Mandiant, Inc.
System and method for generating a malware identifier
Last updated:
Abstract:
One embodiment of the disclosure is directed to a method for generating an identifier for use in malware detection. Herein, a first plurality of indicators of compromise are obtained. These indicators of compromise correspond to a plurality of anomalous behaviors. Thereafter, a filtering operation is performed on the first plurality of indicators of compromise by removing one or more indicators of compromise from the first plurality of indicators of compromise to create a second plurality of indicators of compromise. The identifier represented by the second plurality of indicators of compromise is created.
Status:
Grant
Type:
Utility
Filling date:
28 Aug 2017
Issue date:
5 Nov 2019