Patent · US Active

System and method for advanced malware analysis

US9106692B2 · kind B2 · utility

3Cited by
0References
15Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 31, 2013
Grant dateAug 11, 2015
Priority date
Expiry dateJan 31, 2033

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and a method for advanced malware analysis. The method filters incoming messages with a watch-list, the incoming messages including attachments, if an incoming message matches the watch-list, forwards the message to a malware detection engine, strips the attachments from the forwarded message, the one or more attachments including one or more executable files, launches a plurality of sandboxes, executes each of the executable files in the plurality of sandboxes, the sandboxes generating analysis results that may be used to determine whether each executable file is malicious, normalizes the analysis results, evaluates the risk level of the attachments to the forwarded message based on the normalized analysis results of the executable files in the attachments to the forwarded message, and, if the risk level of an attachment to the forwarded message is above a certain level, determines that the forwarded message is malicious and permanently quarantines the forwarded message.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.