Invention Grant
US09405905B2 Systems and methods for identifying associations between malware samples
有权
识别恶意软件样本之间关联的系统和方法
- Patent Title: Systems and methods for identifying associations between malware samples
- Patent Title (中): 识别恶意软件样本之间关联的系统和方法
-
Application No.: US14524325Application Date: 2014-10-27
-
Publication No.: US09405905B2Publication Date: 2016-08-02
- Inventor: Gregory Sinclair , Ryan Olson , Robert Falcone
- Applicant: Verisign, Inc.
- Applicant Address: US VA Reston
- Assignee: VERISIGN, INC.
- Current Assignee: VERISIGN, INC.
- Current Assignee Address: US VA Reston
- Agency: MH2 Technology Law Group, LLP
- Main IPC: G06F17/30
- IPC: G06F17/30 ; G06F7/00 ; G06F21/56 ; H04L29/06 ; G06Q10/10 ; H04L12/58

Abstract:
Systems and methods are disclosed for identifying associations between binary samples, such as e-mail files and their attachments or a document and an executable program associated with the document. In one implementation, the method includes receiving a plurality of binary samples, and extracting metadata from the plurality of binary samples. The metadata for a binary sample from the plurality of binary samples includes a set of attributes of the binary sample. The method further includes identifying a set of associations between the plurality of binary samples based on the extracted metadata. Each association is characterized by at least one attribute the associated binary samples have in common, and each association has a confidence level indicative of a strength of the association. The method also includes identifying associations with a confidence level that exceeds a predefined threshold.
Public/Granted literature
- US20150113648A1 SYSTEMS AND METHODS FOR IDENTIFYING ASSOCIATIONS BETWEEN MALWARE SAMPLES Public/Granted day:2015-04-23
Information query