×

SYSTEMS AND METHODS FOR AUTOMATED GENERATION OF GENERIC SIGNATURES USED TO DETECT POLYMORPHIC MALWARE

  • US 20170193229A1
  • Filed: 02/11/2016
  • Published: 07/06/2017
  • Est. Priority Date: 12/30/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for automated generation of generic signatures used to detect polymorphic malware, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

  • clustering a set of polymorphic file samples that share a set of static attributes in common with one another;

    computing a distance of the polymorphic file samples from a centroid that represents a reference data point with respect to the set of polymorphic file samples;

    determining that the distance of the polymorphic file samples from the centroid is below a certain threshold;

    upon determining that the distance is below the certain threshold;

    identifying, within the set of static attributes shared in common by the polymorphic file samples, a subset of static attributes whose values are identical across all of the polymorphic file samples;

    generating a generic file-classification signature from the subset of static attributes.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×