发明名称 MALWARE IDENTIFICATION AND SCANNING
摘要 A method for automatically generating a genetic signature for a set of malware, comprising parsing (step S11) the malware to identify a set of binary comparable features present in said malware, storing (step S5; step S11) all binary comparable features occurring in said set of malware, determining (step S13, S14) a subset comprising binary comparable features occurring in at least a predetermined portion of all malware in the set, and including (step S15) representations of the binary comparable features in the subset in the genetic signature. Compared to prior art systems, the genetic signature according to the present invention is unique in that it does not rely on relationships between individual features, only on their occurrence in various malware in the set. A genetic signature according to the present invention may for example consist of associations to five different features which have no relation to each other at all.
申请公布号 US2011154495(A1) 申请公布日期 2011.06.23
申请号 US20090643032 申请日期 2009.12.21
申请人 STRANNE ODD WANDENOR 发明人 STRANNE ODD WANDENOR
分类号 G06F21/22;G06N3/12 主分类号 G06F21/22
代理机构 代理人
主权项
地址