← USPTO Patent Grants

Execution behavior analysis text-based ensemble malware detector

Grant US12585935B2 Kind: B2 Mar 24, 2026

Assignee

Palo Alto Networks, Inc.

Inventors

Sujit Rokka Chhetri, William Redington Hewlett, II

Abstract

A malware detector has been designed that uses a combination of NLP techniques on dynamic malware analysis reports for malware classification of files. The malware detector aggregates text-based features identified in different pre-processing pipelines that correspond to different types of properties of a dynamic malware analysis report. From a dynamic malware analysis report, the pre-processing pipelines of the malware detector generate a first feature set based on individual text tokens and a second feature set based on n-grams. The malware detector inputs the first feature set into a trained neural network having an embedding layer. The malware detector then extracts a dense layer from the trained neural network and aggregates the extracted layer with the second feature set to form an input for a trained boosting model. The malware detector inputs the cross-pipeline feature values into the trained boosting model to generate a malware detection output.

CPC Classifications

G06N 20/00 G06N 3/08 G06N 3/09 G06N 3/045 G06N 3/0464 G06N 3/04 G06N 3/084 G06N 20/20 G06F 21/561 G06F 21/56 G06F 21/562 G06F 21/566

Filing Date

2021-02-10

Application No.

17172519

Claims

23