发明授权
US08925088B1 Method and apparatus for automatically excluding false positives from detection as malware
有权
用于自动排除检测中的误报的恶意软件的方法和装置
- 专利标题: Method and apparatus for automatically excluding false positives from detection as malware
- 专利标题(中): 用于自动排除检测中的误报的恶意软件的方法和装置
-
申请号: US12534171申请日: 2009-08-03
-
公开(公告)号: US08925088B1公开(公告)日: 2014-12-30
- 发明人: Jeffrey Wilhelm , Abubakar Wawda
- 申请人: Jeffrey Wilhelm , Abubakar Wawda
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Wilmer Cutler Pickering Hale and Dorr LLP
- 主分类号: G06F12/14
- IPC分类号: G06F12/14
摘要:
A method and apparatus for automatically excluding false positives from detection as malware is described. In one embodiments, a method for using one or more processors to provide false positive reduction for heuristic-based malware detection of a plurality of files in memory includes accessing global first appearance information associated with a plurality of files, accessing global malware information comprising heuristics and an emergence date associated with each malware group of a plurality of malware groups, comparing the global malware information with the global first appearance information to identify at least one false positive amongst the plurality of files and preventing detection of the at least one false positive as malware.
信息查询