The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 19, 2022

Filed:

Jan. 22, 2019
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Fady Copty, Nazereth, IL;

Matan Danos, Haifa, IL;

Orit Edelstein, Haifa, IL;

Dov Murik, Haifa, IL;

Benjamin Zeltser, Haifa, IL;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/55 (2013.01); G06N 5/04 (2006.01); G06N 20/00 (2019.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 21/554 (2013.01); G06N 5/045 (2013.01); G06N 20/00 (2019.01); G06F 2221/034 (2013.01);
Abstract

Deriving malware signatures by training a binary decision tree using known malware and benign software samples, each tree node representing a different software feature set and having one descending edge representing samples that are characterized by the node's software feature set and another descending edge representing samples that are not characterized thusly, selecting multiple continuous descending paths for multiple subsets of nodes, each path traversing a selected one of the edges descending from each of the nodes in its corresponding subset, deriving, based on the nodes and edges in any of the paths, a malware-associated software feature signature where the malware samples represented by leaves that directly or indirectly descend from an end of the continuous descending path meets a minimum percentage of the total number of samples represented by the leaves, and providing the malware signatures for use by a computer-based security tool configured to identify malware.


Find Patent Forward Citations

Loading…