The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 17, 2022

Filed:

Mar. 29, 2019
Applicant:

Jinan University, Guangdong, CN;

Inventors:

Quanlong Guan, Guangdong, CN;

Weiqi Luo, Guangdong, CN;

Huanming Zhang, Guangdong, CN;

Zhefu Li, Guangdong, CN;

Lin Cui, Guangdong, CN;

Yuanfen Wu, Guangdong, CN;

Assignee:

Other;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); G06F 12/14 (2006.01); G06F 12/16 (2006.01); G08B 23/00 (2006.01); G06F 21/56 (2013.01); G06F 21/54 (2013.01); G06F 21/57 (2013.01); G06F 21/60 (2013.01); G06K 9/62 (2022.01);
U.S. Cl.
CPC ...
G06F 21/564 (2013.01); G06F 21/54 (2013.01); G06F 21/568 (2013.01); G06F 21/577 (2013.01); G06F 21/602 (2013.01); G06K 9/6215 (2013.01);
Abstract

A method for detecting mobile malware, including step S: compressing a mobile software subject to detection and a primary mobile software each containing N functions, wherein each of the functions is compressed into a hash value, a description entropy and a compressed string; S: calculating a quantity of identical functions between the mobile software subject to detection and the primary mobile software; and then finding out a quantity of similar functions using Hdsim method or entropy_descpt_sim method; and then calculating a degree of similarity to obtain a value of similarity; S: comparing the value of similarity with a predetermined threshold value; if the value of similarity is greater then or equal to the predetermined threshold value, the mobile software subject to detection is suspected to repackaging; if the value of similarity is smaller than the predetermined threshold value, the mobile software subject to detection is not suspected to repackaging.


Find Patent Forward Citations

Loading…