Skip to main content


next previous up

Next 3.1- Generating candidate signatures
Previous 2- Virus Scanners and Signatures
Up Automatic Extraction of Computer Virus Signatures

3- The Extraction/Evaluation Algorithm

Suppose that we have just obtained a sample of a new virus imbedded in some host (infected) executable program. We wish to find a good signature for that virus: one that will appear in every instance of the virus, but is extremely unlikely to appear just by coincidence in code not containing the virus.

This is accomplished in two phases. First, a set of signatures that are likely to appear in each instance of the virus is generated. Second, one or a few signatures that minimize the false-positive probability are chosen from this set.




next previous up

Next 3.1- Generating candidate signatures
Previous 2- Virus Scanners and Signatures
Up Automatic Extraction of Computer Virus Signatures


Back To Index