Method of malware detection and system thereof

US11625485B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11625485-B2
Application numberUS-202016849808-A
CountryUS
Kind codeB2
Filing dateApr 15, 2020
Priority dateAug 11, 2014
Publication dateApr 11, 2023
Grant dateApr 11, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

There is provided a system and a computer-implemented method of detecting malware in real time in a live environment. The method comprises: monitoring one or more operations of at least one program concurrently running in the live environment, building at least one stateful model in accordance with the one or more operations, analyzing the at least one stateful model to identify one or more behaviors, and determining the presence of malware based on the identified one or more behaviors.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computer-implemented method of performing a behavior-based analysis of an execution of a program in an operating system, the method comprising: monitoring, by a computer system, by registering one or more kernel filter drivers for kernel space operations via one or more call back functions using an out-of-band monitoring module, one or more operations performed by the execution of the program running in the operating system in a live environment, wherein the monitoring comprises tracking user space operations and the kernel space operations; selecting at least one operation of interest from the one or more operations; generating, by the computer system, an event data for each of the at least one operation of interest, wherein the event data characterizes one or more events of the at least one operation of interest; filtering event data of interest from the event data for each of the at least one operation of interest, the filtering based on one or more predefined filtering rules; normalizing the event data of interest into a logical data structure such that attributes of the event data of interest can accessed and analyzed; building, by the computer system, at least one stateful model of the execution of the program based on the normalized event data of interest, the at least one stateful model comprising a hierarchal structure of the at least one operation of interest performed by the execution of the program in the live environment, the at least one operation of interest linked by an event context, wherein the hierarchal structure comprises: the event context comprising: one or more objects derived from the one or more monitored operations; one or more fields generated for each of the one or more objects, the one or more fields storing one or more parameters characterizing a respective object of the one or more objects and an associate to the respective object; and one or more relationships identified among the one or more objects; and attributes characterizing the one or more objects and the one or more relationships among the one or more objects, wherein the attributes comprise at least a type of the at least one operation of interest and a source of the one or more events, wherein the type comprises an identifier of the at least one operation of interest that characterizes the one or more events, and wherein the source comprises an originating entity that performs the at least one operation of interest, wherein each of the one or more objects represent an entity related to the one or more monitored operations; analyzing, by the computer system, the event context in view of the at least one stateful model to identify one or more behaviors of the execution of the program related to the one or more events; applying a score to the stateful model based on the one or more identified behaviors, wherein applying the score to the stateful model comprises: determining a behavior score for each of the one or more identified behaviors; assigning a weight factor to each behavior score associated with the one or more identified behaviors to generate a weighted behavior score for each of the one or more identified behaviors, wherein the weighted behavior score indicates the likelihood of the presence of malware based on the one or more identified behaviors; determining a sum of the weighted behavior scores for each of the one or more identified behaviors; and comparing the one or more identified behaviors and the score to one or more pre-existing behaviors and a pre-existing score of a pre-existing stateful model, wherein the computer system comprises a processor and memory. 2. The method of claim 1 , further comprising updating, in real time, the at least one stateful model in response to one or more new events. 3. The method of claim 1 , further comprising outputting, via an output device of the computer system, a representation of the one or more identified behaviors of the execution of the program. 4. The method of claim 1 , further comprising storing the one or more identified behaviors of the execution of the program in a behavioral profile database. 5. The method of claim 1 , wherein the computer system comprises a cloud-based computer system. 6. The method of claim 1 , wherein the computer system comprises one or more functional components distributed over more than one computer. 7. The method of claim 1 , wherein the live environment comprises one or more programs, including the program, operating concurrently and interactively for their intended uses. 8. The method of claim 1 , further comprising aggregating the one or more identified behaviors. 9. The method of claim 1 , wherein the one or more behaviors comprise a representation of a behavior pattern of the execution of the program. 10. The method of claim 1 , further comprising analyzing the one or more behaviors to determine if the execution of the program comprises malware. 11. A system for performing a behavior-based analysis of an execution of a program in an operating system, the system comprising: one or more computer readable storage devices configured to store a plurality of computer executable instructions; and one or more hardware computer processors in communication with the one or more computer readable storage devices and configured to execute the plurality of computer executable instructions in order to cause the system to: monitor, by registering one or more kernel filter drivers for kernel space operations via one or more call back functions using an out-of-band monitoring module, one or more operations performed by the execution of the program running in the operating system in a live environment, wherein monitoring comprises tracking user space operations and the kernel space operations; select at least one operation of interest from the one or more operations; generate an event data for each of the at least one operation of interest, wherein the event data characterizes one or more events of the at least one operation of interest; filter event data of interest from the event data for each of the at least one operation of interest, the filtering based on one or more predefined filtering rules; normalize the event data of interest into a logical data structure such that attributes of the event data of interest can accessed and analyzed; build at least one stateful model of the execution of the program based on the normalized event data of interest, the at least one stateful model comprising a hierarchal structure of the at least one operation of interest performed by the execution of the program in the live environment, the at least one operation of interest linked by an event context, wherein the at least one stateful model comprises: the event context comprising: one or more objects derived from the one or more monitored operations; one or more fields generated for each of the one or more objects, the one or more fields storing one or more parameters characterizing a respective object of the one or more objects and an associate to the respective object; and one or more relationships identified among the one or more objects; and attributes characterizing the one or more objects and the one or more relationships among the one or more objects, wherein the attributes comprise at least a type of the at least one operation of interest and a source of the one or more events, wherein the type comprises an identifier of the at least one operation of interest that characterizes the one or more events, and wherein the source comprises an originating entity that performs the at least one operation of interest, wherein each of the one or more objects represent an entity rel

Assignees

Inventors

Classifications

  • G06F21/566Primary

    Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11625485B2 cover?
There is provided a system and a computer-implemented method of detecting malware in real time in a live environment. The method comprises: monitoring one or more operations of at least one program concurrently running in the live environment, building at least one stateful model in accordance with the one or more operations, analyzing the at least one stateful model to identify one or more beh…
Who is the assignee on this patent?
Sentinel Labs Israel Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/566. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 11 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).