Invention Grant
- Patent Title: Method and system for clustering executable files
-
Application No.: US17486428Application Date: 2021-09-27
-
Publication No.: US11947572B2Publication Date: 2024-04-02
- Inventor: Ilia Sergeevich Pomerantsev
- Applicant: F.A.C.C.T. NETWORK SECURITY LLC
- Applicant Address: RU Moscow
- Assignee: GROUP IB TDS, LTD
- Current Assignee: GROUP IB TDS, LTD
- Current Assignee Address: RU Moscow
- Agency: BCF LLP
- Priority: RU 21108261 2021.03.29
- Main IPC: G06F16/00
- IPC: G06F16/00 ; G06F16/11 ; G06F16/28

Abstract:
A method and a system for clustering executable files are provided. The method comprises: obtaining a plurality of executable files; for each executable file: (i) detecting repeat sequences of commands of a predetermined length in a given executable file; (ii) determining at least one frequently occurring sequence of the repeat sequences in the given executable file; and based on the at least one frequently occurring sequence of commands, attributing the given executable file to a respective family; iteratively executing the detecting, the determining, and the attributing until one of: all of the plurality of executable files are attributed to at least one respective family, and until un-attributed files of the plurality of executable files do not contain any repeat sequences of commands; and responsive to presence of un-attributed files, attributing each of the un-attributed files of the plurality of executable files to a separate family.
Public/Granted literature
- US20220309077A1 METHOD AND SYSTEM FOR CLUSTERING EXECUTABLE FILES Public/Granted day:2022-09-29
Information query