×

Automatically determining whether malware samples are similar

  • US 10,200,390 B2
  • Filed: 02/29/2016
  • Issued: 02/05/2019
  • Est. Priority Date: 02/29/2016
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • receiving a plurality of samples for performing automated malware analysis to generate log files based on the automated malware analysis;

    processing the log files to determine artifacts associated with malware, wherein a raw log file generated for each of the plurality of samples comprises one or more lines based on results of the automated malware analysis for each of the plurality of samples, and wherein processing the log files to determine artifacts associated with malware further comprises;

    processing the raw log files for each of the plurality of samples to generate processed log files, wherein each of the processed log files provides a human readable format of the automated malware analysis; and

    identifying distinct lines in each of the processed log files; and

    comparing the processed log files based on the automated malware analysis based on a threshold comparison of a textual representation of one or more artifacts;

    determining whether any of the plurality of samples are similar based on comparing the processed log files based on the automated malware analysis; and

    performing an action based on determining that at least two samples are similar.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×