Invention Grant
- Patent Title: Wavelet decomposition of software entropy to identify malware
-
Application No.: US15236316Application Date: 2016-08-12
-
Publication No.: US09946876B2Publication Date: 2018-04-17
- Inventor: Michael Wojnowicz , Glenn Chisholm , Matthew Wolff , Derek A. Soeder , Xuan Zhao
- Applicant: Cylance Inc.
- Applicant Address: US CA Irvine
- Assignee: Cylance Inc.
- Current Assignee: Cylance Inc.
- Current Assignee Address: US CA Irvine
- Agency: Jones Day
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; G06F21/56 ; G06N3/08

Abstract:
A plurality of data files is received. Thereafter, each file is represented as an entropy time series that reflects an amount of entropy across locations in code for such file. A wavelet transform is applied, for each file, to the corresponding entropy time series to generate an energy spectrum characterizing, for the file, an amount of entropic energy at multiple scales of code resolution. It can then be determined, for each file, whether or not the file is likely to be malicious based on the energy spectrum. Related apparatus, systems, techniques and articles are also described.
Public/Granted literature
- US20160378984A1 Wavelet Decomposition Of Software Entropy To Identify Malware Public/Granted day:2016-12-29
Information query