US2020364337A1PendingUtilityA1
Adversarial attack prevention and malware detection system
Est. expirySep 11, 2037(~11.1 yrs left)· nominal 20-yr term from priority
Inventors:Li-Chieh Chen
G06N 7/01G06N 20/00G06N 20/10G06F 21/566G06F 21/564G06F 21/563G06N 7/005
65
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Systems and methods may be used to classify incoming testing data, such as binaries, function calls, an application package, or the like, to determine whether the testing data is contaminated using an adversarial attack or benign while training a machine learning system to detect malware. A method may include using a sparse coding technique or a semi-supervised learning technique to classify the testing data. Training data may be used to represent the testing data using the sparse coding technique or to train the supervised portion of the semi-supervised learning technique.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A malware detection system for preventing evasion attacks, the malware detection system comprising:
one or more processors coupled to a memory device, the memory device including instructions which, when executed by the one or more processors, cause the one or more processors to:
create a dictionary of samples having classes from training data, wherein the training data includes data labeled as malware or benign;
receive testing data, wherein the testing data is unlabeled as malware or benign;
select a sparse classification system based on determining that a feature of the testing data has been added, removed, or contaminated;
determine sparse coefficients for the testing data using the dictionary of samples;
classify the testing data as malware or benign using the sparse coefficients and the classes of respective samples according to a sparse classification of the sparse classification system; and
output the sparse classification.
2 . The malware detection system of claim 1 , further including instructions which cause the one or more processors to, in response to classifying the testing data as malware, block an internet protocol (IP) address of a source of at least a portion of the testing data.
3 . The malware detection system of claim 1 , further including instructions which cause the one or more processors to train a machine learning system to detect malware attacks using the testing data.
4 . The malware detection system of claim 3 , further including instructions which cause the one or more processors to, in response to classifying the testing data as malware, prevent at least a portion of the testing data from reaching the machine learning system.
5 . The malware detection system of claim 3 , further including instructions which cause the one or more processors to, in response to classifying the testing data as malware, cause the machine learning system to perform a roll back to a previous state before the testing data was received.
6 . At least one non-transitory machine-readable medium including instructions for preventing evasion attacks on a malware detection system, which when executed by a machine, cause the machine to:
create a dictionary of samples having classes from training data, wherein the training data includes data labeled as malware or benign; receive testing data, wherein the testing data is unlabeled as malware or benign; select a sparse classification system based on determining that a feature of the testing data has been added, removed, or contaminated; determine sparse coefficients for the testing data using the dictionary of samples; classify the testing data as malware or benign using the sparse coefficients and the classes of respective samples according to a sparse classification of the sparse classification system; and output the sparse classification.
7 . The at least one non-transitory machine-readable medium of claim 6 , further comprising instructions to, in response to classifying the testing data as malware, block an internet protocol (IP) address of a source of at least a portion of the testing data.
8 . The at least one non-transitory machine-readable medium of claim 6 , further comprising instructions to train a machine learning system to detect malware attacks using the testing data.
9 . The at least one non-transitory machine-readable medium of claim 8 , further comprising instructions to, in response to classifying the testing data as malware, prevent at least a portion of the testing data from reaching the machine learning system.
10 . The at least one non-transitory machine-readable medium of claim 8 , further comprising instructions to, in response to classifying the testing data as malware, cause the machine learning system to perform a roll back to a previous state before the testing data was received.
11 . A malware detection system for preventing evasion attacks, the malware detection system comprising:
one or more processors coupled to a memory device, the memory device including instructions which, when executed by the one or more processors, cause the one or more processors to:
receive training data and testing data, wherein the training data includes data labeled as malware or benign and wherein the testing data is unlabeled as malware or benign;
select a semi-supervised classification system based on determining that a proportion of training data to testing data is below a threshold;
estimate model parameters for a combination of the training data and the testing data using a conditional expectation maximization function;
select a closest fitted model using the estimated model parameters;
determine a likelihood of at least one file of the testing data being malware or benign using the closest fitted model;
classify the at least one file based on the likelihood according to a semi-supervised classification of the semi-supervised classification system; and
output the semi-supervised classification.
12 . The malware detection system of claim 11 , further including instructions which cause the one or more processors to, in response to classifying the at least one file of the testing data as malware, block an internet protocol (IP) address of a source of at least a portion of the testing data.
13 . The malware detection system of claim 11 , further including instructions which cause the one or more processors to train a machine learning system to detect malware attacks using the testing data.
14 . The malware detection system of claim 13 , further including instructions which cause the one or more processors to, in response to classifying the testing data as malware, prevent at least a portion of the testing data from reaching the machine learning system.
15 . The malware detection system of claim 13 , further including instructions which cause the one or more processors to, in response to classifying the testing data as malware, cause the machine learning system to perform a roll back to a previous state before the testing data was received.
16 . At least one non-transitory machine-readable medium including instructions for preventing evasion attacks on a malware detection system, which when executed by a machine, cause the machine to:
receive training data and testing data, wherein the training data includes data labeled as malware or benign and wherein the testing data is unlabeled as malware or benign; select a semi-supervised classification system based on determining that a proportion of training data to testing data is below a threshold; estimate model parameters for a combination of the training data and the testing data using a conditional expectation maximization function; select a closest fitted model using the estimated model parameters; determine a likelihood of at least one file of the testing data being malware or benign using the closest fitted model; classify the at least one file based on the likelihood according to a semi-supervised classification of the semi-supervised classification system; and output the semi-supervised classification.
17 . The at least one non-transitory machine-readable medium of claim 16 , further comprising instructions to, in response to classifying the testing data as malware, block an internet protocol (IP) address of a source of at least a portion of the testing data.
18 . The at least one non-transitory machine-readable medium of claim 16 , further comprising instructions to train a machine learning system to detect malware attacks using the testing data.
19 . The at least one non-transitory machine-readable medium of claim 18 , further comprising instructions to, in response to classifying the testing data as malware, prevent at least a portion of the testing data from reaching the machine learning system.
20 . The at least one non-transitory machine-readable medium of claim 18 , further comprising instructions to, in response to classifying the testing data as malware, prevent at least a portion of the testing data from reaching the machine learning system.Join the waitlist — get patent alerts
Track US2020364337A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.