发明名称 ANOMALY DETECTION TO IDENTIFY MALWARE
摘要 Particular embodiments described herein provide for an electronic device that can be configured to monitor activities of objects in a system, compare the monitored activities to metadata for the system, and identify low prevalence outliers to detect potentially malicious activity. The monitored activities can include an analysis of metadata of the objects in the system to identify polymorphic threats, an object reuse analysis of the system to detect an object reusing metadata from another object, and a filename analysis of the system.
申请公布号 WO2017003588(A1) 申请公布日期 2017.01.05
申请号 WO2016US33978 申请日期 2016.05.25
申请人 MCAFEE, INC. 发明人 BEAN, James;SPURLOCK, Joel R.
分类号 G06F21/56;G06F21/62;H04L29/06 主分类号 G06F21/56
代理机构 代理人
主权项
地址