Nova Patents
WO2012107255A1

Detecting a trojan horse

Abstract

A method and apparatus for detected a Trojan in a suspicious software application in the form of at least one electronic file. A computer device determines the source from which the suspicious software application was obtained. A comparison is then made between the source from which the suspicious software application was obtained and a source from which an original, clean version of the software application was obtained. If the sources differ, then it is determined that the suspicious application is more likely to contain a Trojan horse than if the sources were the same.

WO2012107255A1, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 12 independent, 8 dependent

  1. 1
    CLAIMS:1 . A method of detected a Trojan in a suspicious software application in the form of at least one electronic file, the method comprising: at a computer device, determining the source from which the suspicious software application was obtained;comparing the source from which the suspicious software application was obtained with a source from which an original, clean version of the software application was obtained;and in the event that the sources differ, determining that the suspicious application is likely to contain a Trojan horse.
  2. 4
    The method according to any of claims 1 , 2 or 3, wherein the source from which the original, clean version of the software application was obtained and further metadata relating to the clean version of the software application is stored at a database.
  3. 5
    The method according to any of claims 1 to 4, further comprising sending a message from a computer device to a remote server, the message including any of the suspicious application and metadata relating to the suspicious application such that the server can perform the comparison.
  4. 7
    The method according to any of claims 1 to 6, further comprising, at the device, sending a message to a remote database, the message including at least an identity of the suspicious software application;and receiving from the remote database a response, the response including the source from which the original, clean version of the software application was obtained.
  5. 8
    A device for use in a communication network, the device comprising:a processor for determining that a software application in the form of at least one electronic file is suspicious;the processor being further arranged to determine the source of the software application;the processor being further arranged to compare the source from which the suspicious software application was obtained with a source from which an original, clean version of the software application was obtained and, in the event that the sources differ, determine that the suspicious application is likely to contain a Trojan horse.
  6. 10
    The device according to any of claims 8 or 9, wherein the processor is further arranged to make a comparison between the suspicious version of the software application and the clean version of the software application of any of the version numbers, version histories, application classes, size of code blocks, imported Application Programming Interfaces, Application Programming Interface functions called, file size of components of the software application, and capabilities and access controls indicating the functions that the application wishes to be able to access.
  7. 11
    1 1 . The device according to any of claims 8 to 10, further comprising a database for storing data relating to the source from which the original, clean version of the software application was obtained and further metadata relating to the clean version of the software application.
  8. 12
    A device for use in a communication network, the device comprising:a processor for determining that a software application in the form of at least one electronic file is suspicious;a transmitter for sending a request message to a remote server, the request message including at least an identity of the source from which the suspicious software application was obtained;a receiver for receiving a response from the server, the response including an indication of whether the software application is likely to contain a Trojan horse, the likelihood having been determined at least by the server comparing the source from which the suspicious software application was obtained with an original, clean version of the software application was obtained and, in the event that the sources differ, determining that the suspicious application is likely to contain a Trojan horse.
  9. 13
    A server for use in a communication network, the server comprising:a receiver for receiving from a remote device a request message, the request message including at least an identify of a source from which a suspicious software application in the form of at least one electronic file has been obtained;a processor for comparing the source from which the suspicious software application was obtained with a source from which an original, clean version of the software application was obtained and, in the event that the sources differ, determining that the suspicious application is likely to contain a Trojan horse;a transmitter for sending a response message, the response message including one of the result of the comparison and an indication that the software application is likely to contain a Trojan.
  10. 15
    The server according to any of claims 13 or 14, wherein the sources comprise an identity of a vendor.
  11. 16
    The server according to any of claims 13 to 15, wherein the processor is further arranged to make a comparison between the suspicious version of the software application and the clean version of the software application of any of the version numbers, version histories, application classes, size of code blocks, imported Application Programming Interfaces, Application Programming Interface functions called, file size of components of the software application, and capabilities and access controls indicating the functions that the application wishes to be able to access.
  12. 17
    A computer program, comprising computer readable code which, when run on a device, causes the device to behave as a device as claimed in any of claims 8 to 12.