Invention Grant
- Patent Title: Identification of electronic documents that are likely to contain embedded malware
- Patent Title (中): 识别可能包含嵌入式恶意软件的电子文档
-
Application No.: US13274077Application Date: 2011-10-14
-
Publication No.: US09177142B2Publication Date: 2015-11-03
- Inventor: Rodrigo Ribeiro Montoro
- Applicant: Rodrigo Ribeiro Montoro
- Applicant Address: US IL Chicago
- Assignee: TRUSTWAVE HOLDINGS, INC.
- Current Assignee: TRUSTWAVE HOLDINGS, INC.
- Current Assignee Address: US IL Chicago
- Agency: Hanley, Flight & Zimmerman, LLC
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
The present invention provides a method for determining the likelihood that an electronic document contains embedded malware. After parsing or sequencing an electronic document, the metadata structures that make up the document are analyzed. A number of pre-established rules are then applied with respect to certain metadata structures that are indicative of embedded malware. The application of these rules results in the generation of a score for the electronic document being tested for embedded malware. The score is then compared to a threshold value, where the threshold value was previously generated based on a statistical model relating to electronic documents having the same format as the document being tested. The result of the comparison can then be used to determine whether the document being tested is or is not likely to contain embedded malware.
Public/Granted literature
- US20130097705A1 IDENTIFICATION OF ELECTRONIC DOCUMENTS THAT ARE LIKELY TO CONTAIN EMBEDDED MALWARE Public/Granted day:2013-04-18
Information query