发明名称 Using file prevalence to inform aggressiveness of behavioral heuristics
摘要 The prevalence rate of a file to be subject to behavior based heuristics analysis is determined, and the aggressiveness level to use in the analysis is adjusted, responsive to the prevalence rate. The aggressiveness is set to higher levels for lower prevalence files and to lower levels for higher prevalence files. Behavior based heuristics analysis is applied to the file, using the set aggressiveness level. In addition to setting the aggressiveness level, the heuristic analysis can also comprise dynamically weighing lower prevalence files as being more likely to be malicious and higher prevalence files as being less likely. Based on the applied behavior based heuristics analysis, it is determined whether or not the file comprises malware. If it is determined that the file comprises malware, appropriate steps can be taken, such as blocking, deleting, quarantining and/or disinfecting the file.
申请公布号 US8302194(B2) 申请公布日期 2012.10.30
申请号 US20090606163 申请日期 2009.10.26
申请人 CONRAD ROBERT;CHEN JOSEPH;SYMANTEC CORPORATION 发明人 CONRAD ROBERT;CHEN JOSEPH
分类号 G06F12/14;G06F7/04;G06F11/30;G06F15/16;G06F15/173;H04L9/32;H04L29/06 主分类号 G06F12/14
代理机构 代理人
主权项
地址