×

Static anomaly-based detection of malware files

  • US 10,089,467 B1
  • Filed: 05/23/2017
  • Issued: 10/02/2018
  • Est. Priority Date: 05/23/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting anomalous files, the method comprising:

  • obtaining a file on a client for classification;

    obtaining metadata associated with the file;

    determining, based on the metadata, a subclass of the file selected from a plurality of subclasses;

    selecting a model of a plurality of models based on the subclass of the file, wherein the selected model characterizes a plurality of features of a sample of clean files that are each associated with the subclass, wherein each of the plurality of models is derived from a training set of clean files belonging to a particular subclass and wherein different ones of the plurality of models are associated with different subclasses;

    generating, by a processor, an anomaly score of the file by applying the file to the selected model, the anomaly score indicating a level of dissimilarity between features of the file and the plurality of features of the sample of clean files of the selected model;

    comparing the anomaly score against at least one of a lower threshold score, a center threshold score, and an upper threshold score;

    classifying the file as anomalous based on the anomaly score; and

    remediating the file by the client responsive to the classification of the file.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×