×

Malware detection

  • US 20110041179A1
  • Filed: 08/11/2009
  • Published: 02/17/2011
  • Est. Priority Date: 08/11/2009
  • Status: Abandoned Application
First Claim
Patent Images

1. A method of detecting potential malware, the method comprising:

  • at a server, receiving a plurality of code samples, the code samples including at least one code sample known to be malware and at least one code sample known to be legitimate, executing each of the code samples in an emulated computer system, extracting bytestrings from any changes in the memory of the emulated computer system that result from the execution of each sample, using the extracted bytestrings to determine one or more rules for differentiating between malware and legitimate code, and sending the rule(s) to one or more client computers; and

    at the one of more client computers, for a given target code, executing the target code in an emulated computer system, extracting bytestrings from any changes in the memory of the emulated computer system that result from the execution of the target code, and applying the rule(s) received from the server to the extracted bytestrings to determine if the target code is potential malware.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×