Invention Grant
- Patent Title: Method and system for determining affiliation of software to software families
-
Application No.: US17087775Application Date: 2020-11-03
-
Publication No.: US11250129B2Publication Date: 2022-02-15
- Inventor: Pavel Vladimirovich Slipenchuk , Ilia Sergeevich Pomerantsev
- Applicant: Group IB TDS, Ltd
- Applicant Address: RU Moscow
- Assignee: Group IB TDS, Ltd
- Current Assignee: Group IB TDS, Ltd
- Current Assignee Address: RU Moscow
- Agency: BCF LLP
- Priority: RURU2019139628 20191205
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55 ; G06F21/14 ; G06F21/60

Abstract:
A method and a system for determining an affiliation of a given software with target software are provided. The method comprises: receiving a file including a machine code associated with the given software; determining a file format; identifying, based on the file format, in the machine code, at least one function of a plurality of functions; generating, for each one of the plurality of functions associated with the given software, a respective function identifier; aggregating respective function identifiers, thereby generating an aggregated array of function identifiers associated with the given software; applying at least one classifier to the aggregated array of function identifiers to determine a likelihood parameter indicative of the given software being affiliated to a respective target software; in response to the likelihood parameter being equal to or greater than a predetermined likelihood parameter threshold: identifying the given software as being affiliated to the respective target software.
Public/Granted literature
- US20210173927A1 METHOD AND SYSTEM FOR DETERMINING AFFILIATION OF SOFTWARE TO SOFTWARE FAMILIES Public/Granted day:2021-06-10
Information query