skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Statistical fingerprinting for malware detection and classification

Patent ·
OSTI ID:1214592

A system detects malware in a computing architecture with an unknown pedigree. The system includes a first computing device having a known pedigree and operating free of malware. The first computing device executes a series of instrumented functions that, when executed, provide a statistical baseline that is representative of the time it takes the software application to run on a computing device having a known pedigree. A second computing device executes a second series of instrumented functions that, when executed, provides an actual time that is representative of the time the known software application runs on the second computing device. The system detects malware when there is a difference in execution times between the first and the second computing devices.

Research Organization:
Oak Ridge National Laboratory (ORNL), Oak Ridge, TN (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC05-00OR22725
Assignee:
UT-Battelle, LLC (Oak Ridge, TN)
Patent Number(s):
9,135,440
Application Number:
13/955,784
OSTI ID:
1214592
Resource Relation:
Patent File Date: 2013 Jul 31
Country of Publication:
United States
Language:
English

References (5)

Automatic analysis of a computer virus structure and means of attachment to its hosts patent January 1996
System and method for gathering exhibited behaviors on a .NET executable module in a secure manner patent June 2010
Method and apparatus for providing mobile device malware defense patent March 2013
Behavioral detection of malware: from a survey towards an established taxonomy journal February 2008
Countering code-injection attacks with instruction-set randomization
  • Kc, Gaurav S.; Keromytis, Angelos D.; Prevelakis, Vassilis
  • CCS '03 Proceedings of the 10th ACM conference on Computer and communications security, p. 272-280 https://doi.org/10.1145/948109.948146
conference January 2003

Similar Records

Related Subjects