发明名称 Silent-mode signature testing in anti-malware processing
摘要 Method and computer program product for signature testing used in anti-malware processing. Silent signatures, after being tested, are not updated into a white list and are sent directly to users instead. If the silent signature coincides with malware signature, a user is not informed. A checksum (e.g., hash value) of a suspected file is sent to a server, where statistics are kept and analyzed. Based on collected false positive statistics of the silent-signature, the silent-signature is either valid or invalid. Use of the silent signatures provides for effective signature testing and reduces response time to new malware-related threats. The silent signature method is used for turning off a signature upon first false positive occurrence. Use of silent signatures allows improving heuristic algorithms for detection of unknown malware.
申请公布号 US8356354(B2) 申请公布日期 2013.01.15
申请号 US20100721308 申请日期 2010.03.10
申请人 KASPERSKY LAB, ZAO;NAZAROV DENIS A. 发明人 NAZAROV DENIS A.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址