Invention Grant
- Patent Title: Extraction and comparison of hybrid program binary features
-
Application No.: US15479928Application Date: 2017-04-05
-
Publication No.: US10289843B2Publication Date: 2019-05-14
- Inventor: Junghwan Rhee , Zhichun Li , Zhenyu Wu , Kangkook Jee , Guofei Jiang
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: JP Tokyo
- Assignee: NEC Corporation
- Current Assignee: NEC Corporation
- Current Assignee Address: JP Tokyo
- Agent Joseph Kolodka
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F11/36

Abstract:
Systems and methods for identifying similarities in program binaries, including extracting program binary features from one or more input program binaries to generate corresponding hybrid features. The hybrid features include a reference feature, a resource feature, an abstract control flow feature, and a structural feature. Combinations of a plurality of pairs of binaries are generated from the extracted hybrid features, and a similarity score is determined for each of the pairs of binaries. A hybrid difference score is generated based on the similarity score for each of the binaries combined with input hybrid feature parameters. A likelihood of malware in the input program is identified based on the hybrid difference score.
Public/Granted literature
- US20170293761A1 EXTRACTION AND COMPARISON OF HYBRID PROGRAM BINARY FEATURES Public/Granted day:2017-10-12
Information query