DETECTION OF MALICIOUS EXECUTABLE FILES USING HIERARCHICAL MODELS

Patent №

US 11,113,397

Granted

2021-09-07

Filed 2019

Owner

CISCO TECHNOLOGY, INC.

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

16413880

In one embodiment, a device disassembles an executable file into assembly instructions. The device maps each of the assembly instructions to a fixed length instruction vector using one-hot encoding and an instruction vocabulary and forms vector representations of blocks of a control flow graph for corresponding functions of the executable file by embedding and aggregating bags of the instruction vectors. The device generates, based on the vector representations of the blocks of the control flow graph, a call graph model of the functions in the executable file. The device forms a vector representation of the executable file based in part on the call graph model. The device determines, based on the vector representation of the executable file, whether the executable file is malware.

AI hardwareG06F 21/562G06F 21/563G06F 21/567G06F 21/568G06N 3/0464G06N 3/08G06N 3/0895G06N 3/09+3 more

AI classification

AI hardware0.98
Knowledge representation0.14
Natural language0.03
Machine learning0.01
Vision0.00
Evolutionary computation0.00
Planning0.00
Speech0.00

Ownership

CISCO TECHNOLOGY, INC.

assignment · 491970705

Assignors

PEVNY, TOMAS, FRANCŮ, JAN, SOMOL, PETR

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC