发明名称 METHODS AND SYSTEMS FOR IDENTIFYING POTENTIAL ENTERPRISE SOFTWARE THREATS BASED ON VISUAL AND NON-VISUAL DATA
摘要 Visual and non-visual elements associated with the candidate files are analyzed to determine whether the candidate files are malware. A visual element (e.g., icon) is extracted from the candidate file, and the icon's image is compared to a group of reference images associated with trusted entities. If the icon's image matches a reference image, the candidate file may be malware masquerading as trusted software. The non-visual elements associated with the candidate file are used, in combination with the visual elements, to determine whether the candidate file is malware.
申请公布号 US2016224787(A1) 申请公布日期 2016.08.04
申请号 US201514924289 申请日期 2015.10.27
申请人 Bit9, Inc. 发明人 Guy Jeffrey J.;Gilbert Mark
分类号 G06F21/55;G06F3/0481 主分类号 G06F21/55
代理机构 代理人
主权项
地址 Waltham MA US