- 专利标题: Fuzzy hash of behavioral results
-
申请号: US15076322申请日: 2016-03-21
-
公开(公告)号: US09912691B2公开(公告)日: 2018-03-06
- 发明人: Ali Mesdaq , Paul L. Westin, III
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye, Inc.
- 当前专利权人: FireEye, Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Rutan & Tucker, LLP
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06 ; G06F21/56
摘要:
A computerized method for classifying objects in a malware system is described. The method includes detecting behaviors of an object for classification after processing of the object has begun. Data associated with the detected behaviors is collected, and a fuzzy hash for the received object is generated. The generation of the fuzzy hash may include (i) removing a portion of the data associated with the detected behaviors, and (ii) performing a hash operation on a remaining portion of the data associated with the detected behaviors. Thereafter, the fuzzy hash for the received object is compared to a fuzzy hash of an object in a preexisting cluster to generate a similarity measure. The received object is associated with the preexisting cluster in response to determining that the similarity measure is above a predefined threshold value. Thereafter, the results are reported.
公开/授权文献
- US20160261612A1 FUZZY HASH OF BEHAVIORAL RESULTS 公开/授权日:2016-09-08
信息查询