The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 23, 2024

Filed:

Oct. 12, 2021
Applicant:

AO Kaspersky Lab, Moscow, RU;

Inventors:

Alexander S. Chistyakov, Moscow, RU;

Alexey M. Romanenko, Moscow, RU;

Alexander S. Shevelev, Moscow, RU;

Assignee:

AO Kaspersky Lab, Moscow, RU;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/52 (2013.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01); G06N 20/00 (2019.01); G06N 3/08 (2023.01); G06N 5/04 (2023.01);
U.S. Cl.
CPC ...
G06F 21/554 (2013.01); G06F 21/52 (2013.01); G06F 21/566 (2013.01); G06N 20/00 (2019.01); G06F 2221/033 (2013.01); G06F 2221/034 (2013.01); G06N 3/08 (2013.01);
Abstract

Disclosed herein are methods and systems for selecting a detection model for detection of a malicious file. An exemplary method includes: monitoring a file during execution of the file within a computer system by intercepting commands of the file being executed and determining one or more parameters of the intercepted commands. A behavior log of the file being executed containing behavioral data is formed based on the intercepted commands and based on the one or more parameters of the intercepted commands. The behavior log is analyzed to form a feature vector. The feature vector characterizes the behavioral data. One or more detection models are selected from a database of detection models based on the feature vector. Each of the one or more detection models includes a decision-making rule for determining a degree of maliciousness of the file being executed.


Find Patent Forward Citations

Loading…