Patent №
US 12,314,390
Granted
2025-05-27
Filed 2022
Owner
Check Point Software Technologies Ltd.
Lab
—
AI components
0
Assignment
None on record
Dataset
AIPD
Application
18146092
A method and system are provided for detecting malicious code using graph neural networks. A call graph is created from the computer code by identifying functions in the computer code and vectorizing the identified functions using a stream of application programming interfaces (APIs) called by the functions and using tokens generated for the functions using a byte pair tokenizer. A trained graph neural network (GNN) and a trained attention neural network are applied to the call graph to generate an output graph with each node representing a function and each node assigned weights based on a probability distribution of the maliciousness of the corresponding function. A graph embedding is generated by calculating a weighted sum of the assigned weights and a trained deep neural network is applied to the graph embedding to generate a malicious score for the computer code identifying the computer code as malicious or benign.
Ownership
Check Point Software Technologies Ltd.