Invention Grant
US09043915B2 System and method for detecting malicious executable files based on similarity of their resources 有权
基于资源相似性检测恶意可执行文件的系统和方法

  • Patent Title: System and method for detecting malicious executable files based on similarity of their resources
  • Patent Title (中): 基于资源相似性检测恶意可执行文件的系统和方法
  • Application No.: US14072391
    Application Date: 2013-11-05
  • Publication No.: US09043915B2
    Publication Date: 2015-05-26
  • Inventor: Ivan I. Tatarinov
  • Applicant: Kaspersky Lab ZAO
  • Applicant Address: RU Moscow
  • Assignee: Kaspersky Lab ZAO
  • Current Assignee: Kaspersky Lab ZAO
  • Current Assignee Address: RU Moscow
  • Agency: Arent Fox LLP
  • Agent Michael Fainberg
  • Priority: RU2013125979 20130606
  • Main IPC: G06F12/14
  • IPC: G06F12/14 G06F21/56
System and method for detecting malicious executable files based on similarity of their resources
Abstract:
Disclosed are systems, methods and computer program products for detection of malicious executable files based on the similarity of various types of extractable resources of the executable files. In one aspect, the system determines a type of an executable file being analyzed and determines types of extractable resources of the executable file based on the type of the executable file. The system then extracts the identified extractable resources of the executable file and compares the extracted resources to known resources of malicious executable files. The system then determines a degree of similarity between the compared resources. The system then determines whether the executable file is malicious based on a degree of similarity of the one or more compared resources.
Information query
Patent Agency Ranking
0/0