APPLICATION BEHAVIOR BASED MALWARE DETECTION

Patent №

US 7,779,472

Granted

2010-08-17

Filed 2005

Owner

TREND MICRO, INC.

Lab

AI components

3

ml · planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

11247349

An executable file is loaded into a virtual machine arranged to emulate the instructions of said executable file. The virtual machine keeps track of application programming interfaces (APIs) used by the executable file during emulation. The executable file is scanned to determine names of (APIs) used. Behavior flags are set if certain conditions occur within the executable file. The APIs determined during emulation and during scanning are compared with a set of known behaviors. A match of the APIs and the known behaviors indicates a high risk of malware. A determination of malware being present is based upon any matches and any behavior flags that are set.

AI classification

Machine learning0.96
Planning0.77
AI hardware0.50
Evolutionary computation0.00
Knowledge representation0.00
Vision0.00
Natural language0.00
Speech0.00

Ownership

TREND MICRO, INC.

assignment · 216080096

Assignors

LOU, VIC

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC