IL237347A

Systems and methods for behavior-based automated malware analysis and classification

Abstract

This record has no abstract on file.

IL237347A, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

23 claims: 2 independent, 21 dependent

  1. 1
    CLAIMS:1. A method of identifying malware, comprising: accessing a set of samples, the set of samples comprising samples of different types of malware;running the set of samples on one or more computer systems;extracting, based on running the set of samples, a set of artifacts from the set of samples, wherein the set of artifacts includes information associated with a registry or a memory;determining a set of features from the set of artifacts for at least one sample in the set of samples;selecting one of a set of algorithms based on one or more selection features or parameters;analyzing the set of features using the one of the set of algorithms;and identifying, based at least partially on analyzing the set of features, malware in the set of samples by at least one of classifying or clustering samples in the set of samples into the different types of malware.
  2. 14
    A malware analysis system, comprising:an interface to a data store storing a set of samples of malware, the set of samples comprising samples of different types of malware;and a processor, communicating with the data store via the interface, the processor being configured to: access the set of samples, run the set of samples on one or more computer systems, 02336990\55-01 V2-amended 04.02.2018 -28extract, based on running the set of samples, a set of artifacts from the set of samples wherein the set of artifacts includes information associated with a registry or a memory, determine a set of features from the set of artifacts for at least one sample in the set of samples, select one of a set of algorithms based on one or more selection features or parameters, analyze the set of features using the one of the set of algorithms, and identify, based at least partially on analyzing the set of features, malware in the set of samples by at least one of classifying or clustering samples in the set of samples into the different types of malware.