Invention Grant
- Patent Title: Behavioral signature generation using clustering
- Patent Title (中): 使用聚类的行为签名生成
-
Application No.: US12769262Application Date: 2010-04-28
-
Publication No.: US08464345B2Publication Date: 2013-06-11
- Inventor: Sourabh Satish , Shane Pereira
- Applicant: Sourabh Satish , Shane Pereira
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Fenwick & West LLP
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
A behavioral signature for detecting malware is generated. A computer is used to collect behavior traces of malware in a malware dataset. The behavior traces describe sequential behaviors performed by the malware. The behavior traces are normalized to produce malware behavior sequences. Similar malware behavior sequences are clustered together. The malware behavior sequences in a cluster describe behaviors of a malware family. The cluster is analyzed to identify a behavior subsequence common to the cluster's malware family. A behavior signature for the malware family is generated using the behavior subsequence. A trace of new malware is normalized and aligned with an existing cluster, if possible. The behavioral signature for that cluster is generated based on the behavior sequence of the new malware and the other sequences in the cluster.
Public/Granted literature
- US20110271341A1 BEHAVIORAL SIGNATURE GENERATION USING CLUSTERING Public/Granted day:2011-11-03
Information query