US2019050569A1PendingUtilityA1

Systems and methods of processing data associated with detection and/or handling of malware

Assignee: MCAFEE IRELAND HOLDINGS LTDPriority: Apr 8, 2010Filed: Aug 27, 2018Published: Feb 14, 2019
Est. expiryApr 8, 2030(~3.7 yrs left)· nominal 20-yr term from priority
Inventors:Lixin Lu
G06F 21/561G06F 2221/034G06F 21/564G06F 21/566G06F 21/562G06F 21/568G06F 21/563G06F 21/552
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure relates to malware and, more particularly, towards systems and methods of processing information associated with detecting and handling malware. According to certain illustrative implementations, methods of processing malware are disclosed. Moreover, such methods may include one or more of unpacking and/or decrypting malware samples, dynamically analyzing the samples, disassembling and/or reverse engineering the samples, performing static analysis of the samples, determining latent logic execution path information regarding the samples, classifying the samples, and/or providing intelligent report information regarding the samples.

Claims

exact text as granted — not AI-modified
1 - 83 . (canceled) 
     
     
         84 . At least one non-transitory computer-readable medium comprising instructions, that, when executed by a processor, are to:
 execute malware code within a native operating system of the malware code;   generate a log of executed logic paths of the malware code that have been executed within the native operating system of the malware code;   generate a log of non-executed logic paths of the malware code that have not been executed within the native operating system based on the log of the executed logic paths;   identify a latent behavior of the malware code based on the log of the non-executed logic paths; and   create a malware repair program based on the log of the executed logic paths and the log of the non-executed logic paths, the malware repair program comprising an instruction configured to reverse the latent behavior of the malware code.   
     
     
         85 . The at least one non-transitory computer-readable medium of  claim 84 , wherein the latent behavior of the malware code comprises a malicious code triggers execution based on a condition. 
     
     
         86 . The at least one non-transitory computer-readable medium of  claim 85 , wherein the condition has not been met based on the execution of the malware code within the native operating system of the malware code. 
     
     
         87 . The at least one non-transitory computer-readable medium of  claim 84 , wherein the instructions, when executed by the processor, are to:
 prepare a boot image in an operating system that is different from the native operating system of the malware code.   
     
     
         88 . The at least one non-transitory computer-readable medium of  claim 87 , wherein the instructions, when executed by the processor, are to:
 generate an executable program configured to access a file system of the native operating system of the malware code through the boot image that does not activate the native operating system of the malware code.   
     
     
         89 . The at least one non-transitory computer-readable medium of  claim 84 , wherein the instructions, when executed by the processor, are to:
 generate a graph of the executed logic paths and the non-executed logic paths based on the log of the executed logic paths and the log of the non-executed logic paths.   
     
     
         90 . The at least one non-transitory computer-readable medium of  claim 89 , wherein the graph comprises an electronic graphical representation of the executed logic paths and the non-executed logic paths of the malware code, the electronic graphical representation comprising:
 a first indicia representing the executed logic paths, and   a second indicia representing the non-executed logic paths.   
     
     
         91 . An apparatus comprising:
 an analysis component configured to:
 execute malware code within a native operating system of the malware code; and 
 generate a log of executed logic paths of the malware code that have been executed within the native operating system of the malware code; 
   a management component configured to:
 generate a log of non-executed logic paths of the malware code that have not been executed within the native operating system based on the log of executed logic paths; 
 identify a latent behavior of the malware code based on the log of non-executed logic paths; and 
 create a malware repair program based on the log of executed logic paths and the log of non-executed logic paths, the malware repair program comprising an instruction configured to reverse the latent behavior of the malware code. 
   
     
     
         92 . The apparatus of  claim 91 , wherein the management component operates in an operating system that is different from the native operating system of the malware code. 
     
     
         93 . The apparatus of  claim 91 , wherein the latent behavior of the malware code comprises a malicious code that triggers execution based on a condition. 
     
     
         94 . The apparatus of  claim 93 , wherein the condition has not been met based on the execution of the malware code within the native operating system of the malware code. 
     
     
         95 . The apparatus of  claim 91 , wherein the management component is configured to:
 prepare a boot image in an operating system that is different from the native operating system of the malware code.   
     
     
         96 . The apparatus of  claim 95 , wherein the management component is configured to:
 generate an executable program configured to access a file system of the native operating system of the malware code through the boot image that does not activate the native operating system of the malware code.   
     
     
         97 . The apparatus of  claim 91 , wherein the management component is configured to:
 generate a graph of the executed logic paths and the non-executed logic paths based on the log of the executed logic paths and the log of the non-executed logic paths.   
     
     
         98 . A method comprising:
 executing malware code within a native operating system of the malware code;   generating a log of executed logic paths of the malware code that have been executed within the native operating system of the malware code;   generating a log of non-executed logic paths of the malware code that have not been executed within the native operating system based on the log of executed logic paths;   identifying a latent behavior of the malware code based on the log of non-executed logic paths; and   creating a malware repair program based on the log of executed logic paths and the log of non-executed logic paths, the malware repair program comprising an instruction configured to reverse the latent behavior of the malware code.   
     
     
         99 . The method of  claim 98 , wherein the latent behavior of the malware code comprises a malicious code triggers execution based on a condition. 
     
     
         100 . The method of  claim 99 , wherein the condition has not been met based on the execution of the malware code within the native operating system of the malware code. 
     
     
         101 . The method of  claim 98 , further comprising:
 preparing a boot image in an operating system that is different from the native operating system of the malware code.   
     
     
         102 . The method of  claim 101 , further comprising: generating an executable program configured to access a file system of the native operating system of the malware code through the boot image that does not activate the native operating system of the malware code. 
     
     
         103 . The method of  claim 98 , further comprising:
 generating a graph of the executed logic paths and the non-executed logic paths based on the log of the executed logic paths and the log of the non-executed logic paths.

Join the waitlist — get patent alerts

Track US2019050569A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.