AUTOMATED IDENTIFICATION OF POLYMORPHIC COMPUTER THREATS
UCLA Technology Available For Licensing

UCLA Researchers in the Electrical Engineering Department have developed a novel method of identifying computer threats (malware). By utilizing an effective mutation detector having low rates of false positives and false negatives, it is possible to identify even sophisticated polymorphic malware which modifies itself to evade traditional anti-virus scanning techniques.

BACKGROUND:  Polymorphic malware relies on randomization, hiding, decoys, and other modifications to evade identification. In attempting to identify polymorphic malware, a known technique involves emulating a computer environment to fool the malware. However, current malware can easily thwart emulation in a number of ways. Other known identification attempts include preprocessing schemes, detection of NO-OP sleds, Bayesian/SPAM filtering, and automated structural attribute characterization. These techniques can be easily circumvented, can fail to distinguish between safe programs and malware, or can require significant computation time and manual characterization.

INNOVATION:  The novel method is effective at identifying polymorphic forms of malware including viruses, worms, backdoors, and Trojan horses, as well as hybrid combinations. It automatically learns to classify malware, and the classification time is very low due to the nature of the statistical dataflow analysis. Classifications are distributed across a secure peer-to-peer network, globally increasing effectiveness, robustness, and reliability.

POTENTIAL APPLICATIONS 

ADVANTAGES

DEVELOPMENT-TO-DATE:  The novel method has been experimentally tested and verified against synthesized polymorphic malware as well as polymorphic malware found in the wild.

Reference: UCLA Case No. 2006-132 US Patent Application: 11/537,443

For additional technical details and current licensing
availability, please contact the following UCLA office:

UCLA Office of Intellectual Property
11000 Kinross Avenue, Suite #200
Los Angeles, CA 90095-7231
Tel: 310-794-0558 Fax: 310-794-0638
email: ncd@research.ucla.edu
NCD URL:   http://www.research.ucla.edu/tech/ucla06-132.htm

Lead Inventor: Bill Mangione-Smith

UCLA Technologies Available for Licensing
http://www.research.ucla.edu/oipa/industry

Copyright © 2006 The Regents of the University of California.

keywords: search internet software uclancd ucla technologies intellectual property patents technology transfer invention business card