MITIGATING FALSE POSITIVES IN MALWARE DETECTION
    2.
    发明申请
    MITIGATING FALSE POSITIVES IN MALWARE DETECTION 有权
    在恶意软件检测中减轻虚假的积极性

    公开(公告)号:US20110173698A1

    公开(公告)日:2011-07-14

    申请号:US12684719

    申请日:2010-01-08

    IPC分类号: G06F11/00

    摘要: An anti-malware system that reduces the likelihood of detecting a false positive. The system is applied in an enterprise network in which a server receives reports of suspected malware from multiple hosts. Files on hosts suspected of containing malware are compared to control versions of those files. A match between a suspected file and a control version is used as an indication that the malware report is a false positive. Such an indication may be used in conjunction with other information, such as whether other hosts similarly report suspect files that match control versions or whether the malware report is generated by a recently changed component of the anti-malware system.

    摘要翻译: 一种防恶意软件系统,可以降低检测到假阳性的可能性。 该系统应用在企业网络中,其中服务器从多个主机接收可疑恶意软件的报告。 将怀疑含有恶意软件的主机上的文件与这些文件的控制版本进行比较。 可疑文件和控制版本之间的匹配被用作指示恶意软件报告是假阳性。 这样的指示可以与其他信息一起使用,诸如其他主机是否类似地报告与控制版本相匹配的可疑文件,或者恶意软件报告是否由反恶意软件系统的最近更改的组件生成。

    Mitigating false positives in malware detection
    3.
    发明授权
    Mitigating false positives in malware detection 有权
    减轻恶意软件检测中的误报

    公开(公告)号:US08719935B2

    公开(公告)日:2014-05-06

    申请号:US12684719

    申请日:2010-01-08

    IPC分类号: G06F21/00 G06F21/56

    摘要: An anti-malware system that reduces the likelihood of detecting a false positive. The system is applied in an enterprise network in which a server receives reports of suspected malware from multiple hosts. Files on hosts suspected of containing malware are compared to control versions of those files. A match between a suspected file and a control version is used as an indication that the malware report is a false positive. Such an indication may be used in conjunction with other information, such as whether other hosts similarly report suspect files that match control versions or whether the malware report is generated by a recently changed component of the anti-malware system.

    摘要翻译: 一种防恶意软件系统,可以降低检测到假阳性的可能性。 该系统应用在企业网络中,其中服务器从多个主机接收可疑恶意软件的报告。 将怀疑含有恶意软件的主机上的文件与这些文件的控制版本进行比较。 可疑文件和控制版本之间的匹配被用作指示恶意软件报告是假阳性。 这样的指示可以与其他信息一起使用,诸如其他主机是否类似地报告与控制版本相匹配的可疑文件,或者恶意软件报告是否由反恶意软件系统的最近更改的组件生成。