METHOD AND SYSTEM FOR GENERATING MALWARE DEFINITIONS USING A COMPARISON OF NORMALIZED ASSEMBLY CODE

Number of patents in Portfolio can not be more than 2000

United States of America Patent

APP PUB NO 20090313700A1
SERIAL NO

12137230

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

A system and method for generating malware definitions for use in managing malware on a computer is described. One embodiment comprises receipt of a binary file running in system memory; taking a memory dump of the binary file at a time slice and storing the memory dump in a memory dump file; applying a normalization process to the memory dump file, wherein the normalization process alters a collection of data from the memory dump file, resulting in a normalized file; applying a comparison process between the normalized file and each of a plurality of normalized files stored in a database of malware definitions wherein the comparison process produces a comparison value associated with each of the normalized files in the database of malware definitions; and inserting the normalized file into the database of malware definitions, when each of the comparison values satisfies a predetermined criterion.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
WEBROOT SOFTWARE INC2560 55TH STREET BOULDER CO 80301

International Classification(s)

  • [Classification Symbol]
  • [Patents Count]

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Horne, Jefferson Erie , US 1 23

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation