Using file prevalence to inform aggressiveness of behavioral heuristics
US8302194B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Oct 26, 2009 |
| Grant date | Oct 30, 2012 |
| Priority date | — |
| Expiry date | Sep 17, 2030 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/566
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
The prevalence rate of a file to be subject to behavior based heuristics analysis is determined, and the aggressiveness level to use in the analysis is adjusted, responsive to the prevalence rate. The aggressiveness is set to higher levels for lower prevalence files and to lower levels for higher prevalence files. Behavior based heuristics analysis is applied to the file, using the set aggressiveness level. In addition to setting the aggressiveness level, the heuristic analysis can also comprise dynamically weighing lower prevalence files as being more likely to be malicious and higher prevalence files as being less likely. Based on the applied behavior based heuristics analysis, it is determined whether or not the file comprises malware. If it is determined that the file comprises malware, appropriate steps can be taken, such as blocking, deleting, quarantining and/or disinfecting the file.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.