×

Detection of code-based malware

  • US 8,713,679 B2
  • Filed: 02/18/2011
  • Issued: 04/29/2014
  • Est. Priority Date: 02/18/2011
  • Status: Active Grant
First Claim
Patent Images

1. A system comprising:

  • one or more hardware processors; and

    one or more computer-readable storage media storing computer-executable instructions that are executable by the one or more hardware processors to cause the system to perform operations including;

    determining code contexts from known malicious script and known benign script;

    building abstract syntax trees (ASTs) using code found in the code contexts;

    extracting structural features from the known malicious script and known benign script based on structures and contents of the ASTs, the structural features being different from text of the known malicious script and the known benign script;

    comparing structural features from unclassified script with the structural features from the known malicious script and the known benign script; and

    classifying the unclassified script as malicious or benign based on the comparison of the structural features from the unclassified script with the structural features from the known malicious script and the known benign script.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×