IL226747A

System and method for malware detection learning

Abstract

This record has no abstract on file.

IL226747A, drawing sheet 1
Sheet 1 of 2

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

11 claims: 2 independent, 9 dependent

  1. 1
    CLAIMS 1. A method, comprising:monitoring, by a malware detection system, a protected computer network that is to be protected from malicious software, and an infected computer network that is known to be infected with malicious software;extracting, by the malware detection system, from both the protected computer network and the infected computer network, first communication transactions that are known to be malicious;extracting, by the malware detection system, only from the protected computer network, second communication transactions that are not known to be malicious;and identifying, by the malware detection system, one or more malicious communication transactions exchanged with the protected computer network, by processing the first and second communication transactions, wherein identifying the malicious communication transactions comprises creating, based on the extracted first and second communication transactions, one or more models that distinguish the malicious communication transactions from innocent communication transactions, and detecting the malicious communication transactions using the models, wherein identifying the malicious communication transactions comprises generating alerts based on the models, receiving an analysis of the alerts from an operator, and detecting the malicious communication transactions based on the analysis of the alerts by the operator, wherein extracting the first communication transactions comprises selecting the first communication 226,747/3 transactions depending on reputation levels of respective hosts participating in the communication transactions, and comprising updating at least one of the reputation levels based on the analysis of the alerts by the operator.
  2. 6
    7. A system, comprising:226,747/3 a network interface, which is configured to monitor a protected computer network that is to be protected from malicious software, and an infected computer network that is known to be infected with malicious software;and a processor, which is configured to extract, from both the protected computer network and the infected computer network, first communication transactions that are known to be malicious, to extract, only from the protected computer network, second communication transactions that are not known to be malicious, and to identify one or more malicious communication transactions exchanged with the protected computer network, by processing the first and second communication transactions, wherein the processor is configured to create, based on the extracted first and second communication transactions, one or more models that distinguish the malicious communication transactions from innocent communication transactions, and to detect the malicious communication transactions using the models, wherein the processor is configured to generate alerts based on the models, to receive an analysis of the alerts from an operator, and to identify the malicious communication transactions based on the analysis of the alerts by the operator, wherein the processor is configured to select the first communication transactions depending on reputation levels of respective hosts participating in the communication transactions, and to update at least one of the reputation levels based on the analysis of the alerts by the operator.