发明名称 Mitigating false positives in malware detection
摘要 An anti-malware system that reduces the likelihood of detecting a false positive. The system is applied in an enterprise network in which a server receives reports of suspected malware from multiple hosts. Files on hosts suspected of containing malware are compared to control versions of those files. A match between a suspected file and a control version is used as an indication that the malware report is a false positive. Such an indication may be used in conjunction with other information, such as whether other hosts similarly report suspect files that match control versions or whether the malware report is generated by a recently changed component of the anti-malware system.
申请公布号 US8719935(B2) 申请公布日期 2014.05.06
申请号 US20100684719 申请日期 2010.01.08
申请人 POLYAKOV ALEXEY A.;BIKKULA RAVI;MICROSOFT CORPORATION 发明人 POLYAKOV ALEXEY A.;BIKKULA RAVI
分类号 G06F21/00;G06F21/56 主分类号 G06F21/00
代理机构 代理人
主权项
地址