发明名称 Method and system for automatic invariant byte sequence discovery for generic detection
摘要 A method for creating a set of genericized signatures for detection of byte sequences in computer code includes accessing a first set of sample signatures, determining a maximum number of wildcards that a wildcarded signature may comprise, determining a first wildcarded signature corresponding to the first set of sample signatures, evaluating the first wildcarded signature, and repeating the steps of evaluating for any second wildcarded signatures. Each of the signatures corresponds to an instance of malware. The evaluation further includes if the number of wildcards in the first wildcarded signature exceeds the maximum number of wildcards, determining a plurality of second wildcarded signatures corresponding to a plurality of subsets of the set of sample signatures. The evaluation further includes if the number of wildcards in the first wildcarded signature is less than or equal to the maximum number of wildcards, adding the first wildcarded signature to a set of genericized signatures.
申请公布号 US8555382(B2) 申请公布日期 2013.10.08
申请号 US20100820717 申请日期 2010.06.22
申请人 MICHLIN IRENE;BARTRAM ANTHONY VAUGHAN;MCAFEE, INC. 发明人 MICHLIN IRENE;BARTRAM ANTHONY VAUGHAN
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址