The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 19, 2008

Filed:

Dec. 28, 2001
Applicants:

Nicholas Paul Kelly, Milton Keynes, GB;

Lee Codel Lawson Tarbotton, Leicester, GB;

Kevin Andrew Gudgion, Milton Keynes, GB;

Inventors:

Nicholas Paul Kelly, Milton Keynes, GB;

Lee Codel Lawson Tarbotton, Leicester, GB;

Kevin Andrew Gudgion, Milton Keynes, GB;

Assignee:

McAfee, Inc., Santa Clara, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/30 (2006.01); G08B 23/00 (2006.01);
U.S. Cl.
CPC ...
Abstract

The present invention provides a computer program product, method and data processing apparatus for reviewing files for potential malware. The computer program product comprises logging code operable to maintain a statistical log having an entry for each file sent for review, each entry being arranged to store a count value indicating the number of times that the file has been sent for review and a value of one or more predetermined attributes relating to the file. Weighting table code is also used to maintain a weighting table identifying, for each value of said one or more predetermined attributes, a weighting indicating the likelihood that a file having that value of the one or more predetermined attributes will be malware. The computer program product further comprises statistical log interface code operable, upon receipt of a file, to determine with reference to the statistical log the count value relating to that file, and action determination code operable, if the count value determined by the statistical log interface code exceeds a predetermined threshold, to reference the weighting table to determine the weighting to be associated with the file, based on the value of said one or more predetermined attributes associated with that file in the statistical log. Finally, action performing code is provided to perform predetermined actions in relation to the file depending on the weighting determined by the action determination code. It has been found that this technique is useful in identifying files that may potentially contain malware.


Find Patent Forward Citations

Loading…