Patent · US Active

Mitigating false positives in malware detection

US8719935B2 · kind B2 · utility

9Cited by
1References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 8, 2010
Grant dateMay 6, 2014
Priority date
Expiry dateJul 11, 2032

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/565
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An anti-malware system that reduces the likelihood of detecting a false positive. The system is applied in an enterprise network in which a server receives reports of suspected malware from multiple hosts. Files on hosts suspected of containing malware are compared to control versions of those files. A match between a suspected file and a control version is used as an indication that the malware report is a false positive. Such an indication may be used in conjunction with other information, such as whether other hosts similarly report suspect files that match control versions or whether the malware report is generated by a recently changed component of the anti-malware system.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.