Inventors:
Mark Mason - San Antonio TX, US
Ming-Shih Wong - San Antonio TX, US
Jeff Rhines - Adkins TX, US
Josh Mitchell - San Antonio TX, US
Assignee:
The United States of America as represented by the Secretary of the Air Force - Washington DC
International Classification:
G06F 21/00
Abstract:
An improved approach for classifying portable executable files as malicious (malware) or benign (whiteware) is disclosed. The invention classifies portable executable files as malware or whiteware after using Bayes Theorem to evaluate each observable feature of each file with respect to other observable features of the same portable executable file with reference to statistical information gathered from repositories of known whiteware and malware files.