×

Matrix factorization for automated malware detection

  • US 9,398,034 B2
  • Filed: 12/19/2013
  • Issued: 07/19/2016
  • Est. Priority Date: 12/19/2013
  • Status: Active Grant
First Claim
Patent Images

1. A malware detection system comprising:

  • at least one processor;

    a feature identifier configured to generate a matrix of files and associated machines having a plurality of features associated with the files and machines, the feature identifier further configured to apply matrix factorization to the matrix of files and associated machines to generate a machine matrix and a file matrix, and is configured to perform dimensional reduction to identify a group of features from the plurality of features that are most informative features, wherein the group of features is a fixed number of features and comprises a subset of the plurality of features;

    a malware database comprising files of known malware and a plurality of features associated with the known malware;

    a comparison engine configured to identify for a file a number of other files that are similar to the file from the matrix of files and the malware database and to score the file based on a closeness of the other files to the file; and

    malware classification component configured to identify potential malware based on the score of the file and is further configured to create an alert if the score for the file exceeds a first threshold score.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×