首页> 外国专利> ZERO-HOUR QUARANTINE OF SUSPECT ELECTRONIC MESSAGES

ZERO-HOUR QUARANTINE OF SUSPECT ELECTRONIC MESSAGES

机译:疑似电子消息的零小时检疫

摘要

The zero-hour quarantine comprises a tool for flagging potentially harmful messages/files prior to having an anti-virus signature published for a particular virus. The suspect file is sent to the zero-hour quarantine and periodically scanned, giving time for creation of a signature file that would then detect the virus. An example method may include receiving and examining a message for attributes indicative of its undesirability, and assigning a threat score to the message. The method may comprise disposing of the message by comparing the threat score to first and second thresholds, and the message sent to a permanent quarantine if the threat score passes the first threshold. The message is sent to the zero-hour quarantine if the assigned threat score does not pass the second threshold but passes the second threshold, or is delivered to the recipient if the assigned threat score does not pass the first or second threshold.
机译:零小时隔离区包括一个工具,用于在发布针对特定病毒的防病毒签名之前标记可能有害的邮件/文件。可疑文件将被发送到零时隔离区并定期进行扫描,从而为创建签名文件提供了时间,该签名文件随后将检测到病毒。示例方法可以包括:接收并检查消息的指示其不期望的属性;以及向消息分配威胁分数。该方法可以包括通过将威胁得分与第一和第二阈值进行比较来处置消息,并且如果威胁得分超过第一阈值,则将消息发送到永久隔离。如果分配的威胁评分未超过第二阈值但超过第二阈值,则将邮件发送到零时隔离区;如果分配的威胁评分未通过第一或第二阈值,则将邮件传递给收件人。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号