×

Statistical fingerprinting for malware detection and classification

  • US 9,135,440 B2
  • Filed: 07/31/2013
  • Issued: 09/15/2015
  • Est. Priority Date: 08/01/2012
  • Status: Active Grant
First Claim
Patent Images

1. A system that determines if malware exists in a computing architecture with an unknown pedigree comprising:

  • a first computing device having a known pedigree and operating free of malware, the first computing device operating a known software application that comprises a series of instrumented functions that, when executed, provide a statistical baseline time that is representative of the time it takes the software application to run on a computing device having a known pedigree and operating free of malware; and

    a second computing device having an unknown pedigree and with the potential of operating with malware, the second computing device operating the known software application that further comprises a series of instrumented functions that, when executed, provides an actual time that is representative of the time the known software application runs on the second computing device having an unknown pedigree and operating with the potential of operating with malware;

    where the instrumented functions are injected into the known software application through a code injection that facilitates accessing a plurality of subroutines that is shared by a plurality of software applications; and

    where the difference in times between the statistical baseline time and the actual time identifies a malware status of the second machine.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×