发明名称 Systems, apparatus, and methods for detecting malware
摘要 Various embodiments, including a method comprising creating a first fuzzy fingerprint of a known malware file, the first fuzzy fingerprint including a first set of calculated complexity approximations and weightings for each of a plurality of blocks within the known malware file, creating a second fuzzy fingerprint of a file to be checked, the second fuzzy fingerprint including a second set of calculated complexity approximations and weightings for each of a plurality of blocks within the file to be checked, comparing the second fuzzy fingerprint to the first fuzzy fingerprint, calculating a similarity probability for each of the block-wise comparisons, the calculation including a respective weightings for each of the plurality of blocks within the known malware file and for each of the plurality of blocks within the file to be checked, and the calculation including a distance between the compared blocks; and calculating an overall similarity probability for the plurality of blocks compared.
申请公布号 US8312546(B2) 申请公布日期 2012.11.13
申请号 US20070738882 申请日期 2007.04.23
申请人 ALME CHRISTOPH;MCAFEE, INC. 发明人 ALME CHRISTOPH
分类号 G06F11/00;G06F12/14;G06F12/16;G08B23/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址