发明名称 IDENTIFYING MISUSE OF LEGITIMATE OBJECTS
摘要 A query is received from a client device regarding an object. The query includes an identifier of the object and a set of associated usage attributes describing a usage of the object on the client device. A set of usage facts associated with the identified object is identified. The set of usage facts describe typical usages of the object on a plurality of client devices. A determination is made whether the usage of the object on the client device is suspicious based on the set of usage facts associated with the object and the set of usage attributes included in the query. A report is provided to the client device based on the determination.
申请公布号 US2015281268(A1) 申请公布日期 2015.10.01
申请号 US201514736672 申请日期 2015.06.11
申请人 Symantec Corporation 发明人 Satish Sourabh
分类号 H04L29/06;G06F17/30;H04L12/26 主分类号 H04L29/06
代理机构 代理人
主权项 1. A computer-implemented method of identifying suspicious usage of an object, the method comprising: receiving a query from a client device regarding an object trusted as non-malicious by a security module executing on the client device, the query including an identifier of the object and a set of usage attributes describing a usage of the object on the client device; identifying a set of usage facts associated with the identified object, the set of usage facts describing typical usages of the identified object on a plurality of client devices; comparing, by a computer, the set of usage facts associated with the identified object and the set of usage attributes included in the query from the client device; responsive to a threshold number of usage attributes from the set of usage attributes not matching the set of usage facts associated with the identified object, classifying the usage of the identified object on the client device as suspicious; responsive to the threshold number of usage attributes from the set of usage attributes matching the set of usage facts associated with the identified object, classifying the usage of the identified object on the client device as non-suspicious; and providing a report to the client device including the classification of the usage of the identified object on the client device.
地址 Mountain View CA US