发明名称 Inferring file and website reputations by belief propagation leveraging machine reputation
摘要 The probability of a computer file being malware is inferred by iteratively propagating domain knowledge among computer files, related clients, and/or related source domains. A graph is generated to include machine nodes representing clients, file nodes representing files residing on the clients, and optionally domain nodes representing source domains hosting the files. The graph also includes edges connecting the machine nodes with the related file nodes, and optionally edges connecting the domain nodes with the related file nodes. Priors and edge potentials are set for the nodes and the edges based on related domain knowledge. The domain knowledge is iteratively propagated and aggregated among the connected nodes through exchanging messages among the connected nodes. The iteration process ends when a stopping criterion is met. The classification and associated marginal probability for each file node are calculated based on the priors, the received messages, and the edge potentials associated with the edges through which the messages were received.
申请公布号 US8341745(B1) 申请公布日期 2012.12.25
申请号 US20100710324 申请日期 2010.02.22
申请人 CHAU DUEN HORNG;WRIGHT ADAM;SYMANTEC CORPORATION 发明人 CHAU DUEN HORNG;WRIGHT ADAM
分类号 G06F11/00;G06F12/14;G06F15/173;G08B23/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址