Patent №
US 7,644,441
Granted
2010-01-05
Filed 2004
Owner
CIGITAL
+1 more
Lab
—
AI components
1
hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
10948147
Malicious software is identified in an executable file by identifying malicious structural features, decryption code, and cryptographic functions. A malicious structural feature is identified by comparing a known malicious structural feature to one or more instructions of the executable file. A malicious structural feature is also identified by graphically and statistically comparing windows of bytes or instructions in a section of the executable file. Cryptography is an indicator of malicious software. Decryption code is identified in an executable file by identifying a tight loop around a reversible instruction that writes to random access memory. Cryptographic functions are identified in an executable file be obtaining a known cryptographic function and performing a string comparison of the numeric constants of the known cryptographic function with the executable file.
AI classification
Ownership
CIGITAL
assignment · 163810024
SYNOPSYS, INC.
assignment · 430830490
Assignors
SCHMID, MATTHEW N., YOUNG, ADAM, WEBER, MICHAEL
On an employer assignment, the assignors are typically the inventors.