发明授权
- 专利标题: Lineage-based reputation system
- 专利标题(中): 宗族信誉体系
-
申请号: US12831004申请日: 2010-07-06
-
公开(公告)号: US08510836B1公开(公告)日: 2013-08-13
- 发明人: Carey S. Nachenberg
- 申请人: Carey S. Nachenberg
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Fenwick & West LLP
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F17/00 ; G06F12/14 ; G06F11/00 ; G06F15/18 ; G06F15/16 ; G06Q30/00 ; H04L12/58 ; H04L29/06 ; G06F7/00 ; G06F17/30
摘要:
A computer generates a reputation score for a file based at least in part on the lineage of the file. A security module on a client monitors file creations on the client and identifies a parent file creating a child file. The security module provides a lineage report describing the lineage relationship to a security server. The security server uses lineage reports from the client to generate one or more lineage scores for the files identified by the reports. The security server aggregates the lineage scores for files reported by multiple clients. The aggregated lineage scores are used by the security server to generate reputation scores for files. The reputation score for a file indicates a likelihood that the file is malicious. The security server reports the reputation scores to the clients, and the clients use the reputation scores to determine whether files detected at the clients are malicious.
信息查询