×

System and method for determining data entropy to identify malware

  • US 8,069,484 B2
  • Filed: 01/25/2007
  • Issued: 11/29/2011
  • Est. Priority Date: 01/25/2007
  • Status: Active Grant
First Claim
Patent Images

1. A malware detection method, the method comprising the steps of:

  • calculating a global entropy value for a block of data, said block of data comprising a plurality of data samples;

    iteratively calculating an individual sample entropy value for each of the plurality of data samples to create a plurality of individual sample entropy values, wherein each of the plurality of data samples contains at least a portion of data overlapping at least one of an immediately preceding data sample and an immediately subsequent data sample;

    performing a statistical method on the plurality of individual sample entropy values;

    comparing at least one of the global entropy value and an individual sample entropy value to a threshold value; and

    recording the block of data as suspicious when at least one of the global entropy value and an individual sample entropy value exceeds the threshold value.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×