Patent · US Active

Malicious software detection

US10650146B1 · kind B1 · utility

22Cited by
1References
19Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 1, 2019
Grant dateMay 12, 2020
Priority date
Expiry dateApr 1, 2039

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F16/93
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An amount of data change associated with a version of a content file with respect to one or more previous versions of the content file is determined. The amount of change associated with the version of the content file is determined using a tree data structure associated with the content file that is stored on a storage cluster. One or more statistics associated with backup snapshot are provided to a server. The server is configured to determine that the amount of data change associated with the version of the content file is anomalous based in part on the one or more statistics associated with the backup snapshot. A notification that data associated with the backup snapshot is potentially infected by malicious software is received from the server. The version of the content file is indicated as being potentially infected by malicious software.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.