US Patent:
20210110038, Apr 15, 2021
Inventors:
- Santa Clara CA, US
Prajesh Ambili Rajendran - Hyderabad, IN
Taj un nisha N - TamilNadu, IN
Rahuldeva Ghosh - Portland OR, US
Paul Carlson - Hillsboro OR, US
Zheng Zhang - Portland OR, US
Assignee:
Intel Corporation - Santa Clara CA
International Classification:
G06F 21/56
G06N 20/00
Abstract:
A method comprises generating a first set of hardware performance counter (HPC) events that is ranked based on an ability of an individual HPC event to profile a malware class, generating a second set of HPC event combinations that is ranked based on an ability of a set of at least two joint HPC events to profile a malware class, generating a third set of extended HPC event combinations, profiling one or more malware events and one or more benign applications to obtain a detection accuracy parameter for each malware event, applying a machine learning model to rank the third set of HPC event combinations based on malware detection accuracy, and applying a genetic algorithm to the third set of HPC event combinations to identify a subset of the third set of extended combinations of HPC events to be used for malware detection and classification.