The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 26, 2017

Filed:

Apr. 14, 2015
Applicant:

Drexel University, Philadelphia, PA (US);

Inventors:

Raymond Joseph Canzanese, Jr., Philadelphia, PA (US);

Spiros Mancoridis, Philadelphia, PA (US);

Moshe Kam, Philadelphia, PA (US);

Assignee:

Drexel University, Philadelphia, PA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); G06F 12/14 (2006.01); G06F 12/16 (2006.01); G08B 23/00 (2006.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); G06F 9/455 (2006.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01); G06F 21/50 (2013.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01); G06F 9/45545 (2013.01); G06F 21/53 (2013.01); G06F 21/55 (2013.01); G06F 21/566 (2013.01); H04L 63/1408 (2013.01); G06F 21/50 (2013.01); G06F 2009/45587 (2013.01);
Abstract

A malware detection system and method detects changes in host behavior indicative of malware execution. The system uses linear discriminant analysis (LDA) for feature extraction, multi-channel change-point detection algorithms to infer malware execution, and a data fusion center (DFC) to combine local decisions into a host-wide diagnosis. The malware detection system includes sensors that monitor the status of a host computer being monitored for malware, a feature extractor that extracts data from the sensors corresponding to predetermined features, local detectors that perform malware detection on each stream of feature data from the feature extractor independently, and a data fusion center that uses the decisions from the local detectors to infer whether the host computer is infected by malware.


Find Patent Forward Citations

Loading…