发明名称 MALWARE DETECTION BASED ON TRAINING USING AUTOMATIC FEATURE PRUNING WITH ANOMALY DETECTION OF EXECUTION GRAPHS
摘要 A threat detection system for detecting malware can automatically decide, without manual expert-level interaction, the best set of features on which to train a classifier, which can result in the automatic creation of a signature-less malware detection engine. The system can use a combination of execution graphs, anomaly detection and automatic feature pruning. Execution graphs can provide a much richer structure of runtime execution behavior than conventional flat execution trace files, allowing the capture of interdependencies while preserving attribution (e.g., D happened because of A followed by B followed by C). Performing anomaly detection on this runtime execution behavior can provide higher order knowledge as to what behaviors are anomalous or not among the sample files. During training the system can automatically prune the features on which a classifier is trained based on this higher order knowledge without any manual intervention until a desired level of accuracy is achieved.
申请公布号 WO2016149411(A1) 申请公布日期 2016.09.22
申请号 WO2016US22703 申请日期 2016.03.16
申请人 THREATTRACK SECURITY HOLDING, INC. 发明人 APOSTOLESCU, Paul;ANTONY, Melvin;TOURE, Aboubacar;MARKEY, Jeff
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址