Automated malware family signature generation
Abstract:
A set of metadata associated with a plurality of samples is received. The samples are clustered. For members of a first cluster, a set of similarities shared among at least a portion of the members of the first cluster is determined. A cluster member is identified within the first cluster, and in response, additional analysis is caused to be performed on the outlier cluster member.
Public/Granted literature
Information query
Patent Agency Ranking
0/0