Method for automatic creation of malware detection signature

Inventors

Lakhotia, Arun

Assignees

University of Louisiana at Lafayette

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11556639-B2

Patent

Publication Date

2023-01-17

Expiration Date


Abstract

Herein disclosed is a method for automatically extracting signatures for malware. The method takes advantage of a fundamental economic requirement of malware authors: they must reuse code to manage the time investment. The method disclosed finds shared code between malware and generates signatures from the code. A method is also disclosed for separating code that is found predominantly, if not exceptionally, in malware from code that may be found in benign program.

Core Innovation

The invention provides a method and system for creating and detecting a signature for a collection of one or more malware using a Semantic Indexer, a Procedure Database, and a Signature Generator. The Semantic Indexer populates the Procedure Database by computing semantic indexes for procedures of one or more programs and storing the procedures as records in the database. The Procedure Database stores two or more semantically similar procedures, and the Signature Generator uses the semantically similar procedures to generate signatures for the one or more malware.

The method collects a set of all procedures in the collection of the one or more malware for which to create signatures, and partitions the set into groups of semantically similar procedures. Groups that are not good candidates for creating signatures are removed, and a signature is constructed for each remaining group. For each procedure in a group, a regular expression is constructed by collecting all blocks of code, partitioning the blocks into groups of semantically similar blocks of code, constructing a block signature for each block group, and assigning unique identifiers to block groups that are then used in regular-expression block-identifier sequences sorted on memory address.

The method also constructs a single regular expression for an entire group of procedures by creating a union of all procedure regular expressions and minimizing the union. A procedure signature is then created by replacing each block identifier with the corresponding block signature of the corresponding group of similar blocks of code. Finally, the signatures of the selected semantically similar procedures are combined to construct the signature for the one or more malware.

Claims Coverage

The partial content explicitly provides one independent claim and multiple dependent refinements. The independent claim covers semantic-index-based procedure grouping, candidate filtering, and construction of regular-expression-based procedure and block signatures that are combined into a malware signature.

Semantic indexing into a procedure database for semantically similar procedures

computing semantic indexes for procedures of one or more programs, and storing said procedures in the Procedure Database, wherein the Procedure Database stores two or more semantically similar procedures

Partitioning procedures into semantically similar groups and removing non-candidates

collecting a set of all procedures in a collection of the one or more malware for which to create signatures; partitioning the set of all procedures of the one or more malware into groups of semantically similar procedures; removing from the partition the groups of semantically similar procedures that are not good candidates for creating signatures; constructing a signature for each of the groups of semantically similar procedures remaining in the partition

Block signature construction from semantically similar blocks and identifier-based regular-expression sequencing

constructing a regular expression for each procedure in the group, comprising: collecting all blocks of code in the group of semantically similar procedures; partitioning the collection of blocks of code into groups of semantically similar blocks of code; constructing a block signature for each group of semantically similar blocks of code; generating a unique identifier for each group of semantically similar blocks of code and assigning the identifier to each block in the group; creating a regular expression sequence of block identifiers for each procedure in the group of one or more semantically similar procedures, comprising block identifiers in the sequence sorted on the memory address of the blocks

Union-and-minimization of procedure regular expressions into a group regular expression and procedure signature via block-signature substitution

creating a single regular expression for an entire group of one or more procedures, comprising: creating a union of all procedure regular expressions; and minimizing said union of all procedure regular expressions; creating a signature for the group of similar procedures, comprising constructing a procedure signature by replacing each block identifier with block signature of the corresponding group of similar block of code

Combining procedure signatures to form a malware signature

combining the signatures of the selected semantically similar procedures to construct the signature of the one or more malware

The coverage focuses on computing semantic indexes for procedures and storing semantically similar procedures in a procedure database, partitioning procedures into semantically similar groups and filtering non-candidates, constructing block and procedure regular expressions including union and minimization, and combining selected procedure signatures to construct a malware signature.

Stated Advantages

Documented Applications

No documented applications found

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.