发明名称 Proactively analyzing binary files from suspicious sources
摘要 A malware source analysis component determines which sources of malware are sufficiently suspicious such that all binary files located thereon should be analyzed. In order to makes such determinations, the malware source analysis component receives information concerning malware infections from a plurality of sources. The malware source analysis component analyzes the received information, and determines suspiciousness levels associated with specific sources. Responsive to identifying a given threshold suspiciousness level associated with a source, the malware source analysis component adjudicates that source to be suspicious. Where a source is adjudicated to be suspicious, the malware source analysis component submits submission instructions to that source, directing it to identify binary files thereon and submit them to be analyzed. The malware source analysis component receives binary files from suspicious sources according to the submission instructions, and analyzes the received binary files.
申请公布号 US8370942(B1) 申请公布日期 2013.02.05
申请号 US20090403321 申请日期 2009.03.12
申请人 SYMANTEC CORPORATION;PETERSON CHRISTOPHER;CONRAD ROBERT;CHEN JOSEPH H. 发明人 PETERSON CHRISTOPHER;CONRAD ROBERT;CHEN JOSEPH H.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址