Mandiant, Inc.
System and method for generating a malware identifier

Last updated:

Abstract:

One embodiment of the disclosure is directed to a method for generating an identifier for use in malware detection. Herein, a first plurality of indicators of compromise are obtained. These indicators of compromise correspond to a plurality of anomalous behaviors. Thereafter, a filtering operation is performed on the first plurality of indicators of compromise by removing one or more indicators of compromise from the first plurality of indicators of compromise to create a second plurality of indicators of compromise. The identifier represented by the second plurality of indicators of compromise is created.

Status:
Grant
Type:

Utility

Filling date:

28 Aug 2017

Issue date:

5 Nov 2019