Invention Grant
- Patent Title: Automatically detecting a malicious file using name mangling strings
-
Application No.: US15629397Application Date: 2017-06-21
-
Publication No.: US10243977B1Publication Date: 2019-03-26
- Inventor: Srinivasan Govindarajan , Yuvaraj M , Swapan Kumar Ghosh
- Applicant: SYMANTEC CORPORATION
- Applicant Address: US CA Mountain View
- Assignee: SYMANTEC CORPORATION
- Current Assignee: SYMANTEC CORPORATION
- Current Assignee Address: US CA Mountain View
- Agency: Maschoff Brennan
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; H04L9/06

Abstract:
Automatically detecting a malicious file using name mangling strings. In one embodiment, a method may include (a) identifying a file, (b) identifying name mangling strings in the file, (c) concatenating the name mangling strings together, (d) hashing the concatenated name mangling strings to generate a signature for the file, (e) clustering the file with other files with matching signatures into a cluster, (f) determining that any of the files in the cluster is malicious, (g) adding the signature to a list of signatures of files known to be malicious, (f) identifying a network device file stored on a network device, (g) repeating (b)-(d) on the network device file, (h) determining that the signature for the network device file matches any signature in the list of signatures of files known to be malicious, and (i) performing a security action on the malicious file on the network device.
Information query