Patent 10102372 was granted and assigned to Proofpoint on October, 2018 by the United States Patent and Trademark Office.
Provided herein are systems and methods for behavior profiling of targets to determine malware presence. The method includes, in various embodiments, applying a domain specific language to a target; observing a set of temporal sequences and events of the target; determining the presence of markers within the set of temporal sequences and events indicative of malware; and identifying the target as being associated with malware based on the markers. In some embodiments, a malware detection system is provided for creating a behavioral sandbox environment where a target is inspected for malware. The behavioral sandbox environment can include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine the presence of markers within the set of temporal sequences and events indicative of malware; and detect malware presence based on the markers.