Invention Grant
- Patent Title: Systems and methods for automated generation of generic signatures used to detect polymorphic malware
-
Application No.: US15041043Application Date: 2016-02-11
-
Publication No.: US09836603B2Publication Date: 2017-12-05
- Inventor: Ajitesh RoyChowdhury , Anudeep Kumar , Himanshu Dubey , Nitin Shekokar
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: FisherBroyles, LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F21/56

Abstract:
The disclosed computer-implemented method for automated generation of generic signatures used to detect polymorphic malware may include (1) clustering a set of polymorphic file samples that share a set of static attributes in common with one another, (2) computing a distance of the polymorphic file samples from a centroid that represents a reference data point with respect to the set of polymorphic file samples, (3) determining that the distance of the polymorphic file samples from the centroid is below a certain threshold, and then upon determining that the distance is below the certain threshold, (4) identifying, within the set of static attributes shared in common by the polymorphic file samples, a subset of static attributes whose values are identical across all of the polymorphic file samples and (5) generating a generic file-classification signature from the subset of static attributes. Various other methods, systems, and computer-readable media are also disclosed.
Public/Granted literature
- US20170193229A1 SYSTEMS AND METHODS FOR AUTOMATED GENERATION OF GENERIC SIGNATURES USED TO DETECT POLYMORPHIC MALWARE Public/Granted day:2017-07-06
Information query