×

Identification of mislabeled samples via phantom nodes in label propagation

  • US 10,198,576 B2
  • Filed: 12/09/2016
  • Issued: 02/05/2019
  • Est. Priority Date: 12/10/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for protecting computing devices from mislabeled malware, the method comprising:

  • creating a graph from a plurality of sample executable files by executing the sample executable files in an isolated execution environment, the graph including sample file nodes associated with the sample executable files and behavior nodes associated with behavior signatures, wherein edges in the graph connect a behavior node with a set of one or more sample file nodes, wherein the one or more sample executable files associated with the one or more sample file nodes exhibit the behavior signature associated with the behavior node;

    receiving data indicating a label distribution of a neighbor node of a sample file node in the graph;

    in response to determining that a current label for the sample file node is unknown, setting the current label distribution for the sample file node to a consensus of label distributions of neighboring nodes;

    in response to determining that the current label for the sample file node is known, performing operations including;

    creating a phantom node associated with the sample file node,determining a neighborhood opinion for the phantom node, based at least in part on the label distribution of the neighboring nodes,determining a difference between the neighborhood opinion and the current label for the sample file node, anddetermining whether the current label is incorrect based, at least in part, on the difference; and

    in response to determining that the current label for the sample file node is incorrect, performing at least one remedial action on the sample executable file associated with the sample file node having the incorrect current label.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×