Palo Alto Networks, Inc.
Context profiling for malware detection

Last updated:

Abstract:

Analysis of samples for maliciousness is disclosed. A sample is executed and one or more network activities associated with executing the sample are recorded. The recorded network activities are compared to a malware profile. The malware profile comprises a set of network activities taken by a known malicious application during execution of the known malicious application. A verdict of "malicious" is assigned to the sample based at least in part on a determination that the recorded network activities match the malware profile.

Status:
Grant
Type:

Utility

Filling date:

10 Jul 2020

Issue date:

22 Mar 2022