Detection of a Trojan horse

By comparing the source and metadata of suspect software applications with clean versions, the method efficiently identifies Trojan horses, addressing the inefficiencies of current detection methods and improving detection speed and accuracy.

DE112012000744B4Active Publication Date: 2025-06-18F SECURE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE112012000744
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2011-02-11
Filing Date
2012-01-10
Publication Date
2025-06-18
Estimated Expiration
2032-01-10

AI Technical Summary

Technical Problem

Existing methods for detecting Trojan horses in software applications are resource-intensive and time-consuming, often requiring detailed code analysis or emulation, and do not effectively utilize the source of application acquisition to determine potential malware.

Method used

Compare the source and metadata of a suspect software application with a known clean version to identify discrepancies, such as vendor, version number, and additional capabilities, to determine the likelihood of Trojanization.

Benefits of technology

This method provides a rapid and efficient means to detect Trojan horses by identifying source and metadata differences, reducing the need for extensive code analysis and enhancing detection accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method for detecting a Trojan horse in a suspicious software application in the form of at least one electronic file, comprising: on a computing device, determining the source from which a suspicious software application was obtained; comparing the source from which the suspect software application was obtained with a source from which a clean original version of the software application was obtained; and, If the sources differ, determining that the suspicious application probably contains a Trojan horse.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The invention relates to the field of Trojan horse detection. STATE OF THE ART

[0002] Malware infections of computers and computer systems are a growing problem. There have been numerous high-profile examples of computer malware spreading rapidly around the world, causing millions of dollars in damage through data loss and work stoppages.

[0003] Malware often spreads through computer viruses. Early computer viruses spread by copying infected electronic files onto floppy disks and transferring the electronic file from the disk to an uninfected computer. As soon as the user attempts to open the infected electronic file, the malware is activated and the computer is infected. More recently, viruses have been spread via the internet, for example, through email. Viruses are also known to spread through wireless data transmission, for example, during communication between mobile communication devices on a cellular network.

[0004] There are various antivirus applications available on the market today. These usually work based on a database of signatures or fingerprints of known viruses and malware. With an application with "real-time" virus scanning, whenever the user attempts to perform an operation such as opening, saving, or copying on a file, the request is forwarded to the antivirus application. If the application is not yet familiar with the electronic file, it will scan the electronic file for known signatures of viruses or malware. If a virus or malware is identified in a file, the antivirus application will inform the user, for example, by displaying a message in a pop-up window. The antivirus application can then add the identity of the infected file to a directory of infected files.

[0005] In recent years, so-called "application stores" have become very popular among mobile users. The best-known examples are probably the Apple® App Store and the Android Market. An application store is an online service that allows users to browse and download software applications from a remote server to their device. The applications are often free or very inexpensive, and successful applications are downloaded to millions of devices.

[0006] Although the same software application may be available from another source, the convenience of an application store means that the vast majority of software application downloads occur through an app store.

[0007] The emerging application store paradigm has made it increasingly difficult for malware distributors to use methods such as spam or search result poisoning through search engine optimization (SEO) to deceive their victims into installing malicious applications. Making malware available in an application store is therefore becoming the most successful attack vector. One simple method to trick users into installing malware is to offer the malicious program in the form of an application that appears to provide desirable functionality. This type of malware is called a Trojan horse. A Trojan horse appears to provide desirable functionality but contains malicious code.The malicious code can be executed in addition to providing the desired functionality, so the user is unaware that a Trojan horse is running on their computer device. For example, a Trojan horse can be used to display unwanted advertisements or to grant a malicious third party access to the computer device and enable them to perform unwanted operations, such as calling premium rate numbers, stealing data, installing unwanted software, modifying or deleting existing files, and the like.

[0008] One way to create a Trojan horse is to take an existing application and modify it to add malicious functionality. This process is sometimes referred to as "trojanizing" an application. An example of trojanization is the Geinimi Trojan family, which became active on the Android platform in late 2010. A description of Geinimi can be found at http: / / www.theregister.co.uk / 2010 / 12 / 31 / china_android_trojan / . Geinimi is a malicious mobile program that disguises itself as a gaming application. Once a user installs a Geinimi Trojan, Geinimi can send personal data from the user's device to a remote server. Geinimi can also receive commands from an unrelated third party.

[0009] Trojan horses can be detected by analyzing a software application's code for potential malicious functionality, or by emulating the software application to determine whether it performs any unwanted operations. Both approaches may require a certain amount of time and resources.

[0010] GB 2 463 467 A discloses a method for detecting malware based on whether a file's digital signature belongs to a trusted source. If the signature belongs to a trusted source, then a malware scan of the file is not performed, whereas if the signature cannot be verified to belong to a trusted source, a malware scan is performed. Thus, any file signed by a trusted source is considered trusted, regardless of the file's source.

[0011] US 2006 / 0 230 451 A1 also describes whether a file has been digitally signed by a trusted certification authority. However, there is no indication here that the source from which the application is obtained should be considered to determine whether the application is likely to contain a Trojan horse.

[0012] WO 2009 / 149516 A1 describes a method for monitoring data transmission. A source from which data was downloaded is compared with a designated source, and the data is rejected if these sources differ, e.g., if the request to one source was redirected to another, malicious source. This protects the user from malicious programs that can redirect legitimate data requests to unwanted websites. Thus, this method describes determining whether a data request has been redirected.

[0013] US 2008 / 0 147 837 A1 refers to Trojan horses that modify the Domain Name System (DNS) resolution mechanisms to redirect IP requests from a browser running on an infected computer. This solution describes determining that an IP request is malicious by using a reverse DNS lookup of the hostname of the IP address obtained from a redirected request.

[0014] The publication "WYATT, Tim: Security alert: Geinimi, sophisticated new android trojan found in the wild. Lookout.com, 2010. URL: https: / / blog.lookout.com / security-alert-geinimi-sophisticated-new-android-trojan-found-in-wild" describes evidence that applications found to contain a specific Trojan horse were downloaded from third-party app stores rather than the official Google Android Market. Thus, this solution teaches users to only download applications from trusted sources. SUMMARY

[0015] An object of the present invention is to provide a way to detect a Trojan horse in a software application without immediately resorting to detailed code analysis or emulation. According to a first aspect of the invention, a method for detecting a Trojan horse in a suspect software application in the form of at least one electronic file is provided. A computing device determines the source from which a suspect software application was obtained. A comparison is then performed between the source from which the suspect software application was obtained and a source from which a clean, original version of the software application was obtained. If the sources differ, it is determined that the suspect application likely contains a Trojan horse.

[0016] Optionally, the sources include a seller's identity.

[0017] The method optionally further comprises performing a comparison of the suspect version of the software application with the clean version of the software application. The comparison includes version numbers, version histories, application classes, code block sizes, imported application programming interfaces, called API functions, file sizes of software application components, and / or capabilities and access controls that specify which features the application attempts to access.

[0018] Optionally, the source from which the clean original version of the software application was obtained and other metadata related to the clean version of the software application are stored in a database.

[0019] The invention can optionally be implemented using a backend server. In this case, the method optionally comprises sending a message from the computing device to a remote server, the message containing the components of the suspicious application and / or the metadata related to the suspicious application that the server needs to perform the comparison. In this case, the method can optionally comprise, on the device, receiving a response message from the server. The response message contains an indication that the suspicious software application likely contains a Trojan horse.

[0020] The method optionally includes sending a message from the device to a remote database, the message containing at least one identity of the suspect software application. The device then receives a response from the remote database, the response containing the source from which the clean, original version of the software application was obtained.

[0021] According to a second aspect, a device for use in a communications network is provided. The device is equipped with a processor configured to determine that a software application in the form of at least one electronic file is suspicious. The processor is further configured to determine the source of the software application and is further configured to compare the source from which the suspicious software application was obtained with a source from which a clean, original version of the software application was obtained. If the sources differ, the processor determines that the suspicious application likely contains a Trojan horse.

[0022] Optionally, the device further comprises a transmitter configured to send a request message to either a server or a database. The request message contains a request for the source from which the clean, original version of the software application was obtained. A receiver is also provided configured to receive a response, the response containing the source from which the clean, original version of the software application was obtained. This configuration enables the device to query a database that provides the device with sufficient information to make the determination.

[0023] The processor is optionally further configured to compare the suspect version of the software application with the clean version of the software application with respect to version numbers, version histories, application classes, size of code blocks, imported programming interfaces, called API functions, file size of components of the software application, and / or capabilities and access controls that specify which features the application wants to access.

[0024] In an alternative embodiment, the device comprises a database for storing data relating to the source from which the clean original version of the software application was obtained and further metadata relating to the clean version of the software application.

[0025] According to a third aspect, a device for use in a communications network is provided. The device is equipped with a processor for determining that a software application in the form of at least one electronic file is suspicious. A transmitter is provided for sending a request message to a remote server, the request message containing at least an identity of the source from which the suspicious software application was obtained.A receiver is also provided to receive a response from the server, the response containing an indication as to whether the software application is likely to contain a Trojan horse, the probability being determined by the server at least by comparing the source from which the suspect software application was obtained with a source from which a clean, original version of the software application was obtained and, if the sources are different, by determining that the suspect application is likely to contain a Trojan horse.

[0026] According to a fourth aspect, a server for use in a communications network is provided. The server is equipped with a receiver configured to receive a request message from a remote device, the request message containing at least an identity of a source from which a suspect software application was obtained in the form of at least one electronic file. The processor is further configured to compare the source from which the suspect software application was obtained with a source from which a clean, original version of the software application was obtained. If the sources differ, the processor optionally determines that the suspect application is likely to contain a Trojan horse.A transmitter is provided which is used to send a response message, where the response message contains either the result of the comparison or an indication that the software application probably contains a Trojan.

[0027] Optionally, the server includes a database for storing the source from which the original clean version of the software application was obtained and other metadata related to the clean version of the software application.

[0028] Optionally, the sources include a seller's identity.

[0029] As a further option, the processor is configured to compare the suspect version of the software application with the clean version of the software application with respect to version numbers, version histories, application classes, size of code blocks, imported programming interfaces, called API functions, file size of the software application components and / or capabilities and access controls that specify which features the application wants to access.

[0030] According to a fifth aspect, there is provided a computer program comprising machine-readable code which, when executed on a device, causes the device to behave as a device as described in either the second or third aspect.

[0031] According to a sixth aspect, there is provided a computer program product comprising a machine-readable medium and a computer program as described in the fifth aspect, wherein the computer program is stored on the machine-readable medium.

[0032] According to a seventh aspect, there is provided a computer program comprising machine-readable code which, when executed on a server, causes the server to behave as a server as described in the fourth aspect.

[0033] According to an eighth aspect, there is provided a computer program product comprising a machine-readable medium and a computer program as described in the seventh aspect, wherein the computer program is stored on the machine-readable medium. BRIEF DESCRIPTION OF THE DRAWINGS Fig.1 shows a block diagram schematically a network architecture according to an embodiment of the present invention; Fig. 2 shows a flowchart of the method steps according to an embodiment of the present invention; and Fig. 3 shows a block diagram schematically a device according to a further embodiment of the present invention. DETAILED DESCRIPTION

[0034] To determine whether a suspicious software application has been Trojanized, the suspicious software application is compared to a known clean version of the software application. If the suspicious software application was obtained from a different source than the known clean version of the software application, this increases the likelihood that the suspicious software application has been Trojanized, and further testing can be performed.

[0035] A security service provider, such as antivirus software, obtains known clean versions of software applications. This can be achieved by accepting submissions, for example, from a trusted application store, or by systematically searching the internet. Metadata is extracted from the known clean versions and stored in a database. Metadata can include, for example, the following: 1. Source of the software application; in other words, the application store from which it was obtained, the vendor that provided the software application, or a URI of another type of website from which it was obtained. 2. The name of the software application and an identity of a vendor from whom the application was obtained. The identity can be a cryptographic signature or simply an identity value used by the vendor. 3. The version number of the software application. 4. The size of the software application. 5. A digital signature used to sign the software application. 6. A list of application classes, imported application programming interfaces (APIs), called API functions, and / or code block sizes. 7. A list of capabilities and access controls that specifies which features the application wants to access. 8. A list of external properties of the application, for example, image matching of a splash screen or image matching of the user interface (UI) icon if it is not a standard operating system icon. 9. Clusters of similar code, in other words, an application that has, for example, 95% identical code to other applications in the same cluster (this analysis can only be done by a backend server). 10. Installation location at the end user. For example, under Microsoft Windows®, the path c:\Program Files\ApplicationName is unique and can be used to classify the software application. Under Symbian®, a similar model is used, with c:\private\APPUID (for example, c:\private\10002542b), which is also the only location where the application can store its data.

[0036] Detection of a trojanized software application can be performed in the backend, where suspicious software applications are automatically flagged as malware if they are identified as Trojan horses. Alternatively, an antivirus application on the device that acquired the suspicious application can collect metadata while investigating a suspicious application and compare the information against a local or cloud database, or submit a request to a backend server to compare the metadata.

[0037] Although the detection of a Trojanized software application can be performed in the backend, on a device, or on an online antivirus server in communication with a device, the following example assumes that the detection takes place using a terminal device and an antivirus server.

[0038] In the attached Fig. 1 depicts a device 1, which may be a personal computer, a mobile device, a smartphone, or any other type of computing device. The device 1 can communicate with a remote server 2 located on the network 3.

[0039] The device 1 has a machine-readable medium in the form of a memory 4 in which files 5 can be stored. A processor 6 identifies a suspicious software application. This occurs, for example, when examining software applications stored in the memory 4 or before storing a software application in the memory, for example when downloading the software application from an application store. The processor 6 determines the source of the software application and collects some or all of the other metadata relating to the software application described above as an example. A sender 7 sends a message to the server 2 containing the metadata.

[0040] The server 2 has a receiver 8 that receives the message from the device 1. A processor 9 is available that analyzes the metadata contained in the message and compares the metadata with metadata of a known clean version of the software application stored in a database 10, which is stored on a machine-readable medium in the form of a memory 11. Note that the database 10 is shown to be located on the server 2, but it is equally possible that the database 10 is located on another node that the server 2 can query.

[0041] The processor first compares the source of the suspect software application (e.g., the identity of an application store from which it was obtained or the vendor from whom it was purchased) with the source of the corresponding clean software application stored in database 10. If the source is the same, the probability that the suspect software application has been trojanized is low, although other indicators described below may indicate that the software application has been trojanized. It is possible, although unlikely, that a clean, original version of the software application is available in an application store and a trojanized version of the software application is available in the same application store.

[0042] If the suspicious software application was obtained from a different source than the clean version of the software application, this increases the likelihood that the suspicious software application has been trojanized. A different source could mean that different versions of the software application are available in different application stores, but can also mean that different versions of the software application are available from different vendors in the same or different application stores. Further investigation may be conducted. For example, the suspicious software application may contain additional functionality not included in the clean software application. These include, for example, the ability to call phone numbers, access certain websites, or send short text messages (SMS).If the suspicious version of the software application contains this functionality but the clean version does not, there is a very high probability that the suspicious version has been trojanized.

[0043] The suspicious version of the software application may request more capabilities than the clean version, such as access rights to certain file types, etc. This is also a strong indication that the suspicious version of the software application has been trojanized.

[0044] The digital signatures of the suspicious version of the software application and the clean version of the software application can be compared. Even if the digital signature of the suspicious version of the software application is valid, a discrepancy with the digital signature of the clean version of the software application indicates that the suspicious version of the software application has been modified in some way. This increases the likelihood that the suspicious version of the software application has been Trojanized.

[0045] A comparison can also be made between the features of the clean version of the software application and the suspicious version of the software application. For example, if the suspicious version of the software application has different features than the clean version of the software application or requires different resources, then the suspicious version of the software application has been modified in some way and is more likely to be Trojanized.

[0046] Another test could be to check the suspicious version of the software application for encryption routines used for obfuscation purposes, especially if these routines are not present in the clean version of the software application. This provides further evidence that the suspicious version of the software application has been trojanized, as any malicious code injected into the trojanized suspicious version of the software application would likely use obfuscation techniques.

[0047] Other metadata, such as the version number, version history, and the like, can also be compared. Any difference between the metadata of the clean version of the software application and that of the suspicious version of the software application provides evidence that the suspicious version of the software application has been modified in some way, thus increasing the likelihood that the suspicious version of the software application has been trojanized.

[0048] Database 10 can group applications based on their name, identity, and version information. Applications can also be grouped based on external properties, such as splash image, user interface (UI) icon image matching, or, as described above, clusters of similar code. Applications in the same group can be reviewed to ensure that the same versions of the clean software application and the suspect software application are compared.

[0049] While a single change of the type described above may not be suspicious enough, the detection of multiple changes is highly suspicious if the suspicious version claims to be the same or an updated version of an existing software application. Furthermore, version history can be used to aid in the detection of a trojanized software application. If a functionality is present in a particular version but not in other (either older or newer) versions of the same software application, then this is an indication that a malicious third party has trojanized the software application.

[0050] The memory 4 on the device 1 can also be used to store a computer program 14 that, when executed by the processor 6, causes the device 1 to behave as described above. Similarly, the memory 11 on the server 2 can also be used to store a computer program 15 that, when executed by the processor 9, causes the server 2 to behave as described above.

[0051] To populate the database 10, the server 2 can systematically search the Internet to obtain clean versions (or metadata related to clean versions) of software applications from trusted application stores. Alternatively, software developers can provide the server with clean versions of software applications (or metadata obtained from a clean copy of the software application).

[0052] In order to better describe the invention, Fig.2 Process steps according to an embodiment of the present invention are shown. The following numbers correspond to the Fig. 2 numbers used: S1. A device with a suspicious software application determines the source of the software application. Typically, this is the application store from which the suspicious software was obtained. S2. A comparison is performed between the source of the suspicious software application and the source of the clean original version of the same software application. S3. If the sources match, the process continues at step S6; otherwise, the process continues at step S4. S4. If the sources do not agree, further checks are performed, which may be any of the checks described above. S5. The results of further comparisons are reported to determine whether the suspect software is likely to be trojanized or not. S6. If the sources match, the probability that the suspicious software has been trojanized is low.

[0053] The example above describes a configuration in which a device 1 sends information to a server 2, which then performs the comparison between the application sources. It is also possible to use other architectures, for which Fig. 3 shows an example.

[0054] In this example, a device 16 includes a processor 17 and a machine-readable medium in the form of a memory 18. The memory 18 is used to store files 19 and also a database 20 of known clean versions of software applications. A receiver 21 is provided, which is used to download a software application from an application store. The processor 17 is configured to perform a comparison between the source of the downloaded software application and a clean version of the software application stored in the database 20. In this example, it is not necessary for the device to contact a remote server to determine whether the suspect software application is likely to be trojanized or not.

[0055] A computer program 22 may also be stored in memory 18. Program 22 is configured such that, when executed by processor 17, it causes device 16 to behave as described above.

[0056] While the device 16 here uses a database 20 stored locally on the device, in an alternative embodiment it may be possible to query a backend server or a database in a distributed network to obtain the information needed for the comparison between the source of the suspect software application and the source of the clean original version of the application and for any other metadata comparisons.

[0057] To illustrate the operation of the invention, the example of a software application called MonkeyJump2 is used. It was Trojanized using Geinimi and distributed through a Chinese application store in late 2010. The original software application MonkeyJump2 was distributed through a trusted application store based in the USA.

[0058] Table 1 shows a data comparison between the clean version of MonkeyJump2 and the trojanized version: Table 1. Comparison between clean and trojanized versions of MonkeyJump2 Original Trojan source Trusted, highly trafficked application store in the USA Lesser-known application store in China Signatories Company A Company B skills Only a few and common Extremely long list of privacy-violating capabilities Number of classes N classes N+1 classes Function calls Common for game programs Cryptographic calls (DES functions)

[0059] Prior art methods for detecting Trojanization of the suspicious version of MonkeyJump2 perform code analysis or emulate the behavior of the suspicious application. Both approaches are resource-intensive and time-consuming and can be unreliable. With the present invention, however, a quick comparison between the source of the suspicious software application and the original version of the software application reveals that the sources differ, increasing the likelihood that the suspicious software application has been Trojanized. Further analyses are then performed to determine the likelihood that the suspicious software application has been Trojanized.

[0060] It is evident that the two versions were signed by different companies and that the Trojanized version of the software application contained capabilities not present in the original version. These additional capabilities were also capable of violating privacy, indicating that the suspicious version of the software application was Trojanized. Additionally, the suspicious version of the software application used one more class than the original version and also contained function calls not present in the original. One of these additional function calls used cryptographic functions, providing further evidence that the suspicious version of the software application was Trojanized.

[0061] The present invention enables a greatly simplified and accelerated determination that a software application, in particular a software application obtained from an application store, has been trojanized by comparing the source and other metadata of a suspect software application with that of a clean original version of the same software application.

[0062] Those skilled in the art will appreciate that the above-described embodiment can be modified in various ways without departing from the scope of the present invention. In particular, the system architecture can be changed, a device can obtain information from a local server or from a database in the cloud, and the comparison of the metadata related to the suspect software application can be performed by a backend server.

Claims

[1] A method for detecting a Trojan horse in a suspicious software application in the form of at least one electronic file, comprising: on a computing device, determining the source from which a suspicious software application was obtained; comparing the source from which the suspect software application was obtained with a source from which a clean original version of the software application was obtained; and, If the sources differ, determining that the suspicious application probably contains a Trojan horse. [2] The method of claim 1, wherein the sources include an identity of a seller. [3] The method of any preceding claim, further comprising comparing the suspect version of the software application with the clean version of the software application with respect to version numbers, version histories, application classes, size of code blocks, imported programming interfaces, called API functions, file size of components of the software application, and / or capabilities and access controls that indicate which features the application wants to access. [4] A method according to any one of the preceding claims, wherein the source from which the clean original version of the software application was obtained and further metadata relating to the clean version of the software application are stored in a database. [5] The method of any preceding claim, further comprising sending a message from a computing device to a remote server, the message containing the components of the suspect application and the metadata related to the suspect application required by the server to perform the comparison. [6] The method of claim 5, further comprising receiving a response message from the server on the device, the response message including an indication that the suspect software application likely contains a Trojan horse. [7] The method of claim 1, further comprising sending a message from the device to a remote database, the message containing at least one identity of the suspect software application, and receiving a response from the remote database, the response containing the source from which the clean, original version of the software application was obtained. [8] Device for use in a communications network, comprising: a processor used to determine that a software application in the form of at least one electronic file is suspicious; wherein the processor is further configured to determine the source of the software application; wherein the processor is further configured to compare the source from which the suspect software application was obtained with a source from which a clean, original version of the software application was obtained and, if the sources differ, to determine that the suspect application is likely to contain a Trojan horse. [9] The device of claim 8, further comprising: a sender configured to send a request message to either a server or a database, the request message containing a request for the source from which the clean, original version of the software application was obtained; and a receiver configured to receive a response, the response containing the source from which the clean, original version of the software application was obtained. [10] The device of claim 8 or 9, wherein the processor is further configured to compare the suspect version of the software application with the clean version of the software application with respect to version numbers, version histories, application classes, size of code blocks, imported programming interfaces, called API functions, file size of components of the software application, and / or capabilities and access controls that indicate which features the application wants to access. [11] The apparatus of claim 8, further comprising a database for storing data relating to the source from which the clean original version of the software application was obtained and further metadata relating to the clean version of the software application. [12] A device for use in a communications network, comprising: a processor used to determine that a software application in the form of at least one electronic file is suspicious; a sender configured to send a request message to a remote server, the request message containing at least an identity of the source from which the suspect software application was obtained; a receiver configured to receive a response from the server, the response containing an indication as to whether the software application is likely to contain a Trojan horse, the probability being determined by the server at least by comparing the source from which the suspect software application was obtained with a source from which a clean, original version of the software application was obtained and, if the sources are different, by determining that the suspect application is likely to contain a Trojan horse. [13] A server for use in a communications network, comprising: a receiver operable to receive a request message from a remote device, the request message containing at least one identity of a source from which a suspect software application was obtained in the form of at least one electronic file; a processor used to compare the source from which the suspect software application was obtained with a source from which a clean, original version of the software application was obtained and, if the sources differ, to determine that the suspect application is likely to contain a Trojan horse; a sender configured to send a response message, the response message containing either the result of the comparison or an indication that the software application likely contains a Trojan. [14] The server of claim 13, further comprising a database for storing the source from which the clean original version of the software application was obtained and further metadata related to the clean version of the software application. [15] The server of claim 13 or 14, wherein the sources include an identity of a seller. [16] The server of any one of claims 13 to 15, wherein the processor is further configured to compare the suspect version of the software application with the clean version of the software application with respect to version numbers, version histories, application classes, size of code blocks, imported programming interfaces, called API functions, file size of components of the software application, and / or capabilities and access controls that indicate which features the application wants to access. [17] A computer program comprising machine-readable code which, when executed on a device, causes the device to behave as a device according to any one of claims 8 to 12. [18] A computer program product comprising a machine-readable medium and a computer program according to claim 17, wherein the computer program is stored on the machine-readable medium. [19] A computer program comprising machine-readable code which, when executed on a server, causes the server to behave as a server according to claim 13. [20] A computer program product comprising a machine-readable medium and a computer program according to claim 19, wherein the computer program is stored on the machine-readable medium.

Citation Information

Patent Citations

  • Selective malware scanning of electronic files based on whether an associated digital signature belongs to a trusted source

    GB2463467A

  • Systems and methods for verifying trust of executable files

    US20060230451A1

  • System and Method for Detecting and Mitigating Dns Spoofing Trojans

    US20080147837A1

  • Computer network security system

    WO2009149516A1