The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 08, 2013

Filed:

Feb. 15, 2008
Applicants:

Gil Tahan, Omer, IL;

Asaf Shabtai, Carne Yosef, IL;

Yuval Elovici, Arugot, IL;

Inventors:

Gil Tahan, Omer, IL;

Asaf Shabtai, Carne Yosef, IL;

Yuval Elovici, Arugot, IL;

Assignee:

Other;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 15/18 (2006.01); G06F 11/00 (2006.01);
U.S. Cl.
CPC ...
Abstract

Method for the automatic generation of malware signatures from computer files. A common function library (CFL) created, wherein the CFL contains any functions identified as a part of the standard computer language used to write computer files which are known as not containing malware. The functions of a computer file which does contain a malware are extracted and the CFL is updated with any new common functions if necessary, such that the remaining functions are all considered as candidates for generating the malware signature. The remaining functions are divided into clusters according to their location in the file and the optimal cluster for generating the malware signature is determined. One or more of the functions in the optimal cluster is selected randomly, as the malware signature.


Find Patent Forward Citations

Loading…