Invention Grant
- Patent Title: Automated identification of malware families based on shared evidences
-
Application No.: US18536736Application Date: 2023-12-12
-
Publication No.: US12147537B2Publication Date: 2024-11-19
- Inventor: Yu-Siang Chen , Ci-Hao Wu , Ying-Chen Yu , Pao-Chuan Liao , June-Ray Lin
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Stephen J. Walder, Jr.; Jordan Schiller
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56 ; G06N5/02 ; G06N5/04

Abstract:
A malware family identification engine constructs a graph data structure of direct relationships between malware instances and malware families, direct relationships between malware instances and detected tags, and indirect relationships between detected tags and malware families. The engine builds a dictionary data structure comprising detected tag entries linking each detected tag to one or more malware family nodes based on the graph data structure. The engine identifies significant indirect entities (SIEs) within the detected tag entries of the dictionary data structure and selects a SIE with a highest number of out-going links (OGLs) as a root node in a family tree data structure, recursively connects SIEs with a number of OGLs less than the highest number of OGLs to the root node in the family tree data structure, and converts each SIE name in the family tree data structure to a chained family entity name in the family tree data structure.
Public/Granted literature
- US20240176880A1 Automated Identification of Malware Families Based on Shared Evidences Public/Granted day:2024-05-30
Information query