Patent · US Active

Dynamically adaptive framework and method for classifying malware using intelligent static, emulation, and dynamic analyses

US9171160B2 · kind B2 · utility

240Cited by
126References
31Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 30, 2013
Grant dateOct 27, 2015
Priority date
Expiry dateSep 30, 2033

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/034
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Techniques for malware detection are described herein. According to one aspect, control logic determines an analysis plan for analyzing whether a specimen should be classified as malware, where the analysis plan identifies at least first and second analyses to be performed. Each of the first and second analyses identified in the analysis plan including one or both of a static analysis and a dynamic analysis. The first analysis is performed based on the analysis plan to identify suspicious indicators characteristics related to processing of the specimen. The second analysis is performed based on the analysis plan to identify unexpected behaviors having processing or communications anomalies. A classifier determines whether the specimen should be classified as malicious based on the static and dynamic analyses. The analysis plan, the indicators, the characteristics, and the anomalies are stored in a persistent memory.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.