EP2472425A2

System and method for detecting unknown malware

Abstract

Disclosed are systems, methods and computer program products for detecting unknown malware. A method comprises generating genes for known malicious and clean objects; analyzing object genes using different malware analysis methods; computing a level of successful detection of malicious objects by one or a combination of malware analysis methods based on analysis of genes of the known malicious objects; computing a level of false positive detections of malicious objects by one or a combination of malware analysis methods based on analysis of genes of known clean objects; measuring effectiveness of each one or the combination of malware analysis methods as a function of the level of successful detections and the level of false positive detections; and selecting one or a combination of the most effective malware analysis methods for analyzing unknown object for malware.

EP2472425A2, drawing sheet 1
Sheet 1 of 17

Term

5.1 yearsto projected expiry

Projected expiry 28 October 2031, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

14 claims: 2 independent, 12 dependent

  1. 1
    A method for detecting unknown malware, the method comprising:generating at least one object gene for each one of a plurality of known malicious and clean objects, wherein an object gene is a data structure containing a plurality of information elements retrieved from or associated with an object;analyzing each object gene using one or more malware analysis methods;computing a level of successful detection of malicious objects by one or a combination of two or more malware analysis methods based on analysis of genes of the known malicious objects by said methods;computing a level of false positive detections of malicious objects by one or a combination of two or more malware analysis methods based on analysis of genes of known clean objects by said methods;measuring effectiveness of each one or the combination of malware analysis methods as a function of the level of successful detections of the known malicious objects and the level of false positive detections of the known clean objects;and selecting one or a combination of the most effective malware analysis methods for analyzing an unknown object for presence of malware.
  2. 8
    A system for detecting unknown malware, the system comprising:a memory configured to store a plurality of known malicious and clean objects;a processor coupled to the memory and configured to: generate at least one object gene for each one of a plurality of known malicious and clean objects, wherein an object gene is a data structure containing a plurality of information elements retrieved from or associated with an object;analyze each object gene using one or more malware analysis methods;compute a level of successful detection of malicious objects by one or a combination of two or more malware analysis methods based on analysis of genes of the known malicious objects by said methods;compute a level of false positive detections of malicious objects by one or a combination of two or more malware analysis methods based on analysis of genes of known clean objects by said methods;measure effectiveness of each one or the combination of malware analysis methods as a function of the level of successful detections of the known malicious objects and the level of false positive detections of the known clean objects;and select one or a combination of the most effective malware analysis methods for analyzing an unknown object for presence of malware.