发明名称 Method and system for processing a file to identify unexpected file types
摘要 A method and system for testing a file (or packet) formed from a sequential series of information units, each information unit within a predetermined set of information units, e.g., each information unit may correspond to a character within the ASCII character set. An information unit-pair entropy density measurement is calculated for the received file using a probability matrix. The probability matrix tabulates the probabilities of occurrence for each possible sequential pair of information units of the predetermined set of information units. The computed information unit-pair entropy density measurement is compared with a threshold associated with an expected file type to determine whether the received file is of the expected file type or of an unexpected file type. The probability matrix may optionally be generated from the received file prior to calculating the density thereof. The probability matrix may optionally be predetermined based on the expected file type.
申请公布号 US8516580(B2) 申请公布日期 2013.08.20
申请号 US201113095207 申请日期 2011.04.27
申请人 MENOHER JEFFREY;OWL COMPUTING TECHNOLOGIES, INC. 发明人 MENOHER JEFFREY
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址