发明名称 HEURISTIC MALWARE DETECTION
摘要 Embodiments of the present invention provide a method, system and computer program product for the heuristic malware detection. In one embodiment of the invention, a heuristic malware detection method can include merging a baseline inventory of file attributes for respective files from each client computing system in a community of client computing systems into a merged inventory. The method further can include receiving an updated inventory of file attributes in a current inventory survey from different ones of the client computing systems. Each received survey can be compared to the merged inventory, and in response to the comparison, a deviant pattern of file attribute changes can be detected in at least one survey for a corresponding client computing system. Thereafter, the deviant pattern can be classified as one of a benign event or a malware attack. Finally, malware removal can be requested in the corresponding client computing system if the deviant pattern is classified as a malware attack.
申请公布号 US2008141371(A1) 申请公布日期 2008.06.12
申请号 US20060609170 申请日期 2006.12.11
申请人 BRADICICH THOMAS M;HARPER RICHARD E;PIAZZA WILLIAM J 发明人 BRADICICH THOMAS M.;HARPER RICHARD E.;PIAZZA WILLIAM J.
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址