-
公开(公告)号:US08863279B2
公开(公告)日:2014-10-14
申请号:US12719535
申请日:2010-03-08
申请人: Monty D. McDougal , Randy S. Jennings , Jeffrey C. Brown , Jesse J. Lee , Brian N. Smith , Darin J. De Rita , Kevin L. Cariker , William E. Sterns , Michael K. Daly
发明人: Monty D. McDougal , Randy S. Jennings , Jeffrey C. Brown , Jesse J. Lee , Brian N. Smith , Darin J. De Rita , Kevin L. Cariker , William E. Sterns , Michael K. Daly
CPC分类号: H04L63/1416 , G06F21/56
摘要: According to one embodiment, a computer-implemented method for execution on one or more processors includes receiving a first file and determining a file type of the first file. The method also includes determining, according to a first policy, a plurality of malware detection schemes to apply to the first file based on the determined file type of the first file. In addition, the method includes scheduling the application of the determined plurality of malware detection schemes to the first file amongst a plurality of detection nodes according to a second policy. Further, the method includes determining, in response to determining the results of applying the plurality of malware detection schemes, that the first file is malware or determining that the first file is suspected malware according to a third policy.
摘要翻译: 根据一个实施例,用于在一个或多个处理器上执行的计算机实现的方法包括接收第一文件并确定第一文件的文件类型。 该方法还包括根据第一策略确定多个恶意软件检测方案,以基于所确定的第一文件的文件类型来应用于第一文件。 此外,该方法包括根据第二策略在多个检测节点之中对所确定的多个恶意软件检测方案的应用调度到第一文件。 此外,该方法包括响应于确定应用多个恶意软件检测方案的结果,确定第一文件是恶意软件,或者根据第三策略确定第一文件是可疑的恶意软件。
-
公开(公告)号:US20110219450A1
公开(公告)日:2011-09-08
申请号:US12719535
申请日:2010-03-08
申请人: Monty D. McDougal , Randy S. Jennings , Jeffrey C. Brown , Jesse J. Lee , Brian N. Smith , Darin J. De Rita , Kevin L. Cariker , William E. Sterns , Michael K. Daly
发明人: Monty D. McDougal , Randy S. Jennings , Jeffrey C. Brown , Jesse J. Lee , Brian N. Smith , Darin J. De Rita , Kevin L. Cariker , William E. Sterns , Michael K. Daly
CPC分类号: H04L63/1416 , G06F21/56
摘要: According to one embodiment, a computer-implemented method for execution on one or more processors includes receiving a first file and determining a file type of the first file. The method also includes determining, according to a first policy, a plurality of malware detection schemes to apply to the first file based on the determined file type of the first file. In addition, the method includes scheduling the application of the determined plurality of malware detection schemes to the first file amongst a plurality of detection nodes according to a second policy. Further, the method includes determining, in response to determining the results of applying the plurality of malware detection schemes, that the first file is malware or determining that the first file is suspected malware according to a third policy.
摘要翻译: 根据一个实施例,用于在一个或多个处理器上执行的计算机实现的方法包括接收第一文件并确定第一文件的文件类型。 该方法还包括根据第一策略确定多个恶意软件检测方案,以基于所确定的第一文件的文件类型来应用于第一文件。 此外,该方法包括根据第二策略在多个检测节点之中对所确定的多个恶意软件检测方案的应用调度到第一文件。 此外,该方法包括响应于确定应用多个恶意软件检测方案的结果,确定第一文件是恶意软件,或者根据第三策略确定第一文件是可疑的恶意软件。
-