Fortinet, Inc.
Generic and static detection of malware installation packages

Last updated:

Abstract:

Systems and methods for generic and static detection of malware using machine learning are provided. According to one embodiment, a computing device receives an executable application or a part thereof. A package name associated with the received application is extracted. The received executable application is classified as being malicious or non-malicious based on evaluation of the package name using a language model. When the received executable application is classified as being non-malicious by the language model, then a further classification process is performed on the received executable application by extracting one or more icons associated with the received executable application. A set of icons of the one or more icons is evaluated using a deep neural network (DNN) model.

Status:
Grant
Type:

Utility

Filling date:

30 Nov 2017

Issue date:

14 Apr 2020