Invention Grant
- Patent Title: Detecting malware with hash-based fingerprints
-
Application No.: US15721244Application Date: 2017-09-29
-
Publication No.: US10678921B2Publication Date: 2020-06-09
- Inventor: Libor Mo{hacek over (r)}kovský
- Applicant: Avast Software s.r.o.
- Applicant Address: CZ Prague
- Assignee: Avast Software s.r.o.
- Current Assignee: Avast Software s.r.o.
- Current Assignee Address: CZ Prague
- Agency: Erickson Kernell IP, LLC
- Main IPC: G06F21/56
- IPC: G06F21/56 ; H04L29/06 ; G06F11/30 ; G06F11/34 ; G06F21/52

Abstract:
Detecting malware includes monitoring an event stream for an executable program, where the event stream includes a plurality of events such as API call events. A first plurality of hash values is determined for the event stream. In response to an occurrence of a trigger event in the event stream, the first plurality of hash values for the event stream can be compared with a second plurality of hash values that represents an event stream for a known malware executable. A determination can be made if a behavior represented by the first plurality of hash values is a permitted behavior based on the comparison.
Public/Granted literature
- US20180096149A1 DETECTING MALWARE WITH HASH-BASED FINGERPRINTS Public/Granted day:2018-04-05
Information query