- Agency: Beyer Law Group LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55 ; G06N20/00 ; G06F9/54 ; G06N5/00 ; G06F40/211 ; G06F40/284

Abstract:
An endpoint system receives a target file for evaluation for malicious scripts. The original content of the target file is normalized and stored in a normalized buffer. Tokens in the normalized buffer are translated to symbols, which are stored in a tokenized buffer. Strings in the normalized buffer are stored in a string buffer. Tokens that are indicative of syntactical structure of the normalized content are extracted from the normalized buffer and stored in a structure buffer. The content of the tokenized buffer and counts of tokens represented as symbols in the tokenized buffer are compared against heuristic rules indicative of malicious scripts. The contents of the tokenized buffer and string buffer are compared against signatures of malicious scripts. The contents of the tokenized buffer, string buffer, and structure buffer are input to a machine learning model that has been trained to detect malicious scripts.
Information query