Abstract

A method, apparatus and program product are provided to recognize malware in a computing environment having at least one computer. A sample is received. An automatic determination is made by the at least one computer to determine if the sample is malware using static analysis methods. If the static analysis methods determine the sample is malware, dynamic analysis methods are used by the at least one computer to automatically determine if the sample is malware. If the dynamic analysis methods determine the sample is malware, the sample is presented to a malware analyst to adjudicate the automatic determinations of the static and dynamic analysis. If the adjudication determines the sample is malware, a response action is initiated to recover from or mitigate a threat of the sample.

Document Type

Patent

Status

Issued

Issue Date

6-17-2014

Patent Number

US 8756693 (B2) [ 8,756,693 ]

CPC Classification

G06F21/564

Application number

13/438,240

Assignees

Government of the United States, as represented by the Secretary of the Air Force, Washington, DC (US)

Filing Date

4-3-2012

Share

COinS