IP Library Granted Patent US 9,542,555
Granted Patent B2
US 9,542,555 · App. 14/685,391 · Granted Jan 10, 2017

Malware detection system and method for compressed data on mobile platforms

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,542,555
App. No.
14/685,391
Granted
Jan 10, 2017
Kind
B2
Abstract

A system and method for detecting malware in compressed data. The system and method identifies a set of search strings extracted from compressed executables, each of which is infected with malware from a family of malware. The search strings detect the presence of the family of malware in other compressed executables, fragments of compressed executables, or data streams.

Claims (26)

1. A computing device for developing search strings for detecting malware in compressed data, the device comprising:

a non-transitory memory having stored thereon a plurality of malware-infected executables infected with a family of malware, wherein each of the plurality of malware-infected executables comprises a respective compressed code portion; and

a hardware-based processor configured to:

extract a plurality of candidate strings from the compressed code portions of the plurality of malware-infected executables;

identify at least one of the plurality of candidate strings that is present in each of the plurality of malware-infected executables as a search string common to the compressed code portions of the plurality of malware-infected executables; and

store the search string common to the plurality of malware-infected executables to a mobile device to cause the mobile device to determine whether target applications including compressed code portions are infected with malware based at least in part on the search string.

2. The computing device of claim 1 , wherein the hardware-based processor is configured to extract candidate strings from uncompressed header portions of the plurality of malware-infected executables.

3. The computing device of claim 1 , wherein the candidate strings are extracted from non-ASCII portions of the compressed code portions of the plurality of malware-infected executables.

4. The computing device of claim 1 , wherein the hardware-based processor is configured to identify a plurality of search strings common to the compressed code portions of the plurality of malware-infected executables from the plurality of candidate strings.

5. The computing device of claim 1 , wherein to searching is performed using an algorithm selected from the group consisting of: a greedy algorithm, a heuristic algorithm, an evolutionary algorithm, and dynamic programming.

6. The computing device of claim 1 , wherein the hardware-based processor is configured to:

receive a target executable with the search string present in the target executable;

incorporate the target executable into the plurality of malware-infected executables;

re-execute the identifying to develop one or more improved search strings; and,

distribute the improved search strings to the mobile device.

7. The computing device of claim 6 , wherein the hardware-based processor distributes the improved search strings using a device independent secure management protocol.

8. A mobile device for detecting malware in compressed data, the mobile device comprising:

a non-transitory memory configured to store a search string common to compressed code portions of a plurality of malware-infected executables, wherein each of the malware-infected executables is infected with a family of malware; and

a hardware-based processor configured to:

scan a compressed code portion of a target executable for the search string to detect whether the search string is present in the compressed code portion of the target executable, and

determine that the target executable is infected with malware from the family of malware when the search string is detected in the compressed code portion of the target executable.

9. The mobile device of claim 8 , wherein the hardware-based processor is further configured to:

obtain a second, different search string extracted from uncompressed header portions of the malware-infected executables; and

scan an uncompressed header of the target executable for the second search string.

10. The mobile device of claim 8 , wherein the hardware-based processor is further configured to report the target executable to an operational support system after determining that the search string is present in the compressed code portion of the target executable.

11. The mobile device of claim 8 , wherein the mobile device is selected from a group consisting of: a mobile telephone, a smart phone, a mobile computing device, a smart handheld device, and a network element.

Assignments (11)
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 053269/0339 →
SECURITY INTEREST Recorded May 1, 2017
From: PULSE SECURE, LLC
To: JUNIPER NETWORKS, INC.
Reel/Frame 042197/0822 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →