Invention Grant
- Patent Title: System and method for detecting malicious executable files based on similarity of their resources
- Patent Title (中): 基于资源相似性检测恶意可执行文件的系统和方法
-
Application No.: US14072391Application Date: 2013-11-05
-
Publication No.: US09043915B2Publication Date: 2015-05-26
- Inventor: Ivan I. Tatarinov
- Applicant: Kaspersky Lab ZAO
- Applicant Address: RU Moscow
- Assignee: Kaspersky Lab ZAO
- Current Assignee: Kaspersky Lab ZAO
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: RU2013125979 20130606
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F21/56

Abstract:
Disclosed are systems, methods and computer program products for detection of malicious executable files based on the similarity of various types of extractable resources of the executable files. In one aspect, the system determines a type of an executable file being analyzed and determines types of extractable resources of the executable file based on the type of the executable file. The system then extracts the identified extractable resources of the executable file and compares the extracted resources to known resources of malicious executable files. The system then determines a degree of similarity between the compared resources. The system then determines whether the executable file is malicious based on a degree of similarity of the one or more compared resources.
Public/Granted literature
- US20140366137A1 System and Method for Detecting Malicious Executable Files Based on Similarity of Their Resources Public/Granted day:2014-12-11
Information query