发明名称 SYSTEM AND METHOD FOR COMPUTER INSPECTION OF INFORMATION OBJECTS FOR SHARED MALWARE COMPONENTS
摘要 Embodiments of a system and method for computer inspection of information objects, for example, executable software applications for common components that may include elements of computer viruses, items from hacker exploit libraries, or other malware components. Information objects may contain identified sequences of instructions, each of which may be identified and hierarchically grouped based on their structural relationship(s). In the software context, programming languages may include multiple components that include functional code; these components are often shared between programmers. In some embodiments, an inspection of the hierarchical relationship of components (e.g., constituent functions) in the information objects may allow for identification of common components shared between programs. In some embodiments, authorship of objects or components in the objects may be identified by comparisons between component samples. In some embodiments, inspection of the relationship between components is limited to component groups having a specified structural size, complexity, or eccentricity.
申请公布号 US2014059684(A1) 申请公布日期 2014.02.27
申请号 US201213592596 申请日期 2012.08.23
申请人 WYSCHOGROD DANIEL;JILCOTT STEVEN W.;RUBIN JONATHAN ARON;EVERETT JOHN O.;RAYTHEON BBN TECHNOLOGIES CORP. 发明人 WYSCHOGROD DANIEL;JILCOTT STEVEN W.;RUBIN JONATHAN ARON;EVERETT JOHN O.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址