Invention Grant
- Patent Title: Detecting malware signed with multiple credentials
- Patent Title (中): 检测用多个凭据签名的恶意软件
-
Application No.: US12882882Application Date: 2010-09-15
-
Publication No.: US08996875B1Publication Date: 2015-03-31
- Inventor: William E. Sobel , Sourabh Satish
- Applicant: William E. Sobel , Sourabh Satish
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Brill Law Office
- Agent Jeffrey Brill
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56

Abstract:
Malware that is signed with multiple, valid credentials is detected. A central computer such as a server receives secure hashes of signed application bodies and immutable portions of corresponding digital signatures for a plurality of signed applications from a plurality of client computers. Received secure hashes of signed application bodies are compared. Multiple instances of a single signed application are identified based on the comparing of multiple received secure hashes of signed application bodies. Responsive to identifying multiple instances of the single signed application, received secure hashes of immutable portions of digital signatures corresponding to identified multiple instances of the single signed application are compared. Responsive to the results of this comparing, a potential maliciousness of the signed application is adjudicated.
Information query