发明授权
- 专利标题: Malware family identification using profile signatures
- 专利标题(中): 使用配置文件签名的恶意软件家族识别
-
申请号: US13754789申请日: 2013-01-30
-
公开(公告)号: US09165142B1公开(公告)日: 2015-10-20
- 发明人: Kyle Sanders , Xinran Wang
- 申请人: Palo Alto Networks, Inc.
- 申请人地址: US CA Santa Clara
- 专利权人: Palo Alto Networks, Inc.
- 当前专利权人: Palo Alto Networks, Inc.
- 当前专利权人地址: US CA Santa Clara
- 代理机构: Van Pelt, Yi & James LLP
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; H04L29/06
摘要:
Techniques for malware family identification using profile signatures are disclosed. In some embodiments, malware identification using profile signatures includes executing a potential malware sample in a virtual machine environment (e.g., a sandbox); and determining whether the potential malware sample is associated with a known malware family based on a profile signature. In some embodiments, the virtual machine environment is an instrumented virtual machine environment for monitoring potential malware samples during execution.
信息查询