The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 03, 2018

Filed:

Jun. 14, 2016
Applicant:

AO Kaspersky Lab, Moscow, RU;

Inventors:

Anton M. Ivanov, Moscow, RU;

Alexander V. Liskin, Moscow, RU;

Assignee:

AO KASPERSKY LAB, Moscow, RU;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 9/455 (2018.01); G06F 17/30 (2006.01);
U.S. Cl.
CPC ...
G06F 21/565 (2013.01); G06F 9/45558 (2013.01); G06F 17/30233 (2013.01); G06F 17/30598 (2013.01); G06F 2009/45587 (2013.01); G06F 2221/033 (2013.01); G06F 2221/034 (2013.01);
Abstract

Disclosed are method and system for detecting harmful files executed by a virtual stack machine. An example method includes: analyzing a file executable on the virtual stack machine to identify both parameters of a file section of the file and parameters of a function of the virtual stack machine when executing the file; identifying, in a database, at least one cluster of safe files based on the identified parameters of the file section of the file and the identified parameters of the virtual stack machine; creating, using at least one clustering rule, a data cluster based on the identified at least one cluster of safe files; calculating at least one checksum of the created data cluster; and determining that the file executable on the virtual stack machine is harmful if the computed at least one checksum matches a checksum in a database of checksums of harmful files.


Find Patent Forward Citations

Loading…