The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 07, 2023

Filed:

Jan. 04, 2019
Applicant:

Trend Micro Incorporated, Tokyo, JP;

Inventors:

Te-Ching Chen, Taipei, TW;

Chih-Kun Ho, Taipei, TW;

Yung-Hsiang Lee, Taipei, TW;

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/55 (2013.01); G06N 20/00 (2019.01); G06F 9/54 (2006.01); G06N 5/00 (2006.01); G06F 40/211 (2020.01); G06F 40/284 (2020.01);
U.S. Cl.
CPC ...
G06F 21/564 (2013.01); G06F 9/544 (2013.01); G06F 21/554 (2013.01); G06F 21/563 (2013.01); G06F 21/566 (2013.01); G06F 40/211 (2020.01); G06F 40/284 (2020.01); G06N 5/003 (2013.01); G06N 20/00 (2019.01);
Abstract

An endpoint system receives a target file for evaluation for malicious scripts. The original content of the target file is normalized and stored in a normalized buffer. Tokens in the normalized buffer are translated to symbols, which are stored in a tokenized buffer. Strings in the normalized buffer are stored in a string buffer. Tokens that are indicative of syntactical structure of the normalized content are extracted from the normalized buffer and stored in a structure buffer. The content of the tokenized buffer and counts of tokens represented as symbols in the tokenized buffer are compared against heuristic rules indicative of malicious scripts. The contents of the tokenized buffer and string buffer are compared against signatures of malicious scripts. The contents of the tokenized buffer, string buffer, and structure buffer are input to a machine learning model that has been trained to detect malicious scripts.


Find Patent Forward Citations

Loading…