The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 03, 2024

Filed:

Dec. 23, 2021
Applicant:

Mcafee, Llc, San Jose, CA (US);

Inventors:

Niall Fitzgerald, Mahon, IE;

German Lancioni, San Jose, CA (US);

Brian Gaither, Plano, TX (US);

Assignee:

MCAFEE, LLC, San Jose, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 21/56 (2013.01); G06F 40/20 (2020.01); G06F 40/279 (2020.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01); G06F 21/56 (2013.01); G06F 40/20 (2020.01); H04L 63/1416 (2013.01); G06F 40/279 (2020.01);
Abstract

Methods, apparatus, systems, and articles of manufacture are disclosed to determine mutex entropy for malware classification. An example apparatus includes interface circuitry to access a mutex associated with a software application, the mutex to include a mutex identifier string, normalizer circuitry to normalize the mutex identifier string, character probability circuitry to determine character probabilities of characters within the normalized mutex identifier string, the character probabilities based on a historical mutex character distribution, entropy calculator circuitry to calculate an entropy value for the mutex based on the character probabilities, classifier circuitry to classify the mutex as clean or malicious based on the entropy value, and protector circuitry to mitigate malicious attacks based on the classification.


Find Patent Forward Citations

Loading…