EP2472425B1

System and method for detecting unknown malware

Abstract

This record has no abstract on file.

EP2472425B1, drawing sheet 1
Sheet 1 of 43

Term

5.1 yearsleft in the term

Expires 28 October 2031.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 15 independent, 0 dependent

  1. 1
    A computer-implemented method for detecting unknown malware, the method comprising:generating, by a hardware processor (15), one or more different object genes for a plurality of known clean objects and known malicious objects of a plurality of different file types, wherein an object gene is a data structure containing a plurality of information elements retrieved from an object and wherein different object genes contain different types of information elements characteristic of each of the plurality of different file types;forming, by the hardware processor (15), different combinations of malware analysis methods for analyzing the one or more different object genes of the plurality of known clean and malicious objects, wherein a combination of malware analysis methods includes at least two different malware analysis methods;determining for each combination of malware analysis methods a level XbB of successful malware detections of the known malicious objects, wherein B is the number of known malicious objects with respect to each of the plurality of different file types, and |Xb| is the number of known malicious objects identified by each combination of malware analysis methods asmalicious for each of the plurality of different file types ;determining for each combination of malware analysis methods a level XwW, of false positive detections of the known clean objects, wherein W is the number of known clean objects with respect to each of the plurality of different file types, and |Xw| is the number of known clean objects identified by each combination of malware analysis methods as malicious for each of the plurality of different file types;determining an effectiveness value k for each combination of malware analysis methods with respect to each of the plurality of different file types using the following equation: k={XbB-XwW,ifXbB-XwW≥0,0,otherwiseselecting, based on a comparison of the determined effectiveness values (k), a most effective combination of malware analysis methods for each of the plurality of different file types;selecting, based on the file type of an unknown object, the most effective combination of malware analysis methods, for analyzing the unknown object for presence of malware;generating, on the basis of the selected combination of malware analysis methods, corresponding object genes from the unknown object;andanalyzing each one of the generated object genes of the unknown object using the selected most effective combination of malware analysis methods to determine whether the unknown object is clean or malicious. Computerimplementiertes Verfahren zur Erfassung unbekannter Schadsoftware, wobei das Verfahren umfasst: Erzeugen eines oder mehrerer unterschiedlicher Objektgene für eine Vielzahl von bekannten sauberen Objekten und bekannten schädlichen Objekten einer Vielzahl unterschiedlicher Dateitypen durch einen Hardwareprozessor (15), wobei ein Objektgen eine Datenstruktur ist, die eine Vielzahl von aus einem Objekt abgerufenen Informationselementen enthält, und wobei unterschiedliche Objektgene unterschiedliche Typen von Informationselementen enthalten, die für jeden der Vielzahl unterschiedlicher Dateitypen charakteristisch sind;Bilden von unterschiedlichen Kombinationen von Schadsoftware-Analyseverfahren zum Analysieren des einen oder der mehreren unterschiedlichen Objektgene der Vielzahl von bekannten sauberen und schädlichen Objekten durch den Hardwareprozessor (15), wobei eine Kombination von Schadsoftware-Analyseverfahren wenigstens zwei unterschiedliche Schadsoftware-Analyseverfahren einschließt;Bestimmen eines Niveaus XbB erfolgreicher Schadsoftware-Erfassungen der bekannten schädlichen Objekte für jede Kombination von Schadsoftware-Analyseverfahren, wobei B die Anzahl bekannter schädlicher Objekte bezüglich jedes der Vielzahl unterschiedlicher Dateitypen ist, und |Xb| die Anzahl bekannter schädlicher Objekte ist, die durch jede Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen als schädlich identifiziert wurde;Bestimmen eines Niveaus XwW falscher positiver Erfassungen der bekannten sauberen Objekte für jede Kombination von Schadsoftware-Analyseverfahren, wobei W die Anzahl bekannter sauberer Objekte bezüglich jedes der Vielzahl unterschiedlicher Dateitypen ist, und |Xw| die Anzahl bekannter sauberer Objekte ist, die durch jede Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen als schädlich identifiziert wurde;Bestimmen eines Effektivitätswerts k für jede Kombination von Schadsoftware-Analyseverfahren bezüglich jedes der Vielzahl unterschiedlicher Dateitypen unter Verwendung der folgenden Gleichung: k={XbB-XwW,fallsXbB-XwW≥0,anderfalls0Auswählen, basierend auf einem Vergleich der bestimmten Effektivitätswerte (k), einer effektivsten Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen;Auswählen, basierend auf dem Dateityp eines unbekannten Objekts, der effektivsten Kombination von Schadsoftware-Analyseverfahren zum Analysieren des unbekannten Objekts hinsichtlich des Vorhandenseins von Schadsoftware;Erzeugen, auf der Basis der ausgewählten Kombination von Schadsoftware-Analyseverfahren, entsprechender Objektgene aus dem unbekannten Objekt;undAnalysieren jedes der erzeugten Objektgene des unbekannten Objekts unter Verwendung der ausgewählten effektivsten Kombination von Schadsoftware-Analyseverfahren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist. Procédé mis en oeuvre par ordinateur pour détecter un logiciel malveillant, le procédé consistant à : générer, par un processeur matériel (15), un ou plusieurs gènes d'objets différents pour une pluralité d'objets non infectés connus et d'objets malveillants connus d'une pluralité de différents types de fichiers, où un gène d'objet est une structure de données contenant une pluralité d'éléments d'informations extraits d'un objet et où différents gènes d'objets contiennent différents types d'éléments d'informations caractéristiques de chacun de la pluralité de différents types de fichiers;former, par le processeur matériel (15), différentes combinaisons de procédés d'analyses de logiciels malveillants, pour analyser l'un ou plusieurs des gènes d'objets différents de la pluralité d'objets connus, non infectés et malveillants, où une combinaison de procédés d'analyses de logiciels malveillants comprend au moins deux procédés différents d'analyses de logiciels malveillants;déterminer, pour chaque combinaison de procédés d'analyses de logiciels malveillants, un niveau XbB de détections - réussies - des objets malveillants connus concernant des logiciels malveillants, où B est le nombre d'objets malveillants connus par rapport à chacun de la pluralité des différents types de fichiers, et |Xb| est le nombre d'objets malveillants connus identifiés, par chaque combinaison de procédés d'analyses de logiciels malveillants, comme étant malveillants pour chacun de la pluralité des différents types de fichiers;déterminer, pour chaque combinaison de procédés d'analyses de logiciels malveillants, un niveau XwW de détections positives fausses des objets non infectés connus, où W est le nombre d'objets non infectés connus, par rapport à chacun de la pluralité des différents types de fichiers, et |Xw| est le nombre d'objets non infectés connus identifiés, par chaque combinaison de procédés d'analyses de logiciels malveillants, comme étant malveillants pour chacun de la pluralité des différents types de fichiers;déterminer une valeur d'efficacité k pour chaque combinaison de procédés d'analyses de logiciels malveillants, par rapport à chacun de la pluralité des différents types de fichiers, en utilisant l'équation suivante : k={XbB-XwW,siXbB-XwW≥0,autrement0sélectionner, en se basant sur une comparaison des valeurs d'efficacité déterminées (k), la plus efficace combinaison de procédés d'analyses de logiciels malveillants, pour chacun de la pluralité des différents types de fichiers;sélectionner, en se basant sur le type de fichiers d'un objet inconnu, la plus efficace combinaison de procédés d'analyses de logiciels malveillants, pour analyser l'objet inconnu afin de détecter la présence d'un logiciel malveillant;générer, sur la base de la combinaison sélectionnée de procédés d'analyses de logiciels malveillants, des gènes d'objets correspondants à partir de l'objet inconnu;etanalyser chacun des gènes d'objets générés de l'objet inconnu, en utilisant la plus efficace combinaison sélectionnée de procédés d'analyses de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant.
  2. 2
    Procédé selon la revendication 1, consistant en outre à :déterminer l'intensité de consommation de ressources de chaque procédé d'analyse sélectionné de logiciels malveillants;analyser l'un des gènes d'objets générés de l'objet inconnu, en utilisant initialement la consommation de ressources la moins intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant;etanalyser un ou plusieurs des autres gènes d'objets générés de l'objet inconnu, en utilisant la consommation de ressources la plus intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant, seulement quand la consommation de ressources la moins intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants ne réussit pas à déterminer si l'objet inconnu est non infecté ou malveillant. The method of claim 1, further comprising: determining resource-intensiveness of each selected malware analysis method;analyzing one of the generated object genes of the unknown object initially using the least resource intensive of the selected malware analysis methods to determine whether the unknown object is clean or malicious;andanalyzing one or more of the other generated object genes of the unknown object using more resource intensive of the selected malware analysis methods to determine whether the unknown object is clean or malicious only when the least resource-intensive of the selected malware analysis methods fails to determine if the unknown object is clean or malicious. Verfahren nach Anspruch 1, weiterhin umfassend: Bestimmen der Ressourcenintensivität jedes ausgewählten Schadsoftware-Analyseverfahrens;Analysieren eines der erzeugten Objektgene des unbekannten Objekts anfänglich unter Verwendung des am wenigsten ressourcenintensiven der ausgewählten Schadsoftware-Analyseverfahren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist;undAnalysieren eines oder mehrerer der anderen erzeugten Objektgene des unbekannten Objekts unter Verwendung von ressourcenintensiveren der ausgewählten Schadsoftware-Analyseverfahren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist, nur dann, wenn es der am wenigstens ressourcenintensiven der ausgewählten Schadsoftware-Analyseverfahren nicht gelingt, zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist.
  3. 3
    Procédé selon la revendication 1, dans lequel un gène d'objet pour chaque procédé d'analyse de logiciel malveillant est sélectionné parmi une des lignes uniques de code de l'objet inconnu, des zones opérationnelles de l'objet inconnu, un trajet d'exécution de l'objet inconnu, un type de comportement de l'objet inconnu, un organigramme de programmation de l'objet inconnu ou un graphe d'appel de fonction de l'objet inconnu. The method of claim 1, wherein an object gene for each malware analysis method is selected from one of unique lines of code of the unknown object, operational areas of the unknown object, execution path of the unknown object, behavior pattern of the unknown object, program flowchart of the unknown object, or function call graph of the unknown object. Verfahren nach Anspruch 1, wobei ein Objektgen für jedes Schadsoftware-Analyseverfahren aus einem von einzigartigen Code-Zeilen des unbekannten Objekts, Arbeitsbereichen des unbekannten Objekts, einem Ausführungspfad des unbekannten Objekts, einem Verhaltensmuster des unbekannten Objekts, einem Programmablaufplan des unbekannten Objekts oder einem Funktionsaufrufgraphen des unbekannten Objekts ausgewählt wird.
  4. 4
    Procédé selon la revendication 1, consistant en outre à sélectionner parmi une pluralité d'ordinateurs disponibles (20), l'ordinateur (20) le plus efficace pour analyser l'objet inconnu afin de détecter la présence d'un logiciel malveillant. The method of claim 1, further comprising selecting out of a plurality of available computers (20) a most efficient computer (20) for analyzing the unknown object for presence of malware. Verfahren nach Anspruch 1, das weiterhin umfasst, dass aus einer Vielzahl von verfügbaren Computern (20) ein effizientester Computer (20) für das Analysieren des unbekannten Objekts hinsichtlich des Vorhandenseins von Schadsoftware ausgewählt wird.
  5. 5
    Procédé selon la revendication 4, dans lequel l'ordinateur (20) le plus efficace est sélectionné en se basant sur un ou plusieurs des facteurs suivants :productivité des ordinateurs disponibles (20), accessibilité au réseau des ordinateurs disponibles (20) et l'intensité de consommation de ressources des procédés d'analyses sélectionnés de logiciels malveillants. The method of claim 4, wherein the most efficient computer (20) is selected based on one or more of the following factors: productivity of available computers (20), network accessibility of available computers (20) and resource-intensiveness of the selected malware analysis methods. Verfahren nach Anspruch 4, wobei der effizienteste Computer (20) basierend auf einem oder mehreren der folgenden Faktoren ausgewählt wird: einer Produktivität von verfügbaren Computern (20), einer Netzwerkzugriffsfähigkeit von verfügbaren Computern (20) und einer Ressourcenintensivität der ausgewählten Schadsoftware-Analyseverfahren.
  6. 6
    Procédé selon la revendication 1, dans lequel l'analyse d'un gène d'objet en utilisant les procédés d'analyses de logiciels malveillants comprend en outre une ou plusieurs des étapes consistant à :effectuer une analyse de type de comportement en comparant un gène de type de comportement de l'objet inconnu, à des types de comportement d'objets connus malveillants ou non infectés;effectuer une analyse de correspondance exacte d'un type d'éléments d'informations du gène d'objet, avec des types d'éléments d'informations associés à des objets connus malveillants ou non infectés;effectuer une correspondance en chaîne approximative des éléments d'informations du gène d'objet, avec des types d'éléments d'informations associés à des objets connus malveillants ou non infectés;effectuer une analyse d'estimation de sécurité des éléments d'informations du gène d'objet, en évaluant séparément la malveillance de blocs logiques séparés des éléments d'informations. The method of claim 1, wherein analyzing an object gene using the malware analysis methods further comprises one or more of: performing a behavior pattern analysis by comparing a behavior pattern gene of the unknown object with behavior patterns of known malicious or clean objects;performing an exact match analysis of a pattern of information elements of the object gene with patterns of information elements associated with known malicious or clean objects;performing an approximate string matching of the information elements of the object gene with patterns of information elements associated with known malicious or clean objects;performing a security rating analysis of the information elements of the object gene by separately evaluating maliciousness of separate logical blocks of the information elements. Verfahren nach Anspruch 1, wobei das Analysieren eines Objektgens unter Verwendung der Schadsoftware-Analyseverfahren weiterhin eines oder mehrere umfasst von: Durchführen einer Verhaltensmusteranalyse durch Vergleichen eines Verhaltensmustergens des unbekannten Objekts mit Verhaltensmustern von bekannten schädlichen oder sauberen Objekten;Durchführen einer Analyse hinsichtlich genauer Übereinstimmung eines Musters von Informationselementen des Objektgens mit Mustern von Informationselementen, die mit bekannten schädlichen oder sauberen Objekten assoziiert sind;Durchführen eines ungefähren String-Abgleichs der Informationselemente des Objektgens mit Mustern von Informationselementen, die mit bekannten schädlichen oder sauberen Objekten assoziiert sind;Durchführen einer Sicherheitseinstufungsanalyse der Informationselemente des Objektgens durch separate Evaluierung der Schädlichkeit von separaten logischen Blöcken der Informationselemente.
  7. 7
    A computer-based system (5, 500) for detecting unknown malware, the system (5, 500) comprising:a memory (20) configured to store an unknown software object;anda processor (15) coupled to the memory (20) and configured to: generate one or more different object genes for a plurality of known clean objects and known malicious objects of a plurality of different file types, wherein an object gene is a data structure containing a plurality of information elements retrieved from an object, and wherein different object genes contain different types of information elements characteristic of each of the plurality of different file types;form different combinations of malware analysis methods for analyzing the one or more different object genes of the plurality of known clean and malicious objects, wherein a combination of malware analysis methods includes at least two different malware analysis methods;determine for each combination of malware analysis methods a level XbB of successful malware detections of the known malicious objects, wherein B is the number of known malicious objects with respect to each of the plurality of different file types, and |Xb| is the number of known malicious objects identified by each combination of malware analysis method as malicious for each of the plurality of different file types;determine for each combination of malware analysis methods a level XwW, of false positive detections of known clean objects, wherein W is the number of known clean objects with respect to each of the plurality of different file types, and |Xw| is the number of known clean objects identified by each combination of malware analysis methods as malicious for each of the plurality of different file types;determine an effectiveness value k for each combination of malware analysis methods for each of the plurality of different file types using the following equation: k={XbB-XwW,ifXbB-XwW≥0,0,otherwiseselect, based on a comparison of the determined effectiveness values (k), a most effective combination of malware analysis methods for each of the plurality of different file types;select, based on the file type of an unknown object, the most effective combination of malware analysis methods, for analyzing the unknown object for presence of malware;generate, on the basis of the selected combination of malware analysis methods, corresponding object genes from the unknown object;andanalyze each one of the generated object genes of the unknown object using the selected most effective combination of malware analysis methods to determine whether the unknown object is clean or malicious. Computerbasiertes System (5, 500) zur Erfassung unbekannter Schadsoftware, wobei das System (5, 500) umfasst: einen Speicher (20), der dazu konfiguriert ist, ein unbekanntes Software-Objekt zu speichern;undeinen mit dem Speicher (20) verbundenen Prozessor (15), der dazu konfiguriert ist: für eine Vielzahl von bekannten sauberen Objekten und bekannten schädlichen Objekten einer Vielzahl unterschiedlicher Dateitypen eines oder mehrere unterschiedliche Objektgene zu erzeugen, wobei ein Objektgen eine Datenstruktur ist, die eine Vielzahl von aus einem Objekt abgerufenen Informationselementen enthält, und wobei unterschiedliche Objektgene unterschiedliche Typen von Informationselementen enthalten, die für jeden der Vielzahl unterschiedlicher Dateitypen charakteristisch sind;unterschiedliche Kombinationen von Schadsoftware-Analyseverfahren zum Analysieren des einen oder der mehreren unterschiedlichen Objektgene der Vielzahl von bekannten sauberen und schädlichen Objekten zu bilden, wobei eine Kombination von Schadsoftware-Analyseverfahren wenigstens zwei unterschiedliche Schadsoftware-Analyseverfahren einschließt;für jede Kombination von Schadsoftware-Analyseverfahren ein Niveau XbB erfolgreicher Schadsoftware-Erfassungen der bekannten schädlichen Objekte zu bestimmen, wobei B die Anzahl bekannter schädlicher Objekte bezüglich jedes der Vielzahl unterschiedlicher Dateitypen ist, und |Xb| die Anzahl bekannter schädlicher Objekte ist, die durch jede Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen als schädlich identifiziert wurde;für jede Kombination von Schadsoftware-Analyseverfahren ein Niveau XwW falscher positiver Erfassungen der bekannten sauberen Objekte zu bestimmen, wobei W die Anzahl bekannter sauberer Objekte bezüglich jedes der Vielzahl unterschiedlicher Dateitypen ist, und |Xw| die Anzahl bekannter sauberer Objekte ist, die durch jede Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen als schädlich identifiziert wurde;für jede Kombination von Schadsoftware-Analyseverfahren bezüglich jedes der Vielzahl unterschiedlicher Dateitypen unter Verwendung der folgenden Gleichung einen Effektivitätswert k zu bestimmen: k={XbB-XwW,fallsXbB-XwW≥0,anderfalls0basierend auf einem Vergleich der bestimmten Effektivitätswerte (k) eine effektivste Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen auszuwählen;basierend auf dem Dateityp eines unbekannten Objekts die effektivste Kombination von Schadsoftware-Analyseverfahren zum Analysieren des unbekannten Objekts hinsichtlich des Vorhandenseins von Schadsoftware auszuwählen;auf der Basis der ausgewählten Kombination von Schadsoftware-Analyseverfahren entsprechende Objektgene aus dem unbekannten Objekt zu erzeugen;undjedes der erzeugten Objektgene des unbekannten Objekts unter Verwendung der ausgewählten effektivsten Kombination von Schadsoftware-Analyseverfahren zu analysieren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist. Système géré par ordinateur (5, 500) pour détecter un logiciel malveillant inconnu, le système (5, 500) comprenant : une mémoire (20) configurée pour stocker un objet de logiciel inconnu;etun processeur (15) couplé à la mémoire (20) et configuré pour : générer un ou plusieurs gènes d'objets différents pour une pluralité d'objets non infectés connus et d'objets malveillants connus d'une pluralité de différents types de fichiers, où un gène d'objet est une structure de données contenant une pluralité d'éléments d'informations extraits d'un objet et où différents gènes d'objets contiennent différents types d'éléments d'informations caractéristiques de chacun de la pluralité de différents types de fichiers;former différentes combinaisons de procédés d'analyses de logiciels malveillants, pour analyser l'un ou plusieurs des gènes d'objets différents de la pluralité d'objets connus, non infectés et malveillants, où une combinaison de procédés d'analyses de logiciels malveillants comprend au moins deux procédés différents d'analyses de logiciels malveillants;déterminer, pour chaque combinaison de procédés d'analyses de logiciels malveillants, un niveau XbB de détections - réussies - des objets malveillants connus concernant des logiciels malveillants, où B est le nombre d'objets malveillants connus par rapport à chacun de la pluralité des différents types de fichiers, et |Xb| est le nombre d'objets malveillants connus identifiés, par chaque combinaison de procédés d'analyses de logiciels malveillants, comme étant malveillants pour chacun de la pluralité des différents types de fichiers;déterminer, pour chaque combinaison de procédés d'analyses de logiciels malveillants, un niveau XwW, de détections positives fausses des objets non infectés connus, où W est le nombre d'objets non infectés connus, par rapport à chacun de la pluralité des différents types de fichiers, et |Xw| est le nombre d'objets non infectés connus identifiés, par chaque combinaison de procédés d'analyses de logiciels malveillants, comme étant malveillants pour chacun de la pluralité des différents types de fichiers;déterminer une valeur d'efficacité k pour chaque combinaison de procédés d'analyses de logiciels malveillants, par rapport à chacun de la pluralité des différents types de fichiers, en utilisant l'équation suivante : k={XbB-XwW,siXbB-XwW≥0,autrement0sélectionner, en se basant sur une comparaison des valeurs d'efficacité déterminées (k), la plus efficace combinaison de procédés d'analyses de logiciels malveillants, pour chacun de la pluralité des différents types de fichiers;sélectionner, en se basant sur le type de fichier d'un objet inconnu, la plus efficace combinaison de procédés d'analyses de logiciels malveillants, pour analyser l'objet inconnu afin de détecter la présence d'un logiciel malveillant;générer, sur la base de la combinaison sélectionnée de procédés d'analyses de logiciels malveillants, des gènes d'objets correspondants à partir de l'objet inconnu;etanalyser chacun des gènes d'objets générés de l'objet inconnu, en utilisant la plus efficace combinaison sélectionnée de procédés d'analyses de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant.
  8. 8
    System (5, 500) nach Anspruch 7, wobei der Prozessor (15) weiterhin dazu konfiguriert ist:die Ressourcenintensivität jedes ausgewählten Schadsoftware-Analyseverfahrens zu bestimmen;eines der erzeugten Objektgene des unbekannten Objekts anfänglich unter Verwendung des am wenigsten ressourcenintensiven der ausgewählten Schadsoftware-Analyseverfahren zu analysieren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist;undeines oder mehrere der anderen erzeugten Objektgene des unbekannten Objekts unter Verwendung von ressourcenintensiveren der ausgewählten Schadsoftware-Analyseverfahren zu analysieren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist, nur dann, wenn es der am wenigstens ressourcenintensiven der ausgewählten Schadsoftware-Analyseverfahren nicht gelingt, zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist. Système (5, 500) selon la revendication 7, dans lequel le processeur (15) est configuré en outre pour : déterminer l'intensité de consommation de ressources de chaque procédé d'analyse sélectionné de logiciels malveillants;analyser l'un des gènes d'objets générés de l'objet inconnu, en utilisant initialement la consommation de ressources la moins intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant;etanalyser un ou plusieurs des autres gènes d'objets générés de l'objet inconnu, en utilisant la consommation de ressources la plus intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant, seulement quand la consommation de ressources la moins intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants ne réussit pas à déterminer si l'objet inconnu est non infecté ou malveillant. The system (5, 500) of claim 7, wherein the processor (15) is further configured to: determine resource-intensiveness of each selected malware analysis method;analyze one of the generated object genes of the unknown object initially using the least resource intensive of the selected malware analysis methods to determine whether the unknown object is clean or malicious;andanalyze one or more of the other generated object genes of the unknown object using more resource intensive of the selected malware analysis methods to determine whether the unknown object is clean or malicious only when the least resource-intensive of the selected malware analysis methods fails to determine if the unknown object is clean or malicious.
  9. 9
    System (5, 500) nach Anspruch 7, wobei der Prozessor (15) weiterhin dazu konfiguriert ist, aus einer Vielzahl von verfügbaren Computern (20) einen effizientesten Computer (20) für das Analysieren des unbekannten Objekts hinsichtlich des Vorhandenseins von Schadsoftware auszuwählen. Système (5, 500) selon la revendication 7, dans lequel le processeur (15) est configuré en outre pour sélectionner parmi une pluralité d'ordinateurs disponibles (20), l'ordinateur (20) le plus efficace pour analyser l'objet inconnu afin de détecter la présence d'un logiciel malveillant. The system (5, 500) of claim 7, wherein the processor (15) is further configured to select out of a plurality of available computers (20) a most efficient computer (20) for analyzing the unknown object for presence of malware
  10. 10
    System (5, 500) nach Anspruch 9, wobei der effizienteste Computer (20) basierend auf einem oder mehreren der folgenden Faktoren ausgewählt wird:einer Produktivität von verfügbaren Computern (20), einer Netzwerkzugriffsfähigkeit von verfügbaren Computern (20) und einer Ressourcenintensivität der ausgewählten Schadsoftware-Analyseverfahren. Système (5, 500) selon la revendication 9, dans lequel l'ordinateur (20) le plus efficace est sélectionné en se basant sur un ou plusieurs des facteurs suivants : productivité des ordinateurs disponibles (20), accessibilité au réseau des ordinateurs disponibles (20) et grosse consommation de ressources des procédés d'analyses sélectionnés de logiciels malveillants. The system (5, 500) of claim 9, wherein the most efficient computer (20) is selected based on one or more of the following factors: productivity of available computers (20), network accessibility of available computers (20) and resource-intensiveness of the selected malware analysis methods.
  11. 11
    System (5, 500) nach Anspruch 7, wobei ein Objektgen für jedes Schadsoftware-Analyseverfahren aus einem von einzigartigen Code-Zeilen des unbekannten Objekts, Arbeitsbereichen des unbekannten Objekts, einem Ausführungspfad des unbekannten Objekts, einem Verhaltensmuster des unbekannten Objekts, einem Programmablaufplan des unbekannten Objekts oder einem Funktionsaufrufgraphen des unbekannten Objekts ausgewählt wird. Système (5, 500) selon la revendication 7, dans lequel un gène d'objet pour chaque procédé d'analyse de logiciel malveillant est sélectionné parmi une des lignes uniques de code de l'objet inconnu, des zones opérationnelles de l'objet inconnu, un trajet d'exécution de l'objet inconnu, un type de comportement de l'objet inconnu, un organigramme de programmation de l'objet inconnu ou un graphe d'appel de fonction de l'objet inconnu. The system (5, 500) of claim 7, wherein an object gene for each malware analysis method is selected from one of unique lines of code of the unknown object, operational areas of the unknown object, execution path of the unknown object, behavior pattern of the unknown object, program flowchart of the unknown object, or function call graph of the unknown object.
  12. 12
    System (5, 500) nach Anspruch 7, wobei zum Analysieren eines Objektgens unter Verwendung der Schadsoftware-Analyseverfahren der Prozessor (15) weiterhin dazu konfiguriert ist, eines oder mehrere durchzuführen von:einer Verhaltensmusteranalyse durch Vergleichen eines Verhaltensmustergens des unbekannten Objekts mit Verhaltensmustern von bekannten schädlichen oder sauberen Objekten;einer Analyse hinsichtlich genauer Übereinstimmung eines Musters von Informationselementen des Objektgens mit Mustern von Informationselementen, die mit bekannten schädlichen oder sauberen Objekten assoziiert sind;eines ungefähren String-Abgleichs der Informationselemente des Objektgens mit Mustern von Informationselementen, die mit bekannten schädlichen oder sauberen Objekten assoziiert sind;undeiner Sicherheitseinstufungsanalyse der Informationselemente des Objektgens durch separate Evaluierung der Schädlichkeit von separaten logischen Blöcken der Informationselemente. Système (5, 500) selon la revendication 7, dans lequel, pour analyser un gène d'objet en utilisant les procédés d'analyses de logiciels malveillants, le processeur (15) est configuré en outre pour effectuer une ou plusieurs des tâches suivantes, à savoir : une analyse de type de comportement en comparant un gène de type de comportement de l'objet inconnu, à des types de comportement d'objets connus malveillants ou non infectés;une analyse de correspondance exacte d'un type d'éléments d'informations du gène d'objet, avec des types d'éléments d'informations associés à des objets connus malveillants ou non infectés;une correspondance en chaîne approximative des éléments d'informations du gène d'objet, avec des types d'éléments d'informations associés à des objets connus malveillants ou non infectés;etune analyse d'estimation de sécurité des éléments d'informations du gène d'objet, en évaluant séparément la malveillance de blocs logiques séparés des éléments d'informations. The system (5, 500) of claim 7, wherein to analyze an object gene using the malware analysis methods, the processor (15) is further configured to perform one or more of: a behavior pattern analysis by comparing a behavior pattern gene of the unknown object with behavior patterns of known malicious or clean objects;an exact match analysis of a pattern of information elements of the object gene with patterns of information elements associated with known malicious or clean objects;an approximate string matching of the information elements of the object gene with patterns of information elements associated with known malicious or clean objects;anda security rating analysis of the information elements of the object gene by separately evaluating maliciousness of separate logical blocks of the information elements.
  13. 13
    A computer program product embedded in a non-transitory computer-readable storage medium (25), the computer-readable storage medium (25) comprising computer-executable instructions for detecting unknown malware, wherein the medium comprises instructions for:generating one or more different object genes for a plurality of known clean objects and known malicious objects of a plurality of different file types, wherein an object gene is a data structure containing a plurality of information elements retrieved from an object, and wherein different object genes contain different types of information elements characteristic of each of the plurality of different file types;forming different combinations of malware analysis methods for analyzing the one or more different object genes of the plurality of known clean and malicious objects, wherein a combination of malware analysis methods includes at least two different malware analysis methods;determining for each combination of malware analysis methods a level XbB of successful malware detections of the known malicious objects, wherein B is the number of known malicious objects with respect to each of the plurality of different file types, and |Xb| is the number of known malicious objects identified by each combination of malware analysis method as malicious for the plurality of different file types;determining for each combination of malware analysis methods a level XwW, of false positive detections of the known clean objects, wherein W is the number of known clean objects with respect to each of the plurality of different file types, and |Xw| is the number of known clean objects identified by each combination of malware analysis methods as malicious for each of the plurality of different file types;determining an effectiveness value k for each combination of malware analysis methods with respect to each of the plurality of different file types using the following equation: k={XbB-XwW,ifXbB-XwW≥0,0,otherwiseselecting, based on a comparison of the determined effectiveness values k, a most effective combination of malware analysis methods for each of the plurality of different file types;selecting, based on the file type of an unknown object, the most effective combination of malware analysis methods, for analyzing the unknown object for presence of malware;generating, on the basis of the selected combination of malware analysis methods, corresponding object genes from the unknown object;andanalyzing each one of the generated object genes of the unknown object using the selected most effective combination of malware analysis methods to determine whether the unknown object is clean or malicious. Computerprogrammprodukt, das in ein nichtflüchtiges computerlesbares Speichermedium (25) eingebettet ist, wobei das computerlesbare Speichermedium (25) computerausführbare Instruktionen zur Erfassung unbekannter Schadsoftware umfasst, wobei das Medium Instruktionen umfasst zum: Erzeugen eines oder mehrerer unterschiedlicher Objektgene für eine Vielzahl von bekannten sauberen Objekten und bekannten schädlichen Objekten einer Vielzahl unterschiedlicher Dateitypen, wobei ein Objektgen eine Datenstruktur ist, die eine Vielzahl von aus einem Objekt abgerufenen Informationselementen enthält, und wobei unterschiedliche Objektgene unterschiedliche Typen von Informationselementen enthalten, die für jeden der Vielzahl unterschiedlicher Dateitypen charakteristisch sind;Bilden von unterschiedlichen Kombinationen von Schadsoftware-Analyseverfahren zum Analysieren des einen oder der mehreren unterschiedlichen Objektgene der Vielzahl von bekannten sauberen und schädlichen Objekten, wobei eine Kombination von Schadsoftware-Analyseverfahren wenigstens zwei unterschiedliche Schadsoftware-Analyseverfahren einschließt;Bestimmen eines Niveaus XbB erfolgreicher Schadsoftware-Erfassungen der bekannten schädlichen Objekte für jede Kombination von Schadsoftware-Analyseverfahren, wobei B die Anzahl bekannter schädlicher Objekte bezüglich jedes der Vielzahl unterschiedlicher Dateitypen ist, und |Xb| die Anzahl bekannter schädlicher Objekte ist, die durch jede Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen als schädlich identifiziert wurde;Bestimmen eines Niveaus XwW falscher positiver Erfassungen der bekannten sauberen Objekte für jede Kombination von Schadsoftware-Analyseverfahren, wobei W die Anzahl bekannter sauberer Objekte bezüglich jedes der Vielzahl unterschiedlicher Dateitypen ist, und |Xw| die Anzahl bekannter sauberer Objekte ist, die durch jede Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen als schädlich identifiziert wurde;Bestimmen eines Effektivitätswerts k für jede Kombination von Schadsoftware-Analyseverfahren bezüglich jedes der Vielzahl unterschiedlicher Dateitypen unter Verwendung der folgenden Gleichung: k={XbB-XwW,fallsXbB-XwW≥0,anderfalls0Auswählen, basierend auf einem Vergleich der bestimmten Effektivitätswerte (k), einer effektivsten Kombination von Schadsoftware-Analyseverfahren für jeden der Vielzahl unterschiedlicher Dateitypen;Auswählen, basierend auf dem Dateityp eines unbekannten Objekts, der effektivsten Kombination von Schadsoftware-Analyseverfahren zum Analysieren des unbekannten Objekts hinsichtlich des Vorhandenseins von Schadsoftware;Erzeugen, auf der Basis der ausgewählten Kombination von Schadsoftware-Analyseverfahren, entsprechender Objektgene aus dem unbekannten Objekt;undAnalysieren jedes der erzeugten Objektgene des unbekannten Objekts unter Verwendung der ausgewählten effektivsten Kombination von Schadsoftware-Analyseverfahren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist. Produit de programme informatique intégré à un support d'information non transitoire (25) pouvant être lu par l'ordinateur, le support d'information (25) pouvant être lu par l'ordinateur comprenant des instructions exécutables par l'ordinateur, pour détecter des logiciels malveillants inconnus, où le support comprend des instructions pour : générer un ou plusieurs gènes d'objets différents pour une pluralité d'objets non infectés connus et d'objets malveillants connus d'une pluralité de différents types de fichiers, où un gène d'objet est une structure de données contenant une pluralité d'éléments d'informations extraits d'un objet et où différents gènes d'objets contiennent différents types d'éléments d'informations caractéristiques de chacun de la pluralité de différents types de fichiers;former différentes combinaisons de procédés d'analyses de logiciels malveillants, pour analyser l'un ou plusieurs des gènes d'objets différents de la pluralité d'objets connus, non infectés et malveillants, où une combinaison de procédés d'analyses de logiciels malveillants comprend au moins deux procédés différents d'analyses de logiciels malveillants;déterminer, pour chaque combinaison de procédés d'analyses de logiciels malveillants, un niveau XbB de détections - réussies - des objets malveillants connus concernant des logiciels malveillants, où B est le nombre d'objets malveillants connus par rapport à chacun de la pluralité des différents types de fichiers, et |Xb| est le nombre d'objets malveillants connus identifiés, par chaque combinaison de procédés d'analyses de logiciels malveillants, comme étant malveillants pour chacun de la pluralité des différents types de fichiers;déterminer, pour chaque combinaison de procédés d'analyses de logiciels malveillants, un niveau XwW, de détections positives fausses des objets non infectés connus, où W est le nombre d'objets non infectés connus, par rapport à chacun de la pluralité des différents types de fichiers, et |Xw| est le nombre d'objets non infectés connus identifiés, par chaque combinaison de procédés d'analyses de logiciels malveillants, comme étant malveillants pour chacun de la pluralité des différents types de fichiers;déterminer une valeur d'efficacité k pour chaque combinaison de procédés d'analyses de logiciels malveillants, par rapport à chacun de la pluralité des différents types de fichiers, en utilisant l'équation suivante : k={XbB-XwW,siXbB-XwW≥0,autrement0sélectionner, en se basant sur une comparaison des valeurs d'efficacité déterminées k, la plus efficace combinaison de procédés d'analyses de logiciels malveillants, pour chacun de la pluralité des différents types de fichiers;sélectionner, en se basant sur le type de fichier d'un objet inconnu, la plus efficace combinaison de procédés d'analyses de logiciels malveillants, pour analyser l'objet inconnu afin de détecter la présence d'un logiciel malveillant;générer, sur la base de la combinaison sélectionnée de procédés d'analyses de logiciels malveillants, des gènes d'objets correspondants à partir de l'objet inconnu;etanalyser chacun des gènes d'objets générés de l'objet inconnu, en utilisant la plus efficace combinaison sélectionnée de procédés d'analyses de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant.
  14. 14
    Produit selon la revendication 13, comprenant en outre des instructions pour :déterminer l'intensité de consommation de ressources de chaque procédé d'analyse sélectionné de logiciels malveillants;analyser l'un des gènes d'objets générés de l'objet inconnu, en utilisant initialement la consommation de ressources la moins intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant;etanalyser un ou plusieurs des autres gènes d'objets générés de l'objet inconnu, en utilisant la consommation de ressources la plus intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants, pour déterminer si l'objet inconnu est non infecté ou malveillant, seulement quand la consommation de ressources la moins intensive parmi les procédés d'analyses sélectionnés de logiciels malveillants ne réussit pas à déterminer si l'objet inconnu est non infecté ou malveillant. Produkt nach Anspruch 13, das weiterhin Instruktionen umfasst zum: Bestimmen der Ressourcenintensivität jedes ausgewählten Schadsoftware-Analyseverfahrens;Analysieren eines der erzeugten Objektgene des unbekannten Objekts anfänglich unter Verwendung des am wenigsten ressourcenintensiven der ausgewählten Schadsoftware-Analyseverfahren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist;undAnalysieren eines oder mehrerer der anderen erzeugten Objektgene des unbekannten Objekts unter Verwendung von ressourcenintensiveren der ausgewählten Schadsoftware-Analyseverfahren, um zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist, nur dann, wenn es der am wenigstens ressourcenintensiven der ausgewählten Schadsoftware-Analyseverfahren nicht gelingt, zu bestimmen, ob das unbekannte Objekt sauber oder schädlich ist. The product of claim 13, further comprising instructions for: determining resource-intensiveness of each selected malware analysis method;analyzing one of the generated object genes of the unknown object initially using the least resource intensive of the selected malware analysis methods to determine whether the unknown object is clean or malicious;andanalyzing one or more of the other generated object genes of the unknown object using more resource intensive of the selected malware analysis methods to determine whether the unknown object is clean or malicious only when the least resource-intensive of the selected malware analysis methods fails to determine if the unknown object is clean or malicious.
  15. 15
    Produit selon la revendication 13, dans lequel un gène d'objet pour chaque procédé d'analyse de logiciel malveillant est sélectionné parmi une des lignes uniques de code de l'objet inconnu, des zones opérationnelles de l'objet inconnu, un trajet d'exécution de l'objet inconnu, un type de comportement de l'objet inconnu, un organigramme de programmation de l'objet inconnu ou un graphe d'appel de fonction de l'objet inconnu. Produkt nach Anspruch 13, wobei ein Objektgen für jedes Schadsoftware-Analyseverfahren aus einem von einzigartigen Code-Zeilen des unbekannten Objekts, Arbeitsbereichen des unbekannten Objekts, einem Ausführungspfad des unbekannten Objekts, einem Verhaltensmuster des unbekannten Objekts, einem Programmablaufplan des unbekannten Objekts oder einem Funktionsaufrufgraphen des unbekannten Objekts ausgewählt wird. The product of claim 13, wherein an object gene for each malware analysis method is selected from one of unique lines of code of the unknown object, operational areas of the unknown object, execution path of the unknown object, behavior pattern of the unknown object, program flowchart of the unknown object, or function call graph of the unknown object.
Independent claims15