发明授权
- 专利标题: Systems and methods for detecting malware variants
- 专利标题(中): 用于检测恶意软件变体的系统和方法
-
申请号: US13297244申请日: 2011-11-15
-
公开(公告)号: US08806641B1公开(公告)日: 2014-08-12
- 发明人: Yi Li , Xiao Dong Tan , Kai Xiao
- 申请人: Yi Li , Xiao Dong Tan , Kai Xiao
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: ALG Intellectual Property, LLC
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; G06F21/56
摘要:
A computer-implemented method for detecting malware variants may include (1) identifying an application package file including at least one class file, (2) identifying a set of metadata fields within the class file, (3) comparing the set of metadata fields within the class file with a set of metadata fields within a corresponding class file found in a known malware package to determine a similarity between the application package file and the known malware package, and (4) determining, based on the similarity between the application package file and the known malware package, that the application package file is a threat variant in a same threat family as the known malware package. Various other methods, systems, and computer-readable media are also disclosed.
信息查询