Invention Grant
- Patent Title: Systems and methods for detecting obfuscated malware
- Patent Title (中): 用于检测混淆的恶意软件的系统和方法
-
Application No.: US12500630Application Date: 2009-07-10
-
Publication No.: US09087195B2Publication Date: 2015-07-21
- Inventor: Maxim Y. Golovkin
- Applicant: Maxim Y. Golovkin
- Applicant Address: RU Moscow
- Assignee: Kaspersky Lab ZAO
- Current Assignee: Kaspersky Lab ZAO
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F15/16 ; G06F21/56

Abstract:
Disclosed are systems, methods and computer program products for efficient and reliable analysis, optimization and detection of obfuscated malware. One disclosed example method for malware detection includes loading an executable software code on a computer system and disassembling the software code into an assembly language or other low-level programming language. The method then proceeds to simplifying complex assembly instructions and constructing a data flow model of the simplified software code. The dependencies and interrelations of code elements of the data flow model are analyzed to identify obfuscated software codes therein. The identified obfuscated codes are then optimized. Based on the results of optimization, determination is made whether the software code is malicious and/or whether further antimalware analysis of the optimized software code is necessary.
Public/Granted literature
- US20110010697A1 Systems and Methods for Detecting Obfuscated Malware Public/Granted day:2011-01-13
Information query