Invention Grant
- Patent Title: System and method for detecting a malicious file using image analysis prior to execution of the file
-
Application No.: US15976539Application Date: 2018-05-10
-
Publication No.: US11275833B2Publication Date: 2022-03-15
- Inventor: William Finlayson , Hyrum Anderson
- Applicant: Endgame, Inc.
- Applicant Address: US VA Arlington
- Assignee: Endgame, Inc.
- Current Assignee: Endgame, Inc.
- Current Assignee Address: US VA Arlington
- Agency: Carr & Ferrell LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06N3/04

Abstract:
A system and a method for analyzing files using visual cues in the presentation of the file is provided. These visual aids may be extracted using a convolutional neural network, classified, and used in conjunction with file metadata to determine if a provided document is likely to be malicious. This methodology may be extended to detect a variety of social engineering-related attacks including phishing sites or malicious emails. A method for analyzing a received file to determine if the received file comprises malicious code begins with generating an image that would be displayed if the received file is opened by the native software program. Then the image is analyzed, and object boundaries data is generated. Metadata is also extracted from the received file. Then, a maliciousness score is generated based on the object boundaries data, the metadata, and a reference dataset.
Information query