Invention Grant
- Patent Title: Obfuscated malware detection
- Patent Title (中): 混淆的恶意软件检测
-
Application No.: US12639465Application Date: 2009-12-16
-
Publication No.: US08176559B2Publication Date: 2012-05-08
- Inventor: Rachit Mathur , Cedric Cochin
- Applicant: Rachit Mathur , Cedric Cochin
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Fish & Richardson P.C.
- Main IPC: G06F11/28
- IPC: G06F11/28 ; G06F11/30 ; G08B23/00 ; G06F12/14

Abstract:
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes executing from a binary executable a call instruction and a plurality of instruction subsequent to a target of the call instruction, determining if the value identified by the stack pointer of the call stack is equal to a default value stored in the call stack prior to emulation, determining if there is a non-obfuscation signal resulting from the execution of the call instructions and the plurality of instructions, and if the value identified by the stack pointer is the default value and there is no obfuscation signal, identifying the call instruction as a possibly obfuscated call instruction; Additionally, the method includes determining that if the number of call instructions identified as possibly obfuscated call instructions exceeds a threshold number, identifying the binary executable as an obfuscated executable.
Public/Granted literature
- US20110145921A1 OBFUSCATED MALWARE DETECTION Public/Granted day:2011-06-16
Information query