Methods and systems for detecting and preventing the spread of malware on instant messaging (IM) networks by using automated IM users
    2.
    发明申请
    Methods and systems for detecting and preventing the spread of malware on instant messaging (IM) networks by using automated IM users 有权
    通过使用自动化IM用户来检测和防止即时消息(IM)网络上的恶意软件传播的方法和系统

    公开(公告)号:US20070006028A1

    公开(公告)日:2007-01-04

    申请号:US11171251

    申请日:2005-07-01

    IPC分类号: G06F11/00

    摘要: Methods and systems for reducing the spread of malware in communication between an instant message (IM) client and an IM server are described. A malware trapping system (MTS) creates and registers a set of virtual IM users with an IM server. The virtual IM users include account names by which other users of the IM server can communicate with the virtual IM users. The MTS publicizes the account names of the virtual IM users, which causes sources of malware to illicitly acquire the account names of the virtual IM users. The MTS identifies any IM user sending a message to one of the virtual users as a source of malware. The MTS also identifies such a message as a malware message and collects information about the sources of malware and malware messages and stores the information in a database. An IM filter module, accessing the information stored in the database, identifies and blocks malware messages based on the information.

    摘要翻译: 描述用于减少即时消息(IM)客户端和IM服务器之间的通信中恶意软件传播的方法和系统。 恶意软件陷阱系统(MTS)使用IM服务器创建和注册一组虚拟IM用户。 虚拟IM用户包括IM服务器的其他用户可以与虚拟IM用户通信的帐户名称。 MTS公布虚拟IM用户的帐户名称,这导致恶意软件来源非法获取虚拟IM用户的帐户名称。 MTS标识任何IM用户发送消息到其中一个虚拟用户作为恶意软件的来源。 MTS还将这样的消息识别为恶意软件消息,并收集有关恶意软件和恶意软件消息的信息,并将信息存储在数据库中。 访问存储在数据库中的信息的IM过滤器模块基于该信息识别并阻止恶意软件消息。

    Methods and systems for detecting and preventing the spread of malware on instant messaging (IM) networks by using Bayesian filtering
    4.
    发明申请
    Methods and systems for detecting and preventing the spread of malware on instant messaging (IM) networks by using Bayesian filtering 有权
    通过使用贝叶斯滤波来检测和防止即时消息(IM)网络上的恶意软件扩散的方法和系统

    公开(公告)号:US20070006026A1

    公开(公告)日:2007-01-04

    申请号:US11171249

    申请日:2005-07-01

    IPC分类号: G06F11/00

    摘要: Methods and systems for reducing the spread of malware in communication between an instant message (IM) client and an IM server are described. An IM filter module (IM FM) is configured to analyze messages exchanged between an IM server and an IM client. The IM FM also identifies one or more messages as possibly containing malware among the exchanged messages and assigns a confidence level to each identified message. A confidence level represents a probability of a message containing malware. A Bayesian filter is configured to train itself using the identified messages and the confidence levels and adjust the confidence levels. A feedback training mechanism for the Bayesian filter is also included. In particular, the IM FM examines additional messages exchanged between the IM server and IM client, identifies one or more messages as possibly containing malware among the additional messages using the adjusted confidence values. The IM FM also assigns a confidence level to each additionally identified message. The Bayesian filter is further configured to re-train itself using the identified messages, the additionally identified messages, and the confidence levels and adjust the confidence levels.

    摘要翻译: 描述用于减少即时消息(IM)客户端和IM服务器之间的通信中恶意软件传播的方法和系统。 IM滤波器模块(IM FM)被配置为分析IM服务器和IM客户端之间交换的消息。 IM FM还将一个或多个消息识别为可能在交换的消息之间包含恶意软件,并为每个标识的消息分配置信水平。 置信度级别表示包含恶意软件的邮件的概率。 贝叶斯滤波器被配置为使用识别的消息和置信水平来训练自身,并调整置信水平。 还包括贝叶斯滤波器的反馈训练机制。 特别地,IM FM检查在IM服务器和IM客户端之间交换的附加消息,使用经调整的置信度,在附加消息中识别可能包含恶意软件的一个或多个消息。 IM FM还为每个附加标识的消息分配置信水平。 贝叶斯滤波器还被配置为使用所识别的消息,附加识别的消息和置信水平重新训练自身,并调整置信水平。