Invention Grant
- Patent Title: Systems and methods for evaluating unfamiliar executables
-
Application No.: US15826642Application Date: 2017-11-29
-
Publication No.: US10678917B1Publication Date: 2020-06-09
- Inventor: Brian T. Witten , Christopher Gates
- Applicant: Symantec Corporation
- Applicant Address: US AZ Tempe
- Assignee: NortonLifeLock Inc.
- Current Assignee: NortonLifeLock Inc.
- Current Assignee Address: US AZ Tempe
- Agency: FisherBroyles, LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55

Abstract:
The disclosed computer-implemented method for evaluating unfamiliar executables may include (i) identifying, on the computing device, (a) a code object that is generated from source code written in a programming language, that is specified in an intermediate language different from the programming language, and that can be compiled into an executable file by a just-in-time compiler on the computing device and (b) an executable file that lacks an assigned reputation in a reputation system that distinguishes benign and malicious files, (ii) determining that the executable file was produced by the just-in-time compiler compiling the code object on the computing device, (iii) retrieving, from the reputation system, a reputation for the code object, and (iv) performing a security action on the executable file that is based on the reputation of the code object. Various other methods, systems, and computer-readable media are also disclosed.
Information query