发明授权
- 专利标题: Using expectation measures to identify relevant application analysis results
- 专利标题(中): 使用期望措施确定相关应用分析结果
-
申请号: US13481715申请日: 2012-05-25
-
公开(公告)号: US08806644B1公开(公告)日: 2014-08-12
- 发明人: Bruce McCorkendale , Jun Mao
- 申请人: Bruce McCorkendale , Jun Mao
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Brill Law Office
- 代理商 Jeffrey Brill
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; H04L29/06
摘要:
An application is analyzed, thereby detecting behaviors of the application. Data indicative of the functionality of the application is mined from a plurality of sources. The application is categorized based on the mined data. The categorization of the application indicates expected application behaviors. Multiple categories can be assigned to the application, wherein each assigned category correlates with at least one expected application behavior. Measures of consistency between the detected behaviors of the application and the expected behaviors of the application are determined. Determining the measures of consistency comprises quantifying differences between detected behaviors of the application and expected behaviors of the application. Responsive to the determined measures of consistency, it is adjudicated whether the application is suspect of being malicious.
信息查询