Invention Grant
- Patent Title: Systems and methods for malware classification
- Patent Title (中): 用于恶意软件分类的系统和方法
-
Application No.: US12631001Application Date: 2009-12-04
-
Publication No.: US08635694B2Publication Date: 2014-01-21
- Inventor: Alexey Malyshev , Timur Biyachuev , Dmitry Ilin
- Applicant: Alexey Malyshev , Timur Biyachuev , Dmitry Ilin
- Applicant Address: RU Moscow
- Assignee: Kaspersky Lab ZAO
- Current Assignee: Kaspersky Lab ZAO
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: RU2009136235 20090110
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
Disclosed are systems, methods and computer program products for detection, classification and reporting of malicious software. A method comprises loading software code into a computer system memory and emulating the software code. The software code and its activity log are then analyzed for presence of a malware. If a malware is detected, an execution flow graph is created from the activity log. The execution flow graph is then parsed using heuristic analysis to identify one or more malicious behavior patterns therein. Then, similarity indexes between the identified malicious behavior patterns and one or more malicious behavior patterns associated with known classes of malware are computed. The emulated software code is then classified into one or more classes of malware based on the computed similarity indexes. Finally, a comprehensive malware report of the emulated software code is generated based on the execution flow graph and malware classification information.
Public/Granted literature
- US20100180344A1 Systems and Methods For Malware Classification Public/Granted day:2010-07-15
Information query