IP Library Granted Patent US 8,069,484
Granted Patent B2
US 8,069,484 · App. 11/657,541 · Granted Nov 29, 2011

System and method for determining data entropy to identify malware

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,069,484
App. No.
11/657,541
Granted
Nov 29, 2011
Kind
B2
Abstract

Systems and methods for performing malware detection for determining suspicious data based on data entropy are provided. The method includes acquiring a block of data, calculating an entropy value for the block of data, comparing the entropy value to a threshold value, and recording the block of data as suspicious when the entropy value exceeds the threshold value. An administrator may then investigate suspicious data.

Claims (30)

1. A malware detection method, the method comprising the steps of:

calculating a global entropy value for a block of data, said block of data comprising a plurality of data samples;

iteratively calculating an individual sample entropy value for each of the plurality of data samples to create a plurality of individual sample entropy values, wherein each of the plurality of data samples contains at least a portion of data overlapping at least one of an immediately preceding data sample and an immediately subsequent data sample;

performing a statistical method on the plurality of individual sample entropy values;

comparing at least one of the global entropy value and an individual sample entropy value to a threshold value; and

recording the block of data as suspicious when at least one of the global entropy value and an individual sample entropy value exceeds the threshold value.

2. The method of claim 1 , further comprising reporting suspicious data to an administrator.

3. The method of claim 1 , wherein calculating an entropy value includes calculating Shannon Entropy for the block of data.

4. The method of claim 1 , wherein performing a statistical method includes:

calculating the mean and standard deviation of the plurality of individual sample entropy values; and

adding one standard deviation to the mean.

5. The method of claim, 1 wherein comparing the entropy value to a threshold value includes comparing both the global entropy value and the sample entropy value to the threshold.

6. The method of claim 1 , wherein the portion of data overlapping at least one of the immediately preceding data sample and the immediately subsequent data sample is tunable.

7. The method of claim 1 , further comprising examining metadata for the block of data for suspicious features, wherein said metadata comprises at least one of file type, type of different sections contained in a file, and permissions associated with individual sections within a file.

8. The method of claim 1 , wherein the threshold is 0.9.

9. A computer-readable device having computer-executable instructions for performing a method of malware, the method comprising the steps of:

calculating a global entropy value for a block of data, said block of data comprising a plurality of data samples;

iteratively calculating an individual sample entropy value for each of the plurality of data samples to create a plurality of individual sample entropy values, wherein each of the plurality of data samples contains at least a portion of data overlapping at least one of an immediately preceding data sample and an immediately subsequent data sample;

performing a statistical method on the plurality of individual sample entropy values;

comparing at least one of the global entropy value and an individual sample entropy value to a threshold value; and

recording the block of data as suspicious when at least one of the global entropy value and an individual sample entropy value exceeds the threshold value.

10. The computer-readable device of claim 9 , the method further comprising reporting suspicious packets to an administrator.

11. The computer-readable device of claim 9 , wherein calculating an entropy value includes calculating Shannon Entropy for the block of data.

12. The computer-readable device of claim 9 , wherein performing a statistical method includes:

calculating the mean and standard deviation of the plurality of individual sample entropy values; and

adding one standard deviation to the mean.

13. The computer-readable device of claim 9 , wherein comparing the entropy value to a threshold value includes comparing both the global entropy value and the sample entropy value to the threshold.

14. The computer-readable device of claim 9 , wherein the portion of data overlapping at least one of the immediately preceding data sample and the immediately subsequent data sample is tunable.

15. The computer-readable device of claim 9 , the method further comprising examining metadata for the block of data for suspicious features, wherein said metadata comprises at least one of file type, type of different sections contained in a file, and permissions associated with individual sections within a file.

16. The computer-readable device of claim 9 , wherein the threshold is 0.9.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063272/0743 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0029 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 018843 FRAME: 0960. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 19, 2021
From: MCMILLAN, CHAD; GARMAN, JASON
To: MANDIANT CORPORATION
Reel/Frame 056296/0504 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2016
From: MANDIANT, LLC
To: FIREEYE, INC.
Reel/Frame 038562/0860 →
CHANGE OF NAME Recorded Mar 5, 2014
From: MERCURY MERGER LLC
To: MANDIANT, LLC
Reel/Frame 032351/0340 →
MERGER Recorded Mar 4, 2014
From: MANDIANT CORPORATION
To: MERCURY MERGER LLC
Reel/Frame 032342/0806 →