System and Method to Extract and Utilize Disassembly Features to Classify Software Intent
First Claim
Patent Images
1. A method to extract and utilize disassembly features to classify an intent of a software program, the method comprising the steps of:
- disassembling, at least partially, a software program;
extracting at least one feature from the at least partially disassembled software program;
processing the at least one feature using an algorithm; and
classifying the software program based on a result yielded from processing the at least one feature using the algorithm.
7 Assignments
0 Petitions
Accused Products
Abstract
A system and method operable to identify malicious software by extracting one or more features disassembled from software suspected to be malicious software and employing one or more of those features in a machine-learning algorithm to classify such software.
215 Citations
18 Claims
-
1. A method to extract and utilize disassembly features to classify an intent of a software program, the method comprising the steps of:
-
disassembling, at least partially, a software program; extracting at least one feature from the at least partially disassembled software program; processing the at least one feature using an algorithm; and classifying the software program based on a result yielded from processing the at least one feature using the algorithm. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A system operable to extract and utilize disassembly features to classify software intent of a software program, the system comprising:
-
a disassembly tool operable to at least partially disassemble a software program; an extractor operable to extract at least one feature from the at least partially disassembled software program; a processor operable to process the at least one feature using an algorithm; and a classifier operable to classify the software program based on a result yielded from processing the at least one feature using the algorithm. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18)
-
Specification