The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 30, 2012

Filed:

Oct. 26, 2009
Applicants:

Robert Conrad, Culver City, CA (US);

Joseph Chen, Los Angeles, CA (US);

Inventors:

Robert Conrad, Culver City, CA (US);

Joseph Chen, Los Angeles, CA (US);

Assignee:

Symantec Corporation, Mountain View, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 12/14 (2006.01); G06F 7/04 (2006.01); G06F 11/30 (2006.01); G06F 15/173 (2006.01); G06F 15/16 (2006.01); H04L 29/06 (2006.01); H04L 9/32 (2006.01);
U.S. Cl.
CPC ...
Abstract

The prevalence rate of a file to be subject to behavior based heuristics analysis is determined, and the aggressiveness level to use in the analysis is adjusted, responsive to the prevalence rate. The aggressiveness is set to higher levels for lower prevalence files and to lower levels for higher prevalence files. Behavior based heuristics analysis is applied to the file, using the set aggressiveness level. In addition to setting the aggressiveness level, the heuristic analysis can also comprise dynamically weighing lower prevalence files as being more likely to be malicious and higher prevalence files as being less likely. Based on the applied behavior based heuristics analysis, it is determined whether or not the file comprises malware. If it is determined that the file comprises malware, appropriate steps can be taken, such as blocking, deleting, quarantining and/or disinfecting the file.


Find Patent Forward Citations

Loading…