发明授权
- 专利标题: Systems and methods for identifying malware
- 专利标题(中): 用于识别恶意软件的系统和方法
-
申请号: US14570393申请日: 2014-12-15
-
公开(公告)号: US09519780B1公开(公告)日: 2016-12-13
- 发明人: Jiang Dong
- 申请人: Symantec Corporation
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: FisherBroyles LLC
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; H04L29/06
摘要:
A computer-implemented method for identifying malware may include (1) determining, for multiple commands within bytecode associated with a malware program, whether each command constitutes an invocation command, (2) filtering, based on the determination, invocation commands from the bytecode, (3) adding, for each invocation command filtered from the bytecode, an opcode, a format code, and a function prototype to a collection of opcodes, format codes, and function prototypes, (4) generating a digital fingerprint of the collection including the opcode, the format code, and the function prototype for each invocation command filtered from the bytecode, and (5) performing, by a computer security system, a remedial action to protect a user in response to detecting the presence of a variant of the malware program by determining that the digital fingerprint matches a candidate instance of bytecode under evaluation. Various other methods, systems, and computer-readable media are also disclosed.
信息查询