×

Fuzzy hash of behavioral results

  • US 9,294,501 B2
  • Filed: 09/30/2013
  • Issued: 03/22/2016
  • Est. Priority Date: 09/30/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computerized method for classifying objects in a malware system, comprising:

  • receiving, by a malicious content detection (MCD) system from a client device, an object to be classified;

    detecting behaviors of the received object, wherein the behaviors are detected after processing the received object;

    generating a fuzzy hash for the received object based on the detected behaviors, the generating of the fuzzy hash comprises (i) obtaining a reduced amount of data associated with the detected behaviors by retaining a portion of the data associated with the detected behaviors that corresponds to one or more operations conducted during processing of the received object, and removing metadata associated with the one or more operations conducted during the processing of the received object, the metadata including at least one or more identifiers of processes called during the processing of the received object, and (ii) performing a hash operation on the reduced amount of data associated with the detected behaviors;

    comparing the fuzzy hash for the received object with a fuzzy hash of an object in a preexisting cluster to generate a similarity measure;

    associating the received object with the preexisting cluster in response to determining that the similarity measure is above a predefined threshold value;

    creating a new cluster for the received object in response to determining that the similarity measure is below the predefined threshold value; and

    reporting, by the MCD system, results of either (i) the associating of the received object with the preexisting cluster or (ii) the creating of the new cluster.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×