REDUCTION OF FALSE POSITIVES IN MALWARE DETECTION USING FILE PROPERTY ANALYSIS

Patent №

US 9,858,413

Granted

2018-01-02

Filed 2013

Owner

TREND MICRO INC.

Lab

AI components

1

nlp

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

13935419

A virus detection engine determines that a file is suspected of being malware. A property is retrieved, along with the same file property of other executable files within the same folder. If the property value is similar to property values of the other files then the suspect file is benign. If the number of matches is greater than a threshold then the suspect file is benign. Other file properties of the suspect file are compared. If no file properties are similar to properties of the other files then the suspect file is malware and an alert is generated. The longest common subsequence compares property values. The same property value may be added to files within the same folder after these files are installed on the computer but before any detection takes place. A comparison of the same property values concludes that files are not malware, even if they are suspect.

Natural languageG06F 21/561G06F 21/56

AI classification

Natural language1.00
Knowledge representation0.41
AI hardware0.19
Planning0.12
Machine learning0.00
Vision0.00
Evolutionary computation0.00
Speech0.00

Ownership

TREND MICRO INC.

assignment · 311470541

Assignors

ZUO, WEI, WU, WEIMIN, SHEN, TAO

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC