The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 29, 2013

Filed:

Dec. 23, 2009
Applicants:

Yury V. Mashevsky, Moscow, RU;

Yury V. Namestnikov, Moscow, RU;

Nikolay V. Denishchenko, Moscow, RU;

Pavel A. Zelensky, Moscow, RU;

Inventors:

Yury V. Mashevsky, Moscow, RU;

Yury V. Namestnikov, Moscow, RU;

Nikolay V. Denishchenko, Moscow, RU;

Pavel A. Zelensky, Moscow, RU;

Assignee:

Kaspersky Lab, ZAO, Moscow, RU;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 12/14 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01);
Abstract

A system, method and computer program product for detection of the previously unknown malware, the method comprising: (a) receiving event information and file metadata from a remote computer; (b) identifying whether the event information or the file metadata are indicative of the already known malware presence, indicative of the unknown malware presence, or indicative of malware absence; (c) if the event information or the file metadata are indicative of the known malware or indicative of malware absence, filtering out the event information and the file metadata; (d) performing a risk analysis and risk assessment for the remaining event information and the remaining file metadata to determine if the event and the file metadata are indicative of the previously unknown malware presence; and (e) where performing a risk analysis and risk assessment includes a 'parent-child' hierarchy of the files, and the risk assessed to the parent is based on the risk associated with the child.


Find Patent Forward Citations

Loading…