首页> 外国专利> USING FILE PREVALENCE TO INFORM AGRESSIVENESS OF BEHAVIORAL HEURISTICS

USING FILE PREVALENCE TO INFORM AGRESSIVENESS OF BEHAVIORAL HEURISTICS

机译:使用文件优先级通知行为偏头痛

摘要

The prevalence rate of a file to be subject to behavior based heuristics analysis is determined, and the aggressiveness level to use in the analysis is adjusted, responsive to the prevalence rate. The aggressiveness is set to higher levels for lower prevalence files and to lower levels for higher prevalence files. Behavior based heuristics analysis is applied to the file, using the set aggressiveness level. In addition to setting the aggressiveness level, the heuristic analysis can also comprise dynamically weighing lower prevalence files as being more likely to be malicious and higher prevalence files as being less likely. Based on the applied behavior based heuristics analysis, it is determined whether or not the file comprises malware. If it is determined that the file comprises malware, appropriate steps can be taken, such as blocking, deleting, quarantining and/or disinfecting the file.
机译:确定要进行基于行为的启发式分析的文件的流行率,并响应于该流行率来调整要在分析中使用的积极性水平。对于较低流行率文件,将攻击性设置为较高级别,对于较高流行率文件,将攻击性设置为较低级别。使用设置的攻击级别,将基于行为的启发式分析应用于文件。除了设置攻击性级别之外,启发式分析还可以包括动态权衡较低流行性文件为恶意软件的可能性和较高流行性文件为恶意软件的可能性。基于基于应用行为的启发式分析,确定文件是否包含恶意软件。如果确定文件包含恶意软件,则可以采取适当的步骤,例如阻止,删除,隔离和/或消毒文件。

著录项

  • 公开/公告号EP2494446A1

    专利类型

  • 公开/公告日2012-09-05

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号EP20100828858

  • 发明设计人 CHEN JOSEPH;CONRAD ROBERT;

    申请日2010-10-26

  • 分类号G06F11/00;

  • 国家 EP

  • 入库时间 2022-08-21 17:11:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号