- Patent Title: Leveraging behavior-based rules for malware family classification
-
Application No.: US14967180Application Date: 2015-12-11
-
Publication No.: US10176321B2Publication Date: 2019-01-08
- Inventor: Fahim H. Abbasi , Abdul Salam , Farrukh Shahzad
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Rutan & Tucker, LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56

Abstract:
According to one embodiment, a malware classification scheme operating with an electronic device, configured with one or more hardware processors and a memory that stores the software handling the malware classification scheme that is conducted through analysis of behavior-based rules, is described. This malware classification scheme (i) conducts a determination whether a sequence of rules correspond to potential malicious behaviors detected during analysis of a malware sample within one or more virtual machines, and in response to determining that the sequence of rules corresponds to potential malicious behaviors, (ii) conducts an attempt to classify the malware sample to at least one known malware family based on an analysis of the sequence of rules.
Public/Granted literature
- US20170083703A1 LEVERAGING BEHAVIOR-BASED RULES FOR MALWARE FAMILY CLASSIFICATION Public/Granted day:2017-03-23
Information query