IP Library › Granted Patent US 12,732,484
Granted Patent B2
US 12,732,484 · App. 18/807,767 · Granted Sep 8, 2026

Automated fuzzy hash based signature collecting system for malware detection

Inventors: Yang Ji (San Jose, CA); Wenjun Hu (Santa Clara, CA); Xiao Zhang (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0263H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,484
App. No.
18/807,767
Granted
Sep 8, 2026
Kind
B2
Abstract

Automated fuzzy hash based signature collection is disclosed. A set of candidate fuzzy hashes corresponding to a set of false negative samples is received. A false positive reduction analysis is performed on the received set of candidate fuzzy hashes to generate a reduced set of fuzzy hashes. At least a portion of the reduced set of fuzzy hashes is clustered into a fuzzy hash cluster. A signature for a family of malware is generated based at least in part on the fuzzy hash cluster.

Claims (20)

1 . A system, comprising: a processor configured to: receive a set of candidate fuzzy hashes corresponding to a set of false negative samples; perform a false positive reduction analysis on the received set of candidate fuzzy hashes to generate a reduced set of fuzzy hashes; cluster, at least a portion of the reduced set of fuzzy hashes into a fuzzy hash cluster, wherein as part of the clustering a set of previously identified false negative samples is also evaluated; and generate a signature for a family of malware based at least in part on the fuzzy hash cluster; and a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the processor is further configured to filter out at least one fuzzy hash cluster based at least in part on a similarity match with an existing signature.

3 . The system of claim 1 , wherein performing the false positive reduction analysis includes performing a pairwise comparison between a candidate fuzzy hash included in the set of candidate fuzzy hashes and a fuzzy hash of a known benign sample.

4 . The system of claim 1 , wherein performing the false positive reduction analysis includes removing from consideration a fuzzy hash of a sample that is an infections virus.

5 . The system of claim 1 , wherein generating the signature includes selecting a representative fuzzy hash from the fuzzy hash cluster.

6 . The system of claim 1 , wherein generating the signature includes comparing the signature against a store of existing signatures.

7 . The system of claim 1 , wherein the generated signature is usable by a data appliance to determine whether a file is malicious.

8 . The system of claim 1 , wherein the processor is further configured to use the generated signature to detect a new malware family.

9 . A method, comprising: receiving a set of candidate fuzzy hashes corresponding to a set of false negative samples; performing a false positive reduction analysis on the received set of candidate fuzzy hashes to generate a reduced set of fuzzy hashes; clustering, at least a portion of the reduced set of fuzzy hashes into a fuzzy hash cluster, wherein as part of the clustering a set of previously identified false negative samples is also evaluated; and generating a signature for a family of malware based at least in part on the fuzzy hash cluster.

10 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for: receiving a set of candidate fuzzy hashes corresponding to a set of false negative samples; performing a false positive reduction analysis on the received set of candidate fuzzy hashes to generate a reduced set of fuzzy hashes; clustering, at least a portion of the reduced set of fuzzy hashes into a fuzzy hash cluster, wherein as part of the clustering a set of previously identified false negative samples is also evaluated; and generating a signature for a family of malware based at least in part on the fuzzy hash cluster.

11 . The method of claim 9 , further comprising filtering out at least one fuzzy hash cluster based at least in part on a similarity match with an existing signature.

12 . The method of claim 9 , wherein performing the false positive reduction analysis includes performing a pairwise comparison between a candidate fuzzy hash included in the set of candidate fuzzy hashes and a fuzzy hash of a known benign sample.

13 . The method of claim 9 , wherein performing the false positive reduction analysis includes removing from consideration a fuzzy hash of a sample that is an infections virus.

14 . The method of claim 9 , wherein generating the signature includes selecting a representative fuzzy hash from the fuzzy hash cluster.

15 . The method of claim 9 , wherein generating the signature includes comparing the signature against a store of existing signatures.

16 . The method of claim 9 , wherein the generated signature is usable by a data appliance to determine whether a file is malicious.

17 . The method of claim 9 , further comprising using the generated signature to detect a new malware family.

18 . The computer program product of claim 10 , further comprising instructions for filtering out at least one fuzzy hash cluster based at least in part on a similarity match with an existing signature.

19 . The computer program product of claim 10 , wherein performing the false positive reduction analysis includes performing a pairwise comparison between a candidate fuzzy hash included in the set of candidate fuzzy hashes and a fuzzy hash of a known benign sample.

20 . The computer program product of claim 10 , wherein performing the false positive reduction analysis includes removing from consideration a fuzzy hash of a sample that is an infections virus.

Continuity (2)
Continuation 17472485 · Sep 10, 2021
Related Publication 20240414129A1 · Dec 12, 2024
References Cited (19)
US 9516055B1 · Liu · 2016 [cited by applicant]
US 10432648B1 · Xu · 2019 [cited by applicant]
US 10764309B2 · Wang · 2020 [cited by applicant]
US 11182481B1 · Oliver · 2021 [cited by examiner]
US 11349865B1 · Satpathy · 2022 [cited by applicant]
US 12107831B2 · Ji · 2024 [cited by examiner]
US 20150067839A1 · Wardman · 2015 [cited by applicant]
US 20170251003A1 · Rostami-Hesarsorkh · 2017 [cited by applicant]
US 20190228151A1 · Schmugar · 2019 [cited by applicant]
US 20190238565A1 · Wang · 2019 [cited by examiner]
US 20190238566A1 · Wang · 2019 [cited by applicant]
US 20190364062A1 · Xu · 2019 [cited by examiner]
US 20200226214A1 · Reddekopp · 2020 [cited by examiner]
US 20200252428A1 · Gardezi · 2020 [cited by applicant]
US 20210021612A1 · Higbee · 2021 [cited by applicant]
US 20220400125A1 · Mendelowitz · 2022 [cited by examiner]
Bass et al., Results of SEI Line-Funded Exploratory New Starts Projects (Year: 2012). [cited by applicant]
Namanya et al., Detection of Malicious Portable Executables Using Evidence Combinational Theory with Fuzzy Hashing. 2016 IEEE 4th International Conference on Future Internet of Things and Cloud, 2016, pp. 91-98. [cited by applicant]
Shiel et al., Improving File-Level Fuzzy Hashes for Malware Variant Classification, Digital Investigation 28, 2019, pp. S88-S94. [cited by applicant]