Patent · US Active

Classification of malware using clustering that orders events in accordance with the time of occurance

US7809670B2 · kind B2 · utility

34Cited by
1References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 8, 2006
Grant dateOct 5, 2010
Priority date
Expiry dateAug 4, 2029

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/564
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

The present invention is directed to a method and system for automatically classifying an application into an application group which is previously classified in a knowledge base. More specifically, a runtime behavior of an application is captured as a series of events which are monitored and recorded during the execution of the application. The series of events are analyzed to find a proper application group which shares common runtime behavior patterns with the application. The knowledge base of application groups is previously constructed based on a large number of sample applications. The construction of the knowledge base is done in such a manner that each sample application can be classified into application groups based on a set of classification rules in the knowledge base. The set of classification rules are applied to a new application in order to classify the new application into one of the application groups.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.