IP Library Granted Patent US 7,624,449
Granted Patent B1
US 7,624,449 · App. 10/763,673 · Granted Nov 24, 2009

Countering polymorphic malicious computer code through code optimization

Assignee: Symantec Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,624,449
App. No.
10/763,673
Granted
Nov 24, 2009
Kind
B1
Abstract

Methods, apparati, and computer-readable media for determining whether computer code ( 30 ) contains malicious code. In a method embodiment, the computer code ( 30 ) is optimized ( 40 ) to produce optimized code; and the optimized code is subject to a malicious code detection protocol. In an embodiment, the optimizing ( 40 ) comprises at least one of constant folding ( 53 ), copy propagation ( 54 ), non-obvious dead code elimination ( 62,63 ), code motion ( 49 ), peephole optimization ( 52 ), abstract interpretation ( 59,68 ), instruction specialization ( 55 ), and control flow graph reduction ( 44 ).

Claims (53)

1. A computer-implemented method for determining whether computer code contains malicious code, said method comprising the steps of:

identifying computer code having a decryption loop and a body;

performing a dead code elimination procedure on the computer code;

noting an amount of dead code eliminated during the dead code elimination procedure;

responsive to the amount of dead code eliminated during the dead code elimination procedure exceeding a preselected dead code threshold, declaring a suspicion of malicious code in the computer code;

optimizing the decryption loop to produce optimized loop code;

performing a malicious code detection procedure on the optimized loop code; and

responsive to the malicious code detection procedure detecting malicious code in the optimized loop code declaring that the computer code contains malicious code.

2. The method of claim 1 wherein optimizing the decryption loop comprises performing at least one technique from the group of techniques consisting of constant folding, copy propagation, non-obvious dead code elimination, code motion, peephole optimization, abstract interpretation, instruction specialization, and control flow graph reduction.

3. The method of claim 2 wherein at least two of said techniques are combined synergistically.

4. The method of claim 1 wherein the malicious code detection procedure is a procedure from the group of procedures consisting of pattern matching, emulation, checksumming, heuristics, tracing, and algorithmic scanning.

5. The method of claim 1 , further comprising:

optimizing a body of the computer code to produce optimized body code;

subjecting the optimized body code to a malicious code detection protocol; and

responsive to the malicious code detection protocol detecting malicious code in the optimized body code, declaring that the computer code contains malicious code.

6. The method of claim 5 wherein the malicious code detection protocol is a protocol from the group of protocols consisting of pattern matching, emulation, checksumming, heuristics, tracing, X-raying, and algorithmic scanning.

7. The method of claim 5 wherein the step of optimizing the body comprises using at least one output from the group of steps consisting of optimizing the decryption loop and performing a malicious code detection procedure on the optimized loop code.

8. The method of claim 5 wherein, when the step of performing a malicious code detection procedure on the optimized loop code indicates the presence of malicious code in the computer code, the steps of optimizing the body and subjecting the optimized body code to a malicious code detection protocol are aborted.

9. The method of claim 1 further comprising the additional step of, after the step of performing a malicious code detection procedure on the optimized loop code, revealing an encrypted body.

10. The method of claim 9 wherein the step of revealing an encrypted body comprises emulating the optimized loop code.

11. The method of claim 9 wherein the step of revealing an encrypted body comprises applying a key gleaned from the optimized loop code.

12. The method of claim 1 , wherein optimizing the decryption loop to produce optimized loop code comprises:

performing a forward pass operation;

performing a backward pass operation;

performing a control flow graph reduction; and

iterating the above three steps a plurality of times.

13. The method of claim 12 wherein the iteration of the three steps stops after either:

a preselected number of iterations; or

observing that no optimizations of the computer code were performed in the most recent iteration.

14. The method of claim 12 further comprising the step of performing a code motion procedure, wherein the four steps are iterated a plurality of times.

15. The method of claim 12 wherein the forward pass operation comprises one or more steps from the set consisting of:

peephole optimization;

constant folding;

copy propagation;

forward computations related to abstract interpretation; and

instruction specialization.

16. The method of claim 12 wherein the backward pass operation comprises one or more steps from the set consisting of backward computations related to abstract interpretation and local dead code elimination.

17. The method of claim 16 wherein the backward pass operation comprises the additional step of global dead code elimination.

18. The method of claim 1 wherein the malicious code detection procedure comprises emulating the optimized loop code.

19. A computer-readable storage medium containing executable computer program instructions for determining whether computer code contains malicious code, said computer program instructions performing the steps of:

identifying computer code having a decryption loop and a body;

performing a dead code elimination procedure on the computer code;

noting an amount of dead code eliminated during the dead code elimination procedure;

responsive to the amount of dead code eliminated during the dead code elimination procedure exceeding a preselected dead code threshold, declaring a suspicion of malicious code in the computer code;

optimizing the decryption loop to produce optimized loop code;

performing a malicious code detection procedure on the optimized loop code; and

responsive to the malicious code detection procedure detecting malicious code in the optimized loop code declaring that the computer code contains malicious code.

20. The computer-readable medium of claim 19 wherein the malicious code detection procedure is a procedure from the group of procedures consisting of pattern matching, emulation, checksumming, heuristics, tracing, X-raying, and algorithmic scanning.

21. The computer-readable medium of claim 19 wherein optimizing the decryption loop comprises performing at least one technique from the group of techniques consisting of constant folding, copy propagation, non-obvious dead code elimination, code motion, peephole optimization, abstract interpretation, instruction specialization, and control flow graph reduction.

22. The computer-readable medium of claim 19 , wherein the computer program instructions are for further performing the steps of:

optimizing a body of the computer code to produce optimized body code;

subjecting the optimized body code to a malicious code detection protocol; and

responsive to the malicious code detection protocol detecting malicious code in the optimized body code, declaring that the computer code contains malicious code.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2004
From: PERRIOT, FREDRERIC
To: SYMANTEC CORPORATION
Reel/Frame 014929/0103 →