Invention Grant
- Patent Title: Malware classification for unknown executable files
- Patent Title (中): 未知可执行文件的恶意软件分类
-
Application No.: US13361054Application Date: 2012-01-30
-
Publication No.: US08745760B2Publication Date: 2014-06-03
- Inventor: Steven Robert Poulson
- Applicant: Steven Robert Poulson
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: G06F21/10
- IPC: G06F21/10 ; G06F15/173

Abstract:
Devices, methods and instructions encoded on computer readable medium are provided herein for implementation of classification techniques in order to determine if an unknown executable file is malware. In accordance with one example method, an unknown executable file comprising a sequence of operation codes (opcodes) is received. Based on the operation codes of the unknown executable, a subset of executable files in a training set is identified in which each of the files in the subset have the same beginning sequence of operation codes as the unknown executable. After the subset is identified, a feature set extracted from the unknown executable file is compared to one or more feature sets extracted from each of executable files in the identified subset. A determination is made, based on the feature set comparison, whether the unknown executable file is malware.
Public/Granted literature
- US20130198841A1 Malware Classification for Unknown Executable Files Public/Granted day:2013-08-01
Information query