发明名称 Using file reputations to identify malicious file sources in real time
摘要 File reputations are used to identify malicious file sources. Attempts to access files from external sources are monitored. For each monitored attempt to access a file, a reputation of the specific file is determined. Responsive to a determined reputation of a file meeting a threshold, the file is adjudicated to be malicious. Attempts by sources to distribute malicious files are tracked. Responsive to tracked attempts by sources to distribute malicious files, reputations of file sources are determined. Responsive to a determined reputation of a source meeting a threshold, the source is adjudicated to be malicious, and files the source distributes are analyzed to determine whether they comprise malware. Malicious sources are blocked. Malware and malicious sources are analyzed to identify exploits and distribution patterns.
申请公布号 US8683585(B1) 申请公布日期 2014.03.25
申请号 US201113025109 申请日期 2011.02.10
申请人 CHEN JOSEPH H.;WOIRHAYE BRENDON V.;SYMANTEC CORPORATION 发明人 CHEN JOSEPH H.;WOIRHAYE BRENDON V.
分类号 G06F11/00;G06F12/14;G06F12/16;G08B23/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址