×

Method of modeling behavior pattern of instruction set in N-gram manner, computing device operating with the method, and program stored in storage medium to execute the method in computing device

  • US 10,007,788 B2
  • Filed: 02/05/2016
  • Issued: 06/26/2018
  • Est. Priority Date: 02/11/2015
  • Status: Active Grant
First Claim
Patent Images

1. A non-transitory computer-readable storage medium storing a program configured to model a behavior pattern associated with system calls that occur by an instruction set executed in a computing device, the program executing a process, in the computing device, that comprises:

  • hooking, by a processor of the computing device, the system calls while the instruction set is executed under a control of the processor;

    extracting, by the processor, a category to which each of the hooked system calls belongs, with reference to category information stored in at least one of a first storage of the computing device or a second storage provided separately from the computing device;

    extracting, by the processor, one or more behavior sequences expressed in an N-gram manner from a full sequence of the hooked system calls, with reference to the extracted category;

    generating, by the processor, a model of the behavior pattern based on a number of times that each of the extracted N-gram behavior sequences occurs;

    comparing at least one of the generated model of the behavior pattern or the stored model of the behavior pattern with a reference model; and

    determining, based on the comparison, whether the executed instruction set is malicious or normal.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×