发明名称 False alarm detection for malware scanning
摘要 A method of scanning files for malware on a computer system. The method includes receiving a file to be scanned in the system, and using at least one malware scanning engine to determine whether or not the file possesses properties that are indicative of malware. If it is determined that the file does possess properties that are indicative of malware, then at least one cleanliness scanning engine is used to determine whether or not the file possesses properties that are indicative of a clean file. If it is determined that the file possesses properties that are indicative of a clean file, then a false alarm is signalled.
申请公布号 US8914889(B2) 申请公布日期 2014.12.16
申请号 US201013376862 申请日期 2010.05.28
申请人 F-Secure Corporation 发明人 Niemela Jarno
分类号 G06F11/00;G06F12/14;G06F12/16;G08B23/00;G06F21/56 主分类号 G06F11/00
代理机构 Harrington & Smith 代理人 Harrington & Smith
主权项 1. A method of providing a malware scanning service to a multiplicity of client computers, the method comprising at a backend server or set of servers performing the steps of: receiving files to be scanned and for each file using at least one malware scanning engine to determine whether or not the file possesses properties that are indicative of malware, if it is determined that the file does possess properties that are indicative of malware, then using at least one cleanliness scanning engine to determine, using one or more heuristics, whether or not the file possesses properties that are indicative of a clean file, if it is determined that the file possesses properties that are indicative of a clean file, then signaling a false alarm; for files for which false alarms are signaled, performing a further automatic and/or manual check to confirm whether or not the file is malware; and for each file that is confirmed as malware and for each file that possesses properties that are indicative of malware but does possess properties that are indicative of a clean file, generating a scanning signature and/or scanning rule and distributing this/these to the client computers.
地址 Helsinki FI