The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Patent No.:

US 8332944 B1

PDF
Full Text
Expired
Date of Patent:
Dec. 11, 2012

Filed:

Feb. 01, 2010
Applicants:

Boris Rozenberg, Beer Sheva, IL;

Ehud Gudes, Beer Sheva, IL;

Yuval Elovici, Moshav Arugot, IL;

Inventors:

Boris Rozenberg, Beer Sheva, IL;

Ehud Gudes, Beer Sheva, IL;

Yuval Elovici, Moshav Arugot, IL;

Assignee:

Other;

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 12/14 (2006.01);
U.S. Cl.
CPC ...
Abstract

The invention relates to a method for detecting malicious executables, which comprises: in an offline training phase, finding a collection of system call sequences that are characteristic only to malicious files, when such malicious files are executed, and storing said sequences in a database; and, in runtime, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences of system calls within the database to determine whether there exists a match between a portion of the sequence of the run-time system calls and one or more of the database sequences, and when such a match is found, declaring said executable as malicious.


Find Patent Forward Citations

Loading…