Invention Grant
- Patent Title: Automated malware family signature generation
-
Application No.: US16537403Application Date: 2019-08-09
-
Publication No.: US11057405B2Publication Date: 2021-07-06
- Inventor: Zhi Xu , Jiajie Wang , Xiao Zhang , Wenjun Hu
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Van Pelt, Yi & James LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N20/00

Abstract:
The automatic generation of malware family signatures is disclosed. A set of metadata associated with a plurality of samples is received. The samples are clustered. For members of a first cluster, a set of similarities shared among at least a portion of the members of the first cluster is determined. The similarities are evaluated for suitability as a malware family signature. Suitability is evaluated based on how well the similarities uniquely identify the members of the first cluster. In the event the similarities are determined to be suitable as a malware family signature, a signature is generated.
Information query