发明名称 SYSTEMS AND METHODS FOR IDENTIFYING ASSOCIATIONS BETWEEN MALWARE SAMPLES
摘要 Systems and methods are disclosed for identifying associations between binary samples, such as e-mail files and their attachments or a document and an executable program associated with the document. In one implementation, the method includes receiving a plurality of binary samples, and extracting metadata from the plurality of binary samples. The metadata for a binary sample from the plurality of binary samples includes a set of attributes of the binary sample. The method further includes identifying a set of associations between the plurality of binary samples based on the extracted metadata. Each association is characterized by at least one attribute the associated binary samples have in common, and each association has a confidence level indicative of a strength of the association. The method also includes identifying associations with a confidence level that exceeds a predefined threshold.
申请公布号 US2013046763(A1) 申请公布日期 2013.02.21
申请号 US201113338845 申请日期 2011.12.28
申请人 VERISIGN, INC.;SINCLAIR GREGORY;OLSON RYAN;FALCONE ROBERT 发明人 SINCLAIR GREGORY;OLSON RYAN;FALCONE ROBERT
分类号 G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址