Palo Alto Networks, Inc.
AUTOMATED MALWARE FAMILY SIGNATURE GENERATION

Last updated:

Abstract:

The automatic generation of malware family signatures is disclosed. A set of metadata associated with a plurality of samples is received. The samples are clustered. For members of a first cluster, a set of similarities shared among at least a portion of the members of the first cluster is determined. The similarities are evaluated for suitability as a malware family signature. Suitability is evaluated based on how well the similarities uniquely identify the members of the first cluster. In the event the similarities are determined to be suitable as a malware family signature, a signature is generated.

Status:
Application
Type:

Utility

Filling date:

9 Aug 2019

Issue date:

28 Nov 2019