Invention Grant
- Patent Title: System and method for detecting malicious compound files
-
Application No.: US15411132Application Date: 2017-01-20
-
Publication No.: US10339312B2Publication Date: 2019-07-02
- Inventor: Andrey V. Krukov , Alexander V. Liskin , Anton M. Ivanov
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO KASPERSKY LAB
- Current Assignee: AO KASPERSKY LAB
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: RU2016139470 20161010
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
A method and system is provided for detecting malicious compound files. An example method includes: obtaining at least one compound file; identifying a first set of features of the at least one compound file including features associated with a header of the at least one compound file; subsequent to identifying the first set of features, identifying, by the processor, a second set of features of the at least one compound file including features associated with at least one directory of the at least one compound file; determining a hash sum of the at least one compound file based on the first and second set of features; comparing the hash sum of the at least one compound file with information associated with a plurality of compound files stored in a database; and identifying the at least one compound file as being malicious, trusted or untrusted based at least on comparison results.
Public/Granted literature
- US20180101682A1 SYSTEM AND METHOD FOR DETECTING MALICIOUS COMPOUND FILES Public/Granted day:2018-04-12
Information query