MULTI-BEHAVIOR POLICY MATCHING FOR MALWARE DETECTION

Patent №

US 8,370,931

Granted

2013-02-05

Filed 2008

Owner

TREND MICRO INCORPORATED

Lab

AI components

4

ml · kr · planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

12212250

Multi-behavior matching in a computer system is performed in order to identify suspicious sequences of activities. System behavior is captured using driver hooks. A behavior monitoring system determines the process to which the system behavior belongs by processing a table. This includes using the process ID and thread ID of the system behavior as lookups into the table. A multi-behavior matching algorithm is applied to determine if there is any matching suspicious behavior by matching sets of rules (a policy) to system events caused by a particular process. A state machine is used to keep track of matching policies. Options to the rules and policies (such as “offset,” “depth,” “distance,” “within,” “ordered” and “occurrence/interval”) are used to refine when a rule or policy is allowed to produce a positive match, reducing false positives.

AI classification

AI hardware1.00
Planning1.00
Machine learning0.99
Knowledge representation0.94
Natural language0.01
Vision0.00
Evolutionary computation0.00
Speech0.00

Ownership

TREND MICRO INCORPORATED

assignment · 219220212

Assignors

CHIEN, HAO-LIANG, SHIH, MING-CHANG, WU, CHUN-DA

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC