Invention Grant
- Patent Title: Automatic extraction of signatures for malware
- Patent Title (中): 自动提取恶意软件的签名
-
Application No.: US12031832Application Date: 2008-02-15
-
Publication No.: US08353040B2Publication Date: 2013-01-08
- Inventor: Gil Tahan , Asaf Shabtai , Yuval Elovici
- Applicant: Gil Tahan , Asaf Shabtai , Yuval Elovici
- Agency: Roach Brown McCarthy & Gruber, P.C.
- Agent Kevin D. McCarthy
- Priority: IL181426 20070219
- Main IPC: G06F15/18
- IPC: G06F15/18 ; G06F11/00

Abstract:
Method for the automatic generation of malware signatures from computer files. A common function library (CFL) created, wherein the CFL contains any functions identified as a part of the standard computer language used to write computer files which are known as not containing malware. The functions of a computer file which does contain a malware are extracted and the CFL is updated with any new common functions if necessary, such that the remaining functions are all considered as candidates for generating the malware signature. The remaining functions are divided into clusters according to their location in the file and the optimal cluster for generating the malware signature is determined. One or more of the functions in the optimal cluster is selected randomly, as the malware signature.
Public/Granted literature
- US20080201779A1 AUTOMATIC EXTRACTION OF SIGNATURES FOR MALWARE Public/Granted day:2008-08-21
Information query