发明名称 Systems and methods for detecting selective malware attacks
摘要 A computer-implemented method for detecting selective malware attacks is described. A website visited by a user is identified based on a number of visits to the website satisfying a predetermined threshold. A web crawl is performed on the identified website. Results of the web crawl are analyzed to determine whether the identified website includes a malicious software attack designed to selectively attack visitors to the website.
申请公布号 US9275226(B1) 申请公布日期 2016.03.01
申请号 US201314029451 申请日期 2013.09.17
申请人 Symantec Corporation 发明人 Roundy Kevin;Bhatkar Sandeep;Guo Fanglu
分类号 G06F11/00;G06F12/14;G06F12/16;G06F21/56 主分类号 G06F11/00
代理机构 Holland & Hart, LLP 代理人 Holland & Hart, LLP
主权项 1. A computer-implemented method for detecting selective malware attacks, the method comprising: identifying a website visited by a first device operating at a first location, wherein a number of visits to the website satisfies a predetermined threshold; identifying a low prevalence file based on a web crawl of the identified website performed by the first device at the first location, wherein the low prevalence file comprises a file unclassified by a predetermined server; determining whether a web crawl of the identified website performed by the predetermined server results in the predetermined server detecting the low prevalence file; determining whether a web crawl of the identified website performed by a second device operating at a second location results in the second device detecting the low prevalence file; analyzing, by at least one of the first device, second device, and the predetermined server, results of the web crawls to determine whether the identified website distributes a malicious software attack designed to selectively attack visitors to the website; and upon determining the low prevalence file is detected by the second device and not detected by the predetermined server, generating a notification comprising an alert that the identified website is suspected of distributing a malicious software attack designed to target the first device.
地址 Mountain View CA US