发明名称 IDENTIFYING APPLICATION REPUTATION BASED ON RESOURCE ACCESSES
摘要 Malware detection is often based on monitoring a local application binary and/or process, such as detecting patterns of malicious code, unusual local resource utilization, or suspicious application behavior. However, the volume of available software, variety of malware, and sophistication of evasion techniques may reduce the effectiveness of detection based on monitoring local resources. Presented herein are techniques for identifying malware based on the reputations of remote resources (e.g., web content, files, databases, IP addresses, services, and users) accessed by an application. Remote resource accesses may be reported to a reputation service, which may identify reputations of remote resources, and application reputations of applications that utilize such remote resources. These application reputations may be used to adjust the application policies of the applications executed by devices and servers. These techniques thereby achieve rapid detection and mitigation of newly identified malware through application telemetry in a predominantly automated manner.
申请公布号 US2013042294(A1) 申请公布日期 2013.02.14
申请号 US201113205136 申请日期 2011.08.08
申请人 MICROSOFT CORPORATION;COLVIN RYAN CHARLES;HABER ELLIOTT JEB;BHATAWDEKAR AMEYA;PENTA ANTHONY P. 发明人 COLVIN RYAN CHARLES;HABER ELLIOTT JEB;BHATAWDEKAR AMEYA;PENTA ANTHONY P.
分类号 G06F21/00;G06F11/00;G06F17/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址