IP Library Patent Application 13072114
Patent Application
App. No. 13/072,114

DETECTION OF GLOBAL METAMORPHIC MALWARE VARIANTS USING CONTROL AND DATA FLOW ANALYSIS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/072,114
Abstract

Malware feature extraction derives semantic summaries of executable malware using global, inter-procedural program analysis techniques. A combination of global, inter-procedural program analysis techniques constructs semantic summaries of malware which automatically detect and discard any noise introduced by transformations and capture the essence of the underlying computations in a succinct form. This is achieved in two ways. First, global control flow analysis techniques are used to derive a high level representation of malware code that, for instance, removes the effects of subroutine calls. Second, global data flow analysis techniques are employed to detect and remove all spurious elements of malware that do not contribute towards its underlying computation, thereby preventing the resulting summaries from being “corrupted” with unnecessary, extraneous elements.

Claims (8)

1 . A method of deriving malware signatures comprising:

applying global control flow analysis to code containing malware to provide a high level representation of malware code;

applying global data flow analysis to code containing malware to detect and remove spurious elements of malware to provide malware-free code; and

combining the high level representation and malware-free code outputs.

2 . The method as set forth in claim 1 , wherein said combining comprises projecting the representation over the malware-free code thereby creating a high level semantic summary.

3 . The method as set forth claim 1 , wherein said control flow analysis partitions statements in malware code into super blocks.

4 . The method as set forth in claim 1 , further comprising arranging said partitions into a super block dominator tree

5 . The method as set forth in claim 1 , wherein said data flow analysis creates a program slice from a program dependence graph.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS (REEL 030747 FRAME 0733) Recorded May 23, 2014
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: TT GOVERNMENT SOLUTIONS, INC.
Reel/Frame 033013/0163 →
SECURITY AGREEMENT Recorded Jul 3, 2013
From: TT GOVERNMENT SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 030747/0733 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2013
From: TELCORDIA TECHNOLOGIES, INC.
To: TT GOVERNMENT SOLUTIONS, INC.
Reel/Frame 030534/0134 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2011
From: AGRAWAL, HIRA
To: TELCORDIA TECHNOLOGIES, INC.
Reel/Frame 027197/0345 →