Invention Grant
- Patent Title: Methods for identifying malicious software
- Patent Title (中): 识别恶意软件的方法
-
Application No.: US10948147Application Date: 2004-09-24
-
Publication No.: US07644441B2Publication Date: 2010-01-05
- Inventor: Matthew N. Schmid , Michael Weber , Michael Haddox-Schatz , David Geyer
- Applicant: Matthew N. Schmid , Michael Weber , Michael Haddox-Schatz , David Geyer
- Applicant Address: US VA Dulles
- Assignee: Cigital, Inc.
- Current Assignee: Cigital, Inc.
- Current Assignee Address: US VA Dulles
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: G08B23/00
- IPC: G08B23/00 ; G06F11/30 ; G06F12/14

Abstract:
Malicious software is identified in an executable file by identifying malicious structural features, decryption code, and cryptographic functions. A malicious structural feature is identified by comparing a known malicious structural feature to one or more instructions of the executable file. A malicious structural feature is also identified by graphically and statistically comparing windows of bytes or instructions in a section of the executable file. Cryptography is an indicator of malicious software. Decryption code is identified in an executable file by identifying a tight loop around a reversible instruction that writes to random access memory. Cryptographic functions are identified in an executable file be obtaining a known cryptographic function and performing a string comparison of the numeric constants of the known cryptographic function with the executable file.
Public/Granted literature
- US20050223238A1 Methods for identifying malicious software Public/Granted day:2005-10-06
Information query