×

Automatic generation of generic file signatures

  • US 9,762,593 B1
  • Filed: 09/09/2014
  • Issued: 09/12/2017
  • Est. Priority Date: 09/09/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for automatically generating signatures for detecting malware, comprising:

  • collecting a set of static attributes from a malware dataset and a goodware dataset;

    generating a plurality of decision trees from the set of static attributes, wherein each decision tree in the plurality of decision trees comprises a plurality of terminal nodes;

    identifying, for each sample in a known-file dataset, a pattern of terminal nodes to which the sample is mapped by the plurality of decision trees, wherein the pattern of terminal nodes of the sample comprises a representation of a terminal node from each decision tree within the plurality of decision trees to which the sample has been mapped;

    generating a cluster of samples comprising samples in the known file dataset that have identical patterns of terminal nodes;

    validating the cluster of samples against a reputation value range to determine a purity of the cluster of samples; and

    generating, based at least in part on the purity of the cluster of samples, a signature for identifying additional files that are similar to the samples in the cluster of samples.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×